Package impact
npm / @clerk/express
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-42349 | high | 8.1 | 8.1 | 23d ago | Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other… | |||
| CVE-2026-34076 | high | 7.4 | 7.4 | 2mo ago | Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host | |||
| CVE-2025-53548 | unknown | — | — | 11mo ago | @clerk/backend Performs Insufficient Verification of Data Authenticity |