GHSA-vqx2-fgx2-5wq9

Suggest an improvement
Source
https://github.com/advisories/GHSA-vqx2-fgx2-5wq9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vqx2-fgx2-5wq9/GHSA-vqx2-fgx2-5wq9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vqx2-fgx2-5wq9
Aliases
  • CVE-2026-41248
Published
2026-04-16T21:28:26Z
Modified
2026-05-05T16:11:29.169574Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Official Clerk JavaScript SDKs: Middleware-based route protection bypass
Details

Summary

createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers.

Sessions are not compromised and no existing user can be impersonated - the bypass only affects the middleware-level gating decision.

Who is affected

All apps using createRouteMatcher should upgrade to the patched versions. Patches are drop-in with no API changes. The information below describes the scope of the bypass and helps you understand whether you are potentially affected, but is not a reason to delay the upgrade.

Apps relying only on middleware gating via createRouteMatcher are affected, because a crafted request can skip middleware checks and reach downstream handlers (API routes, server components, etc.). This middleware pattern permits the bypass:

// Next.js example, equivalent patterns exist in Nuxt and Astro
const isProtectedRoute = createRouteMatcher(['/admin(.*)']);

export default clerkMiddleware(async (auth, req) => {
  if (isProtectedRoute(req)) {
    await auth.protect();
  }
});

That said, the bypass is limited to the middleware-level route-matching gate. clerkMiddleware still authenticates the request and auth() reflects the real authentication state of the caller. Auth checks performed inside your route handlers, server components, or server actions continue to work correctly and are not affected. Whether your app is affected in practice depends on whether you have those downstream checks.

External APIs that authenticate each request with a token are also unaffected on those endpoints, since token verification runs independently.

Additionally, this common middleware pattern correctly blocks the bypass at the middleware layer:

// Next.js example, equivalent patterns exist in Nuxt and Astro
const isPublicRoute = createRouteMatcher(['/docs(.*)']);

export default clerkMiddleware(async (auth, req) => {
  if (!isPublicRoute(req)) {
    await auth.protect();
  }
});

@clerk/shared is usually not imported directly in application code, but if you import createPathMatcher from an affected @clerk/shared version, you are also affected. Run npm why @clerk/shared (or your package manager's equivalent) to check your installed version.

Recommended actions

Install the patched version for your framework (pick the one matching your current major):

@clerk/nextjs - v7.x: fixed in 7.2.1 - v6.x: fixed in 6.39.2 - v5.x: fixed in 5.7.6

@clerk/nuxt - v2.x: fixed in 2.2.2 - v1.x: fixed in 1.13.28

@clerk/astro - v3.x: fixed in 3.0.15 - v2.x: fixed in 2.17.10 - v1.x: fixed in 1.5.7

@clerk/shared - v4.x: fixed in 4.8.1 - v3.x: fixed in 3.47.4 - v2.x: fixed in 2.22.1

Workaround

If you cannot upgrade immediately, adding server-side auth checks (auth()) inside your route handlers, server components, or server actions provides defense-in-depth against this bypass.

Timeline

This issue was reported on 13 APR 2026, patched on 15 APR 2026, and publicly disclosed on 15 APR 2026.

Thanks to Christiaan Swiers for the responsible disclosure of this vulnerability.

Database specific
{
    "nvd_published_at": "2026-04-24T21:16:18Z",
    "severity": "CRITICAL",
    "cwe_ids": [
        "CWE-436",
        "CWE-863"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-04-16T21:28:26Z"
}
References

Affected packages

npm
@clerk/nextjs

Package

Name
@clerk/nextjs
View open source insights on deps.dev
Purl
pkg:npm/%40clerk/nextjs

Affected ranges

Type
SEMVER
Events
Introduced
5.0.0
Fixed
5.7.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vqx2-fgx2-5wq9/GHSA-vqx2-fgx2-5wq9.json"
@clerk/nuxt

Package

Name
@clerk/nuxt
View open source insights on deps.dev
Purl
pkg:npm/%40clerk/nuxt

Affected ranges

Type
SEMVER
Events
Introduced
1.1.0
Fixed
1.13.28

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vqx2-fgx2-5wq9/GHSA-vqx2-fgx2-5wq9.json"
@clerk/astro

Package

Name
@clerk/astro
View open source insights on deps.dev
Purl
pkg:npm/%40clerk/astro

Affected ranges

Type
SEMVER
Events
Introduced
0.0.1
Fixed
1.5.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vqx2-fgx2-5wq9/GHSA-vqx2-fgx2-5wq9.json"
@clerk/shared

Package

Name
@clerk/shared
View open source insights on deps.dev
Purl
pkg:npm/%40clerk/shared

Affected ranges

Type
SEMVER
Events
Introduced
2.20.17
Fixed
2.22.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vqx2-fgx2-5wq9/GHSA-vqx2-fgx2-5wq9.json"
@clerk/nextjs

Package

Name
@clerk/nextjs
View open source insights on deps.dev
Purl
pkg:npm/%40clerk/nextjs

Affected ranges

Type
SEMVER
Events
Introduced
6.0.0-snapshot.vb87a27f
Fixed
6.39.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vqx2-fgx2-5wq9/GHSA-vqx2-fgx2-5wq9.json"
@clerk/nextjs

Package

Name
@clerk/nextjs
View open source insights on deps.dev
Purl
pkg:npm/%40clerk/nextjs

Affected ranges

Type
SEMVER
Events
Introduced
7.0.0
Fixed
7.2.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vqx2-fgx2-5wq9/GHSA-vqx2-fgx2-5wq9.json"
@clerk/nuxt

Package

Name
@clerk/nuxt
View open source insights on deps.dev
Purl
pkg:npm/%40clerk/nuxt

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0
Fixed
2.2.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vqx2-fgx2-5wq9/GHSA-vqx2-fgx2-5wq9.json"
@clerk/astro

Package

Name
@clerk/astro
View open source insights on deps.dev
Purl
pkg:npm/%40clerk/astro

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0-snapshot.v20241206174604
Fixed
2.17.10

Database specific

last_known_affected_version_range
"<= 2.17.9"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vqx2-fgx2-5wq9/GHSA-vqx2-fgx2-5wq9.json"
@clerk/astro

Package

Name
@clerk/astro
View open source insights on deps.dev
Purl
pkg:npm/%40clerk/astro

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.0.15

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vqx2-fgx2-5wq9/GHSA-vqx2-fgx2-5wq9.json"
@clerk/shared

Package

Name
@clerk/shared
View open source insights on deps.dev
Purl
pkg:npm/%40clerk/shared

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0-canary.v20250225091530
Fixed
3.47.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vqx2-fgx2-5wq9/GHSA-vqx2-fgx2-5wq9.json"
@clerk/shared

Package

Name
@clerk/shared
View open source insights on deps.dev
Purl
pkg:npm/%40clerk/shared

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0
Fixed
4.8.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-vqx2-fgx2-5wq9/GHSA-vqx2-fgx2-5wq9.json"