CVE-2026-67345

Source
https://cve.org/CVERecord?id=CVE-2026-67345
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67345.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-67345
Published
2026-07-30T14:39:13.577Z
Modified
2026-08-01T08:06:15.937622Z
Severity
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft
Details

MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix matches a registered URI without proper dot-boundary anchoring. Attackers who control a domain ending with the registered redirect URI hostname can social-engineer victims into clicking a crafted authorization URL, causing the authorization code to be issued to the attacker-controlled URI and exchanged for an access token granting access to the victim's identity.

Database specific
{
    "cwe_ids": [
        "CWE-183"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67345.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/dromara/maxkey

Affected ranges

Type
GIT
Repo
https://github.com/dromara/maxkey
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.1.12"
        }
    ]
}

Affected versions

3.*
3.5.11
3.5.12
3.5.14
3.5.15
3.5.16
3.5.17
3.5.18
3.5.19
4.*
4.0.0
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.1.10
4.1.11
4.1.12
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.1.9
v.*
v.1.2.1GA
v.1.2GA
v.1.3GA
v1.*
v1.4.0GA
v2.*
v2.0.0GA
v2.0.0RC1
v2.0.0RC2
v2.0.0RC3
v2.0.0RC5
v2.1.0GA
v2.1.0RC
v2.2.0GA
v2.2.0RC2
v2.3.0GA
v2.4.0GA
v2.4.0RC2
v2.5.0GA
v2.6.0GA
v2.7.0GA
v2.8.0GA
v2.8.0RC1
v2.8.1GA
v2.9.0GA
v2.9.0RC1
v3.*
v3.0.0GA
v3.1.0GA
v3.1.1GA
v3.2.0
v3.2.0GA
v3.3.0GA
v3.3.1GA
v3.3.2GA
v3.3.3GA
v3.5.0GA
v3.5.0RC
v3.5.10
v3.5.13
v3.5.1GA
v3.5.2GA
v3.5.3GA
v3.5.4GA
v3.5.5
v3.5.5GA
v3.5.6
v3.5.7
v3.5.8
v3.5.9
v3.5.9ga

Database specific

vanir_signatures_modified
"2026-08-01T08:06:15Z"
vanir_signatures
[
    {
        "signature_type": "Function",
        "target": {
            "file": "maxkey-protocols/maxkey-protocol-oauth-2.0/src/main/java/org/dromara/maxkey/authz/oauth2/provider/endpoint/DefaultRedirectResolver.java",
            "function": "hostMatches"
        },
        "deprecated": false,
        "source": "https://github.com/dromara/maxkey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45",
        "id": "CVE-2026-67345-4d6c364c",
        "signature_version": "v1",
        "digest": {
            "function_hash": "287585772765132522710139460860102708420",
            "length": 147.0
        }
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "maxkey-protocols/maxkey-protocol-oauth-2.0/src/main/java/org/dromara/maxkey/authz/oauth2/provider/endpoint/DefaultRedirectResolver.java",
            "function": "setMatchSubdomains"
        },
        "deprecated": false,
        "source": "https://github.com/dromara/maxkey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45",
        "id": "CVE-2026-67345-c97db32e",
        "signature_version": "v1",
        "digest": {
            "function_hash": "188136250604559453682289204246208760068",
            "length": 57.0
        }
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "maxkey-protocols/maxkey-protocol-oauth-2.0/src/main/java/org/dromara/maxkey/authz/oauth2/provider/endpoint/DefaultRedirectResolver.java"
        },
        "deprecated": false,
        "source": "https://github.com/dromara/maxkey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45",
        "id": "CVE-2026-67345-ca67d345",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "38637543247145702219091304799434618326",
                "172781858488998338174801995593525759215",
                "177435896602084273933368745346724103788",
                "18166653487348395528859802906914124926",
                "172110309762217062769022754769746667407",
                "92437229593070574272090375540635769228",
                "216483213234058914964045917949104757015",
                "201356060067639613504028734947336966917",
                "36555837475947430869975421529726659438",
                "16168487373566756704410185613341309373",
                "241611231070522369960257327495177804949",
                "337153961504811810864137275789434211501",
                "238298155245927721710647091651773130868",
                "18160314448009251623615611930836328089"
            ],
            "threshold": 0.9
        }
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67345.json"