CVE-2026-67345: Permissive List of Allowed Inputs in dromara MaxKey
MaxKey versions up to 4.1.12 contain a vulnerability in the OAuth 2.0 redirect URI validation logic. The DefaultRedirectResolver.hostMatches() method does not properly anchor hostname suffixes, allowing attackers controlling domains with suffixes matching registered redirect URIs to hijack authorization codes. This can lead to attackers obtaining access tokens and accessing victim identities. The issue was fixed in a commit after version 4.1.12. The vulnerability has a high severity with a CVSS score of 8.5.
AI Analysis
Technical Summary
MaxKey through version 4.1.12 has an insufficient redirect URI validation vulnerability in the DefaultRedirectResolver.hostMatches() function. The validation fails to enforce proper dot-boundary anchoring on hostname suffixes, enabling attackers who control a domain ending with the registered redirect URI hostname to craft authorization URLs that cause OAuth 2.0 authorization codes to be issued to attacker-controlled URIs. This allows attackers to exchange the authorization code for access tokens, potentially compromising victim identities. The vulnerability was fixed in a commit identified as ddbb72f, which is after version 4.1.12.
Potential Impact
An attacker who controls a domain with a hostname suffix matching a registered redirect URI can trick victims into clicking a crafted authorization URL. This results in the OAuth 2.0 authorization code being issued to the attacker-controlled URI. The attacker can then exchange the authorization code for an access token, gaining unauthorized access to the victim's identity information. This compromises the confidentiality and integrity of user authentication and authorization processes.
Mitigation Recommendations
A fix for this vulnerability is available in a commit identified as ddbb72f, which addresses the insufficient redirect URI validation. Users should upgrade to a version of MaxKey that includes this fix. Since the affected versions are up to and including 4.1.12, upgrading to any version after 4.1.12 that contains the fix is recommended. Patch status is not explicitly confirmed in the advisory, so users should verify the vendor's official release notes or advisories for the fixed version.
CVE-2026-67345: Permissive List of Allowed Inputs in dromara MaxKey
Description
MaxKey versions up to 4.1.12 contain a vulnerability in the OAuth 2.0 redirect URI validation logic. The DefaultRedirectResolver.hostMatches() method does not properly anchor hostname suffixes, allowing attackers controlling domains with suffixes matching registered redirect URIs to hijack authorization codes. This can lead to attackers obtaining access tokens and accessing victim identities. The issue was fixed in a commit after version 4.1.12. The vulnerability has a high severity with a CVSS score of 8.5.
CVSS v4.0
Score 8.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
MaxKey through version 4.1.12 has an insufficient redirect URI validation vulnerability in the DefaultRedirectResolver.hostMatches() function. The validation fails to enforce proper dot-boundary anchoring on hostname suffixes, enabling attackers who control a domain ending with the registered redirect URI hostname to craft authorization URLs that cause OAuth 2.0 authorization codes to be issued to attacker-controlled URIs. This allows attackers to exchange the authorization code for access tokens, potentially compromising victim identities. The vulnerability was fixed in a commit identified as ddbb72f, which is after version 4.1.12.
Potential Impact
An attacker who controls a domain with a hostname suffix matching a registered redirect URI can trick victims into clicking a crafted authorization URL. This results in the OAuth 2.0 authorization code being issued to the attacker-controlled URI. The attacker can then exchange the authorization code for an access token, gaining unauthorized access to the victim's identity information. This compromises the confidentiality and integrity of user authentication and authorization processes.
Mitigation Recommendations
A fix for this vulnerability is available in a commit identified as ddbb72f, which addresses the insufficient redirect URI validation. Users should upgrade to a version of MaxKey that includes this fix. Since the affected versions are up to and including 4.1.12, upgrading to any version after 4.1.12 that contains the fix is recommended. Patch status is not explicitly confirmed in the advisory, so users should verify the vendor's official release notes or advisories for the fixed version.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-29T13:09:45.993Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6b8fab9c2644c7f8731757
Added to database: 07/30/2026, 17:53:47 UTC
Last enriched: 07/30/2026, 18:07:07 UTC
Last updated: 07/30/2026, 18:12:48 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.