CVE-2020-36950: Laravel Nova 3.7.0 - 'range' DoS
Published Jan 27, 2026
·Updated
Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server.
Affected Software
1 affected component
Laravel Nova
Event History
Jan 27, 2026
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-36950?
CVE-2020-36950 is classified as a denial of service vulnerability that can severely impact application availability.
2
How do I fix CVE-2020-36950?
To mitigate CVE-2020-36950, update Laravel Nova to version 3.7.1 or later where the vulnerability is addressed.
3
Who is affected by CVE-2020-36950?
CVE-2020-36950 affects users of Laravel Nova version 3.7.0.
4
Can unauthenticated users exploit CVE-2020-36950?
No, CVE-2020-36950 requires authentication to exploit the denial of service condition.
5
What kind of attack does CVE-2020-36950 enable?
CVE-2020-36950 allows authenticated users to crash the application by sending high range values in requests.