Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-27 16:16
Updated : 2026-01-29 16:31
NVD link : CVE-2020-36950
Mitre link : CVE-2020-36950
CVE.ORG link : CVE-2020-36950
JSON object : View
Products Affected
No product.
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
