What is CVE-2026-67345?
MaxKey through version 4.1.12 contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches(). This allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix matches a registered one. Administrators should immediately apply the fix from commit ddbb72f.
Azərbaycanca: MaxKey platformasının 4.1.12-ə qədər olan versiyalarında DefaultRedirectResolver.hostMatches() funksiyasında yetərsiz redirect URI doğrulaması aşkarlanıb. Bu, uzaqdan hücum edənə xüsusi hazırlanmış redirect_uri vasitəsilə OAuth 2.0 avtorizasiya kodlarını ələ keçirməyə imkan verir. Xidmət sahibləri dərhal ddbb72f commit-i ilə yenilənməlidir.
FAQ2
Which versions of MaxKey are affected by this vulnerability?
All versions of MaxKey through 4.1.12 are affected by this vulnerability.
How can an attacker hijack OAuth 2.0 authorization codes?
A remote attacker can hijack codes by supplying a crafted redirect_uri whose hostname suffix matches a registered one, exploiting the insufficient validation in the DefaultRedirectResolver.hostMatches() function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.