VYPR

Maxkey

by Maxkey

CVEs (2)

  • CVE-2026-67345HigJul 30, 2026
    risk 0.46cvss 8.1epss 0.00

    MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix…

  • CVE-2025-6517MedJun 23, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add of the file maxkey-webs\maxkey-web-mgt\src\main\java\org\dromara\maxkey\web\apps\contorller\SAML20DetailsController.java of the component Meta URL Handler. The…