CVE-2026-67345 | dromara MaxKey up to 4.1.12 Redirect URI Validation DefaultRedirectResolver.hostMatches redirect_uri

SecurityVulns

A vulnerability marked as problematic has been reported in dromara MaxKey up to 4.1.12. Impacted is the function DefaultRedirectResolver.hostMatches of the component Redirect URI Validation. This manipulation of the argument redirect_uri causes open redirect.

The identification of this vulnerability is CVE-2026-67345. It is possible to initiate the attack remotely. There is no exploit available.

Applying a patch is the recommended action to fix this issue.VulDB Recent EntriesRead More