Critical 9.1 CVSS Bypass in Clerk’s Middleware Gating
ID: ea566abd-82a5-5ba0-b35f-c7d5f8bad2be
STIX ID: report--ea566abd-82a5-5ba0-b35f-c7d5f8bad2be
Feed Name: securityonline.info
Threat Score
A critical CVSS 9.1 vulnerability in Clerk's createRouteMatcher can let crafted requests bypass middleware gating in Next.js, Nuxt, Astro and other frameworks, potentially allowing unauthorized traffic to reach downstream handlers. Clerk confirms sessions and authentication state are not compromised, has released drop-in fixes across affected packages, and recommends adding server-side auth() checks as a defense-in-depth mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
