{"id":"CVE-2026-67345","summary":"MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft","details":"MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix matches a registered URI without proper dot-boundary anchoring. Attackers who control a domain ending with the registered redirect URI hostname can social-engineer victims into clicking a crafted authorization URL, causing the authorization code to be issued to the attacker-controlled URI and exchanged for an access token granting access to the victim's identity.","modified":"2026-08-15T09:53:24.780099Z","published":"2026-07-30T14:39:13.577Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-183"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67345.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67345.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67345"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/maxkey-defaultredirectresolver-oauth-authorization-code-theft"},{"type":"REPORT","url":"https://github.com/dromara/MaxKey/issues/269"},{"type":"FIX","url":"https://github.com/dromara/MaxKey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45"},{"type":"PACKAGE","url":"https://github.com/dromara/MaxKey"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dromara/maxkey","events":[{"introduced":"0"},{"fixed":"3a3a5c7657d0034fe6cf8a96d469bc2828d70072"},{"fixed":"ddbb72fb24ab8e66aa422fb14b1177330bcffb45"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"4.1.12"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["4.1.12","4.1.11","4.1.10","4.1.9","4.1.8","4.1.7","4.1.6","4.1.5","4.1.4","4.1.3","4.1.2","4.0.5","4.1.1","4.1.0","4.0.4","4.0.3","4.0.2","4.0.0","3.5.19","3.5.18","3.5.17","3.5.16","3.5.15","3.5.14","v3.5.13","3.5.12","3.5.11","v3.5.10","v3.5.9ga","v3.5.9","v3.5.8","v3.5.7","v3.5.6","v3.5.5GA","v3.5.5","v3.5.4GA","v3.5.3GA","v3.5.2GA","v3.5.1GA","v3.5.0GA","v3.5.0RC","v3.3.3GA","v3.3.2GA","v3.3.1GA","v3.3.0GA","v3.2.0","v3.2.0GA","v3.1.1GA","v3.1.0GA","v3.0.0GA","v2.9.0GA","v2.9.0RC1","v2.8.1GA","v2.8.0GA","v2.8.0RC1","v2.7.0GA","v2.6.0GA","v2.5.0GA","v2.4.0GA","v2.4.0RC2","v2.3.0GA","v2.2.0GA","v2.2.0RC2","v2.1.0RC","v2.1.0GA","v2.0.0GA","v2.0.0RC5","v2.0.0RC3","v2.0.0RC2","v2.0.0RC1","v1.4.0GA","v.1.3GA","v.1.2.1GA","v.1.2GA"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67345.json","vanir_signatures_modified":"2026-08-15T09:53:24Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/dromara/maxkey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45","target":{"file":"maxkey-protocols/maxkey-protocol-oauth-2.0/src/main/java/org/dromara/maxkey/authz/oauth2/provider/endpoint/DefaultRedirectResolver.java","function":"hostMatches"},"deprecated":false,"digest":{"function_hash":"287585772765132522710139460860102708420","length":147},"id":"CVE-2026-67345-4d6c364c","signature_type":"Function"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/dromara/maxkey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45","target":{"file":"maxkey-protocols/maxkey-protocol-oauth-2.0/src/main/java/org/dromara/maxkey/authz/oauth2/provider/endpoint/DefaultRedirectResolver.java","function":"setMatchSubdomains"},"deprecated":false,"digest":{"function_hash":"188136250604559453682289204246208760068","length":57},"id":"CVE-2026-67345-c97db32e"},{"deprecated":false,"digest":{"line_hashes":["38637543247145702219091304799434618326","172781858488998338174801995593525759215","177435896602084273933368745346724103788","18166653487348395528859802906914124926","172110309762217062769022754769746667407","92437229593070574272090375540635769228","216483213234058914964045917949104757015","201356060067639613504028734947336966917","36555837475947430869975421529726659438","16168487373566756704410185613341309373","241611231070522369960257327495177804949","337153961504811810864137275789434211501","238298155245927721710647091651773130868","18160314448009251623615611930836328089"],"threshold":0.9},"id":"CVE-2026-67345-ca67d345","signature_type":"Line","signature_version":"v1","source":"https://github.com/dromara/maxkey/commit/ddbb72fb24ab8e66aa422fb14b1177330bcffb45","target":{"file":"maxkey-protocols/maxkey-protocol-oauth-2.0/src/main/java/org/dromara/maxkey/authz/oauth2/provider/endpoint/DefaultRedirectResolver.java"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}