OAuth2 redirect_uri mismatch allows callback interception
ID: security/oauth2-redirect-uri-mismatch-allows-callback-interception
Version Compatibility
| Version | Status | Introduced | Deprecated | Notes |
|---|---|---|---|---|
| OAuth2.0 | active | — | — | — |
| Spring Security 5.6+ | active | — | — | — |
| Keycloak 21.0.0 | active | — | — | — |
| Okta 2023.09.0 | active | — | — | — |
Root Cause
When the redirect_uri in an OAuth2 authorization request does not match the registered callback URL, an attacker can intercept the authorization code by using a different redirect URI that they control.
generic中文
当OAuth2授权请求中的redirect_uri与注册的回调URL不匹配时,攻击者可以通过使用他们控制的不同重定向URI来拦截授权代码。
Official Documentation
https://datatracker.ietf.org/doc/html/rfc6749#section-3.1.2Workarounds
-
95% success Register exact redirect URIs on the authorization server (e.g., https://myapp.com/callback) and validate that the request's redirect_uri matches exactly, including path and query parameters. Example in Keycloak: in client settings, set 'Valid Redirect URIs' to 'https://myapp.com/callback' without wildcards.
Register exact redirect URIs on the authorization server (e.g., https://myapp.com/callback) and validate that the request's redirect_uri matches exactly, including path and query parameters. Example in Keycloak: in client settings, set 'Valid Redirect URIs' to 'https://myapp.com/callback' without wildcards.
-
90% success Implement strict redirect URI validation on the client side: compare the received redirect URI against a whitelist of allowed URIs before processing the authorization code.
Implement strict redirect URI validation on the client side: compare the received redirect URI against a whitelist of allowed URIs before processing the authorization code.
-
88% success Use PKCE in combination with exact redirect URI matching to prevent interception even if the redirect URI is slightly different.
Use PKCE in combination with exact redirect URI matching to prevent interception even if the redirect URI is slightly different.
中文步骤
Register exact redirect URIs on the authorization server (e.g., https://myapp.com/callback) and validate that the request's redirect_uri matches exactly, including path and query parameters. Example in Keycloak: in client settings, set 'Valid Redirect URIs' to 'https://myapp.com/callback' without wildcards.
Implement strict redirect URI validation on the client side: compare the received redirect URI against a whitelist of allowed URIs before processing the authorization code.
Use PKCE in combination with exact redirect URI matching to prevent interception even if the redirect URI is slightly different.
Dead Ends
Common approaches that don't work:
-
75% fail
Using a wildcard in the registered redirect URI (e.g., https://*.example.com) allows attackers to register a subdomain they control, intercepting the code.
-
65% fail
Allowing redirect URIs with different paths but same host is insufficient because attackers can use a path they control (e.g., /attacker-callback).
-
60% fail
Validating only the hostname but not the path or query parameters leaves the system vulnerable to path-based interception.