logo

Critical 9.1 CVSS Bypass in Clerk’s Middleware Gating

ID: ea566abd-82a5-5ba0-b35f-c7d5f8bad2be

STIX ID: report--ea566abd-82a5-5ba0-b35f-c7d5f8bad2be

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-20

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical CVSS 9.1 vulnerability in Clerk's createRouteMatcher can let crafted requests bypass middleware gating in Next.js, Nuxt, Astro and other frameworks, potentially allowing unauthorized traffic to reach downstream handlers. Clerk confirms sessions and authentication state are not compromised, has released drop-in fixes across affected packages, and recommends adding server-side auth() checks as a defense-in-depth mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.