CVE-2026-105127mediumCWE-770

CVE-2026-105127: medium-severity vulnerability in laradashboard

LaraDashboard 1.4.2 before 1.4.8 Resource Exhaustion via Password Recovery Endpoints

Published · Updated

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.9epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N