{"id":"CVE-2026-67345","summary":"MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft","details":"MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix matches a registered URI without proper dot-boundary anchoring. Attackers who control a domain ending with the registered redirect URI hostname can social-engineer victims into clicking a crafted authorization URL, causing the authorization code to be issued to the attacker-controlled URI and exchanged for an access token granting access to the victim's identity.","modified":"2026-08-04T11:49:17.702433766Z","published":"2026-07-30T14:39:13.577Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-183"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67345.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67345.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67345"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/maxkey-defaultredirectresolver-oauth-authorization-code-theft"},{"type":"REPORT","url":"https://github.com/dromara/MaxKey/issues/269"},{"type":"FIX","url":"https://github.com/dromara/MaxKey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45"},{"type":"PACKAGE","url":"https://github.com/dromara/MaxKey"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dromara/maxkey","events":[{"introduced":"0"},{"last_affected":"3a3a5c7657d0034fe6cf8a96d469bc2828d70072"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"4.1.12"}],"source":"AFFECTED_FIELD"}}],"versions":["4.1.12","4.1.11","4.1.10","4.1.9","4.1.8","4.1.7","4.1.6","4.1.5","4.1.4","4.1.3","4.1.2","4.0.5","4.1.1","4.1.0","4.0.4","4.0.3","4.0.2","4.0.0","3.5.19","3.5.18","3.5.17","3.5.16","3.5.15","3.5.14","v3.5.13","3.5.12","3.5.11","v3.5.10","v3.5.9ga","v3.5.9","v3.5.8","v3.5.7","v3.5.6","v3.5.5GA","v3.5.5","v3.5.4GA","v3.5.3GA","v3.5.2GA","v3.5.1GA","v3.5.0GA","v3.5.0RC","v3.3.3GA","v3.3.2GA","v3.3.1GA","v3.3.0GA","v3.2.0","v3.2.0GA","v3.1.1GA","v3.1.0GA","v3.0.0GA","v2.9.0GA","v2.9.0RC1","v2.8.1GA","v2.8.0GA","v2.8.0RC1","v2.7.0GA","v2.6.0GA","v2.5.0GA","v2.4.0GA","v2.4.0RC2","v2.3.0GA","v2.2.0GA","v2.2.0RC2","v2.1.0RC","v2.1.0GA","v2.0.0GA","v2.0.0RC5","v2.0.0RC3","v2.0.0RC2","v2.0.0RC1","v1.4.0GA","v.1.3GA","v.1.2.1GA","v.1.2GA"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67345.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}