<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T04:01:11.699342+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318583</id>
    <title>EUVD-2026-318583</title>
    <updated>2026-10-06T04:01:11.748132+00:00</updated>
    <content>EUVD-2026-318583</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318583"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42349</id>
    <title>fkie_cve-2026-42349</title>
    <updated>2026-10-06T04:01:11.748176+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a gated action to proceed for a user who does not satisfy the full set of requested conditions. This call shape can be bypassed if certain conditions are met: a has() or auth.protect() call that combines a reverification check with any of role, permission, feature, or plan, or that combines a billing check (feature or plan) with a role or permission check. This vulnerability is fixed in  @clerk/clerk-js 5.125.10 and 6.7.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42349"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w24r-5266-9c3c</id>
    <title>GHSA-w24r-5266-9c3c — Clerk has an authorization bypass when combining organization, billing, or reverification checks</title>
    <updated>2026-10-06T04:01:11.748214+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @clerk/shared, npm: @clerk/backend, npm: @clerk/nextjs, npm: @clerk/clerk-js, npm: @clerk/clerk-react, npm: @clerk/react, npm: @clerk/vue, npm: @clerk/astro, npm: @clerk/nuxt, npm: @clerk/clerk-expo and 7 more</p>
<p>### Summary</p>
<p>`has()`, `auth.protect()`, and related authorization predicates in `@clerk/shared`, `@clerk/nextjs`, `@clerk/backend`, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a gated action to proceed for a user who does not satisfy the full set of requested conditions.</p>
<p>Sessions are not compromised and no existing user can be impersonated. The bypass is limited to the authorization decision returned by the predicate. `clerkMiddleware` continues to authenticate requests correctly, `auth()` reflects the real authentication state, and token verification is unaffected.</p>
<p>### Who is affected</p>
<p>All apps that combine more than one authorization dimension in a single `has()` or `auth.protect()` call should upgrade to the patched versions. Patches are drop-in with no API changes. The information below describes the scope of the bypass and helps developers understand whether their apps are potentially affected, but is not a reason to delay the upgrade.</p>
<p>This call shape can be bypassed if certain conditions are met: a `has()` or `auth.protect()` call that combines a `reverification` check with any of `role`, `permission`, `feature`, or `plan`, or that combines a billing check (`feature` or `plan`) with a role or permission check.</p>
<p>```ts
// Reverification combined with role / permission / feature / plan
await auth.protect({ permission: 'org:settings:delete', reverification: 'strict' });
const canAct = has(…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w24r-5266-9c3c"/>
  </entry>
</feed>
