clerk CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

clerk vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to clerk, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-42349 Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a gated action to proceed for a user who does not satisfy the full set of requested conditions. This call shape can be bypassed if certain conditions are met: a has() or auth.protect() [email protected] 7.6 0.05% 2026-05-11 2026-06-01
CVE-2024-22206 Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in the Pages Router. This vulnerability was patched in version 4.29.3. [email protected] 9.0 0.26% 2024-01-12 2024-11-21
CVE-2022-3907 The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options. [email protected] 7.5 0.58% 2022-12-05 2025-04-23
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence