CVE-2026-105127

Source
https://cve.org/CVERecord?id=CVE-2026-105127
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105127.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105127
Related
Published
2026-10-03T23:40:00Z
Modified
2026-10-06T02:30:28Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints
Details

LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-770"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105127.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "1.4.2"
                },
                {
                    "fixed":  "1.4.8"
                }
            ],
            "source":  "AFFECTED_FIELD"
        },
        {
            "extracted_events":  [
                {
                    "fixed":  "1.4.8"
                }
            ],
            "source":  "CPE_FIELD"
        },
        {
            "extracted_events":  [
                {
                    "introduced":  "1.4.2"
                },
                {
                    "fixed":  "1.4.8"
                }
            ],
            "source":  "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/laradashboard/laradashboard

Affected ranges

Type
GIT
Repo
https://github.com/laradashboard/laradashboard
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source":  "REFERENCES"
}

Affected versions

Other
Day1
Day10
Day2
Day3
Day4
Day5
Day6
Day7
Day8
Day9
Laravel11.*
Laravel11.x
Laravel12.*
Laravel12.x-module-logs
Laravel12.x-tailadmin
Laravel7.*
Laravel7.x
Laravel9.*
Laravel9.x
v0.*
v0.9.0
v0.9.10
v0.9.11
v0.9.12
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.9
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.1.0
v1.1.5
v1.2.0
v1.2.1
v1.3.0
v1.3.1
v1.3.2
v1.4.0
v1.4.2
v1.4.5
v1.5.0
v1.5.1
v1.6.0
v11.*
v11.x-main
v2.*
v2.0.1
v2.1.0
v2.2.0
v2.3.0
v2.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105127.json"