Applications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events.
@clerk/backend: the helper has been patched as of 2.4.0@clerk/astro: the helper has been patched as of 2.10.2@clerk/express: the helper has been patched as of 1.7.4@clerk/fastify: the helper has been patched as of 2.4.4@clerk/nextjs: the helper has been patched as of 6.23.3@clerk/nuxt: the helper has been patched as of 1.7.5@clerk/react-router: the helper has been patched as of 1.6.4@clerk/remix: the helper has been patched as of 4.8.5@clerk/tanstack-react-start: the helper has been patched as of 0.18.3The issue was resolved in @clerk/backend 2.4.0 by:
If unable to upgrade, developers can workaround this issue by verifying webhooks manually, per this documentation.
{
"cwe_ids": [
"CWE-345"
],
"github_reviewed": true,
"github_reviewed_at": "2025-07-09T18:07:40Z",
"nvd_published_at": "2025-07-09T18:15:24Z",
"severity": "HIGH"
}