๐Ÿ” CVE Alert

CVE-2026-67345

HIGH 8.1

MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix matches a registered URI without proper dot-boundary anchoring. Attackers who control a domain ending with the registered redirect URI hostname can social-engineer victims into clicking a crafted authorization URL, causing the authorization code to be issued to the attacker-controlled URI and exchanged for an access token granting access to the victim's identity.

CWE CWE-183
Vendor dromara
Product maxkey
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for dromara maxkey

Be the first to know when new high vulnerabilities affecting dromara maxkey are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

dromara / MaxKey
0 โ‰ค 4.1.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dromara/MaxKey/issues/269 github.com: https://github.com/dromara/MaxKey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45 vulncheck.com: https://www.vulncheck.com/advisories/maxkey-defaultredirectresolver-oauth-authorization-code-theft

Credits

George Chen