MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix matches a registered URI without proper dot-boundary anchoring. Attackers who control a domain ending with the registered redirect URI hostname can social-engineer victims into clicking a crafted authorization URL, causing the authorization code to be issued to the attacker-controlled URI and exchanged for an access token granting access to the victim's identity.
{
"cwe_ids": [
"CWE-183"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67345.json",
"cna_assigner": "VulnCheck"
}"2026-08-01T08:06:15Z"
[
{
"signature_type": "Function",
"target": {
"file": "maxkey-protocols/maxkey-protocol-oauth-2.0/src/main/java/org/dromara/maxkey/authz/oauth2/provider/endpoint/DefaultRedirectResolver.java",
"function": "hostMatches"
},
"deprecated": false,
"source": "https://github.com/dromara/maxkey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45",
"id": "CVE-2026-67345-4d6c364c",
"signature_version": "v1",
"digest": {
"function_hash": "287585772765132522710139460860102708420",
"length": 147.0
}
},
{
"signature_type": "Function",
"target": {
"file": "maxkey-protocols/maxkey-protocol-oauth-2.0/src/main/java/org/dromara/maxkey/authz/oauth2/provider/endpoint/DefaultRedirectResolver.java",
"function": "setMatchSubdomains"
},
"deprecated": false,
"source": "https://github.com/dromara/maxkey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45",
"id": "CVE-2026-67345-c97db32e",
"signature_version": "v1",
"digest": {
"function_hash": "188136250604559453682289204246208760068",
"length": 57.0
}
},
{
"signature_type": "Line",
"target": {
"file": "maxkey-protocols/maxkey-protocol-oauth-2.0/src/main/java/org/dromara/maxkey/authz/oauth2/provider/endpoint/DefaultRedirectResolver.java"
},
"deprecated": false,
"source": "https://github.com/dromara/maxkey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45",
"id": "CVE-2026-67345-ca67d345",
"signature_version": "v1",
"digest": {
"line_hashes": [
"38637543247145702219091304799434618326",
"172781858488998338174801995593525759215",
"177435896602084273933368745346724103788",
"18166653487348395528859802906914124926",
"172110309762217062769022754769746667407",
"92437229593070574272090375540635769228",
"216483213234058914964045917949104757015",
"201356060067639613504028734947336966917",
"36555837475947430869975421529726659438",
"16168487373566756704410185613341309373",
"241611231070522369960257327495177804949",
"337153961504811810864137275789434211501",
"238298155245927721710647091651773130868",
"18160314448009251623615611930836328089"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67345.json"