Record summary

CVE-2020-36950 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.

Description

Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List3.7.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBLaravel Nova 3.7.0 - 'range' DoSExploitDB exploitby iqzer0Not analyzed1 file
ExploitDB

PoC details

References

5