<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 00:12:03 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-278520</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-278520</link>
      <description>EUVD-2026-278520</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-278520</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34076</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34076</link>
      <description>&lt;p&gt;Clerk JavaScript is the official JavaScript repository for Clerk authentication. In @clerk/hono from versions 0.1.0 to before 0.1.5, @clerk/express from versions 2.0.0 to before 2.0.7, @clerk/backend from versions 3.0.0 to before 3.2.3, and @clerk/fastify from versions 3.1.0 to before 3.1.5, the clerkFrontendApiProxy function in @clerk/backend is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can craft a request path that causes the proxy to send the application&amp;#39;s Clerk-Secret-Key to an attacker-controlled server. This issue has been patched in @clerk/hono version 0.1.5, @clerk/express version 2.0.7, @clerk/backend version 3.2.3, and @clerk/fastify version 3.1.5.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Clerk JavaScript is the official JavaScript repository for Clerk authentication. In @clerk/hono from versions 0.1.0 to before 0.1.5, @clerk/express from versions 2.0.0 to before 2.0.7, @clerk/backend from versions 3.0.0 to before 3.2.3, and @clerk/fastify from versions 3.1.0 to before 3.1.5, the clerkFrontendApiProxy function in @clerk/backend is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can craft a request path that causes the proxy to send the application&amp;#39;s Clerk-Secret-Key to an attacker-controlled server. This issue has been patched in @clerk/hono version 0.1.5, @clerk/express version 2.0.7, @clerk/backend version 3.2.3, and @clerk/fastify version 3.1.5.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34076</guid>
    </item>
    <item>
      <title>GHSA-gjxx-92w9-8v8f — Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gjxx-92w9-8v8f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @clerk/backend, npm: @clerk/express, npm: @clerk/hono, npm: @clerk/fastify&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `clerkFrontendApiProxy` function in `@clerk/backend` is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can craft a request path that causes the proxy to send the application&amp;#39;s `Clerk-Secret-Key` to an attacker-controlled server.&lt;/p&gt;
&lt;p&gt;## Affected packages&lt;/p&gt;
&lt;p&gt;Only applications that have opted into the `frontendApiProxy` feature are affected. This feature is not enabled by default. **Users of `@clerk/nextjs` are not affected** due to how the framework handles repeated `/` in request paths.&lt;/p&gt;
&lt;p&gt;| Package | Affected versions | Fixed version |
|---|---|---|
| `@clerk/backend` | `&amp;gt;= 3.0.0, &amp;lt;= 3.2.2` | `3.2.3` |
| `@clerk/express` | `&amp;gt;= 2.0.0, &amp;lt;= 2.0.6` | `2.0.7` |
| `@clerk/hono` | `&amp;gt;= 0.1.0, &amp;lt;= 0.1.4` | `0.1.5` |
| `@clerk/fastify` | `&amp;gt;= 3.1.0, &amp;lt;= 3.1.4` | `3.1.5` |&lt;/p&gt;
&lt;p&gt;Search your codebase for the `frontendApiProxy` option. If none of the patterns below appear in your code, you are not affected.&lt;/p&gt;
&lt;p&gt;**@clerk/express**
```ts
app.use(clerkMiddleware({ frontendApiProxy: { enabled: true } }));
```&lt;/p&gt;
&lt;p&gt;**@clerk/hono**
```ts
app.use(&amp;#39;*&amp;#39;, clerkMiddleware({ frontendApiProxy: { enabled: true } }));
```&lt;/p&gt;
&lt;p&gt;**@clerk/fastify**
```ts
fastify.register(clerkPlugin, { frontendApiProxy: { enabled: true } });
```&lt;/p&gt;
&lt;p&gt;**@clerk/backend**
```ts
import { clerkFrontendApiProxy } from &amp;#39;@clerk/backend/proxy&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;A quick way to check across your entire project:&lt;/p&gt;
&lt;p&gt;```sh
grep -r &amp;#34;frontendApiProxy\|clerkFrontendApiProxy&amp;#34; .
```&lt;/p&gt;
&lt;p&gt;If there are no matches, you are not using this feature.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @clerk/backend, npm: @clerk/express, npm: @clerk/hono, npm: @clerk/fastify&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `clerkFrontendApiProxy` function in `@clerk/backend` is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can craft a request path that causes the proxy to send the application&amp;#39;s `Clerk-Secret-Key` to an attacker-controlled server.&lt;/p&gt;
&lt;p&gt;## Affected packages&lt;/p&gt;
&lt;p&gt;Only applications that have opted into the `frontendApiProxy` feature are affected. This feature is not enabled by default. **Users of `@clerk/nextjs` are not affected** due to how the framework handles repeated `/` in request paths.&lt;/p&gt;
&lt;p&gt;| Package | Affected versions | Fixed version |
|---|---|---|
| `@clerk/backend` | `&amp;gt;= 3.0.0, &amp;lt;= 3.2.2` | `3.2.3` |
| `@clerk/express` | `&amp;gt;= 2.0.0, &amp;lt;= 2.0.6` | `2.0.7` |
| `@clerk/hono` | `&amp;gt;= 0.1.0, &amp;lt;= 0.1.4` | `0.1.5` |
| `@clerk/fastify` | `&amp;gt;= 3.1.0, &amp;lt;= 3.1.4` | `3.1.5` |&lt;/p&gt;
&lt;p&gt;Search your codebase for the `frontendApiProxy` option. If none of the patterns below appear in your code, you are not affected.&lt;/p&gt;
&lt;p&gt;**@clerk/express**
```ts
app.use(clerkMiddleware({ frontendApiProxy: { enabled: true } }));
```&lt;/p&gt;
&lt;p&gt;**@clerk/hono**
```ts
app.use(&amp;#39;*&amp;#39;, clerkMiddleware({ frontendApiProxy: { enabled: true } }));
```&lt;/p&gt;
&lt;p&gt;**@clerk/fastify**
```ts
fastify.register(clerkPlugin, { frontendApiProxy: { enabled: true } });
```&lt;/p&gt;
&lt;p&gt;**@clerk/backend**
```ts
import { clerkFrontendApiProxy } from &amp;#39;@clerk/backend/proxy&amp;#39;;
```&lt;/p&gt;
&lt;p&gt;A quick way to check across your entire project:&lt;/p&gt;
&lt;p&gt;```sh
grep -r &amp;#34;frontendApiProxy\|clerkFrontendApiProxy&amp;#34; .
```&lt;/p&gt;
&lt;p&gt;If there are no matches, you are not using this feature.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gjxx-92w9-8v8f</guid>
    </item>
  </channel>
</rss>
