Skip to content
CVE-2026-105222 Exposes Google Maps API Keys

CVE-2026-105222 Exposes Google Maps API Keys

First seen 5 Oct 2026, 08:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 08:05 UTC
  • •CVE-2026-105222 has a CVSS score of 9.1, classified as critical.
  • •The vulnerability allows interception of Google Maps API keys due to disabled TLS verification.
  • •Laravel applications using the affected package are at high risk, especially in untrusted networks.

The alexpechkarev/google-maps Laravel package, through version 12.16, disables TLS certificate verification by default, allowing on-path attackers to intercept web-service requests. This vulnerability can expose Google Maps API keys and enable unauthorized API usage, leading to unexpected costs or misleading functionality. Laravel applications using this package are particularly at risk, especially in environments where outbound traffic can be intercepted. The CVE-2026-105222 has a CVSS score of 9.1, marking it as. No proof-of-concept or exploitation in the wild has been confirmed yet, but immediate remediation is advised. Developers are urged to upgrade to a version that enables certificate verification and to review their API key usage.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-10-04
CVE-2026-105222 published
CVE-2026-105222 was published with a CVSS score of 9.1, detailing a critical vulnerability in the google-maps Laravel package.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-105222 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of the package are affected?
The alexpechkarev/google-maps Laravel package through version 12.16 is affected.
What immediate actions should be taken?
Upgrade to a version that enables TLS certificate verification and review API key usage.
Is there any confirmed exploitation of this vulnerability?
No, there is currently no confirmed exploitation or proof-of-concept available.