HackTesting
HomeArticlesTagsContact

CVE-2026-105127

LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.

Credits

EVIL0RD

References

https://github.com/laradashboard/laradashboard/security/advisories/GHSA-v36p-8578-8gch
https://github.com/laradashboard/laradashboard/security/advisories/GHSA-5hq2-r2f3-9vp9
https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ForgotPasswordRequest.php#L22-L27
https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ResetPasswordRequest.php#L23-L30
https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailVerificationService.php#L95-L114
https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailDomainCheckService.php#L128
https://github.com/laradashboard/laradashboard/pull/339
https://github.com/laradashboard/laradashboard/commit/8babc803066a74c628fa012928fb1e6591411eba
https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8
https://github.com/laradashboard/laradashboard
https://www.vulncheck.com/advisories/laradashboard-1.4.2-before-1.4.8-resource-exhaustion-via-password-recovery-endpoints
Published
Oct 3, 2026 23:40:00 UTC
Updated
Oct 3, 2026 23:40:00 UTC
Reserved
Oct 3, 2026 12:05:26 UTC
  • Home
  • Contact Us
  • Recently Updated CVEs
  • Articles
  • Tags
  • RSS Feed
  • Privacy Policy
© 2026 HackTesting. All rights reserved.