CVE-2026-41248Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers. This vulnerability is fixed in @clerk/astro 1.5.7, 2.17.10, and 3.0.15; @clerk/nextjs 5.7.6, 6.39.2, and 7.2.1; @clerk/nuxt 1.13.28 and 2.2.2; and @clerk/shared 2.22.1, 3.47.4, anc 4.8.1

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-436CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: rising

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-05-21)
  • 8 total mentions across 6 days

Deep dive

Activity timeline8 mentions / 6d
01223Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-04-27: 1Mentions · 2026-04-30: 1Mentions · 2026-05-01: 1Mentions · 2026-05-21: 3Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-30: 104-2404-2504-2704-3005-0105-21
Signal classification3 categories
Disclosure
675.0%
Patch
112.5%
General
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-251
Disclosure1
2026-04-271
Patch1
2026-04-301
Disclosure1
2026-05-011
General1
2026-05-213
Disclosure3
Full discourse8 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Clerk Auth Bypass: Middleware Gating Fails Across Next.js, Nuxt, Astro (CVE-2026-41248) Clerk published security advisories on April 24, 2026, disclosing CVE-2026-41248, a critical vulnerability in its official JavaScript authentication library.

    Post summary

    Clerk’s advisory publicly discloses CVE-2026-41248, a critical flaw in its JavaScript authentication library, without providing PoC, exploit, or patch details.

    1000043
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Clerk published security advisories on April 24, 2026, disclosing CVE-2026-41248, a critical vulnerability in its official JavaScript authentication library. The flaw affects the routing middleware used by thousands of developers building modern web applications with…

    Post summary

    Clerk announced a critical vulnerability (CVE-2026-41248) in its JavaScript authentication library affecting routing middleware, but no further detail on exploits, patches, or technical specifics was provided.

    1000030
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    24, 2026, — Clerk Auth Bypass: Middleware Gating Fails Across Next.js, Nuxt, Astro (CVE-2026-41248). Clerk published security advisories on April 24, 2026, disclosing CVE-2026-41248, a critical vulnerability in its official JavaScript authentication library.

    Post summary

    Clerk announced CVE‑2026‑41248 as a critical flaw in its JavaScript authentication library, without providing PoC, exploit code, or remedial guidance.

    1000043
    227 followersView on X
  • selva@SelvaKtm2
    General

    CVE-2026-41248: Clerk SDK Auth Bypass Exposes Millions of Web Apps https://thecybrdef.com/cve-2026-41248-clerk-sdk-auth-bypass/

    Post summary

    The provided text only names the CVE and a headline, offering no additional context or technical information.

    0000024
    4 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-41248: Clerk SDK Auth Bypass Exposes Millions of Web Apps https://thecybrdef.com/cve-2026-41248-clerk-sdk-auth-bypass/

    Post summary

    The headline announces a disclosure of CVE‑2026‑41248, detailing an authentication bypass in the Clerk SDK that could impact millions of web apps, but no exploit, patch, or active exploitation information is given.

    0000022
    8 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical function bypass vulnerability in #Clerk authentication. CVE-2026-41248 CVSS: 9.1. This can lead to functions being bypassed by certain crafted requests. #Patch #Patch #Patch

    Post summary

    A high‑severity function bypass vulnerability (CVE‑2026‑41248) in Clerk authentication is announced with a CVSS score of 9.1, and the post urges users to apply a patch, though no PoC or exploitation evidence is provided.

    00000180
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41248 Middleware Bypass in Clerk JavaScript Authentication Libraries via createRouteMatcher https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41248

    Post summary

    The post announces CVE-2026-41248 as a middleware bypass in Clerk JavaScript authentication libraries through the createRouteMatcher function, but it offers no PoC, exploit code, active exploitation info, patches, or debunking details.

    0000040
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41248 Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by… https://www.cve.org/CVERecord?id=CVE-2026-41248

    Post summary

    The text announces CVE‑2026‑41248 and notes a bypass of Clerk’s createRouteMatcher in several frameworks, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000073
    57.2K followersView on X

Explore more