Laravel Nova Official Homepageproduct
https://nova.laravel.com/ CVE-2020-36950
HIGH
Laravel Nova 3.7.0 - 'range' DoS
Record summary
CVE-2020-36950 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Laravel NovaBrowse Laravel Holdings Inc. / Laravel Nova | CVE List | 3.7.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBLaravel Nova 3.7.0 - 'range' DoSExploitDB exploitby iqzer0Not analyzed1 file
References
5Laravel Nova Releases Pagepatch
https://nova.laravel.com/releases nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-36950 ExploitDB-49198exploit
https://www.exploit-db.com/exploits/49198 VulnCheck Advisory: Laravel Nova 3.7.0 - 'range' DoSThird-party advisory
https://www.vulncheck.com/advisories/laravel-nova-range-dos