top of page
perceptive_background_267k.jpg

MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that all…

Published:

30 juli 2026 om 00:00:00

Alert date:

30 juli 2026 om 18:04:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Identity & Access, Web Technologies

MaxKey through version 4.1.12 contains an insufficient redirect URI validation vulnerability in the DefaultRedirectResolver.hostMatches() method. The flaw allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix matches a registered URI without proper dot-boundary anchoring. Attackers who control a domain ending with the registered redirect URI hostname can social-engineer victims into clicking a malicious authorization URL. This causes the authorization code to be issued to the attacker-controlled URI, which can then be exchanged for an access token. The access token grants the attacker access to the victim's identity. The vulnerability has been fixed in commit ddbb72f of the MaxKey repository.

Technical details

Mitigation steps:

Affected products:

MaxKey 4.1.12 and earlier

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page