CVE-2026-105222 Exposes Google Maps API Keys
Article Content
- •CVE-2026-105222 has a CVSS score of 9.1, classified as critical.
- •The vulnerability allows interception of Google Maps API keys due to disabled TLS verification.
- •Laravel applications using the affected package are at high risk, especially in untrusted networks.
The alexpechkarev/google-maps Laravel package, through version 12.16, disables TLS certificate verification by default, allowing on-path attackers to intercept web-service requests. This vulnerability can expose Google Maps API keys and enable unauthorized API usage, leading to unexpected costs or misleading functionality. Laravel applications using this package are particularly at risk, especially in environments where outbound traffic can be intercepted. The CVE-2026-105222 has a CVSS score of 9.1, marking it as. No proof-of-concept or exploitation in the wild has been confirmed yet, but immediate remediation is advised. Developers are urged to upgrade to a version that enables certificate verification and to review their API key usage.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-105222 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of the package are affected?
What immediate actions should be taken?
Is there any confirmed exploitation of this vulnerability?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…