


Perceptive Security
SOC/SIEM Consultancy

MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that all…
Published:
30 juli 2026 om 00:00:00
Alert date:
30 juli 2026 om 18:04:07
Source:
nvd.nist.gov
Identity & Access, Web Technologies
MaxKey through version 4.1.12 contains an insufficient redirect URI validation vulnerability in the DefaultRedirectResolver.hostMatches() method. The flaw allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix matches a registered URI without proper dot-boundary anchoring. Attackers who control a domain ending with the registered redirect URI hostname can social-engineer victims into clicking a malicious authorization URL. This causes the authorization code to be issued to the attacker-controlled URI, which can then be exchanged for an access token. The access token grants the attacker access to the victim's identity. The vulnerability has been fixed in commit ddbb72f of the MaxKey repository.
Technical details
Mitigation steps:
Affected products:
MaxKey 4.1.12 and earlier
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67345
https://github.com/dromara/MaxKey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45
https://github.com/dromara/MaxKey/issues/269
https://www.vulncheck.com/advisories/maxkey-defaultredirectresolver-oauth-authorization-code-theft
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
