← Back to CVE List
CVE-2026-105127NVD
Vulnerability Summary
LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.
CVSS v4.0 Base Metrics — Score 6.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityLow
Affected & Patched Versions
- laradashboard laradashboard >= 1.4.2 and < 1.4.8
- laradashboard laradashboard 1.4.8
External References
- https://github.com/laradashboard/laradashboard/security/advisories/GHSA-v36p-8578-8gch
- https://github.com/laradashboard/laradashboard/security/advisories/GHSA-5hq2-r2f3-9vp9
- https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ForgotPasswordRequest.php#L22-L27
- https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ResetPasswordRequest.php#L23-L30
- https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailVerificationService.php#L95-L114
- https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailDomainCheckService.php#L128
- https://github.com/laradashboard/laradashboard/pull/339
- https://github.com/laradashboard/laradashboard/commit/8babc803066a74c628fa012928fb1e6591411eba
- https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8
- https://github.com/laradashboard/laradashboard
- https://www.vulncheck.com/advisories/laradashboard-1.4.2-before-1.4.8-resource-exhaustion-via-password-recovery-endpoints