VYPR

MaxKey

by Dromara

CVEs (1)

  • CVE-2026-67345Jul 30, 2026
    risk 0.00cvss epss 0.00

    MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix…