CVE-2020-36950 HIGH

CVE-2020-36950: Laravel Nova 3.7.0 - 'range' DoS

Vendor Laravel Holdings Inc.
Product Laravel Nova
Weakness CWE-770 · Uncontrolled resource consumption
Published January 27, 2026
Last update April 7, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

Description

Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server.

Key dates

Disclosure timeline

January 27, 2026 CVE published
April 7, 2026 Record updated