---
id: CVE-2026-105222
title: >-
  The alexpechkarev/google-maps Laravel package through 12.16 disables TLS
  certificate verification by default because the bundled config sets
  ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER
summary: >-
  The alexpechkarev/google-maps Laravel package through 12.16 disables TLS
  certificate verification by default because the bundled config sets
  ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path
  attackers can prese…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-295
vendor: alexpechkarev
product: google-maps
affected:
  - google-maps >= 1.0.3 <= 12.16
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T23:16:59.917'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105222'
references:
  - url: 'https://github.com/alexpechkarev/google-maps'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/alexpechkarev/google-maps/blob/v12.14/src/WebService.php#L267-L269
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/alexpechkarev/google-maps/blob/v12.16/src/config/googlemaps.php#L28
    label: disclosure@vulncheck.com
  - url: 'https://github.com/alexpechkarev/google-maps/issues/123'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/alexpechkarev-google-maps-through-12.16-disabled-tls-certificate-verification-via-ssl-verify-peer
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-04T23:05:36.130Z'
---

## Overview

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
