CVE-2026-41248: Clerk Astro
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Clerk JavaScript is the official JavaScript repository for Clerk authentication. createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro can be bypassed by certain crafted requests, allowing them to skip middleware gating and reach downstream handlers. This vulnerability is fixed in @clerk/astro 1.5.7, 2.17.10, and 3.0.15; @clerk/nextjs 5.7.6, 6.39.2, and 7.2.1; @clerk/nuxt 1.13.28 and 2.2.2; and @clerk/shared 2.22.1, 3.47.4, anc 4.8.1
Affected products
- Clerk Astro: from 0.0.1, before 1.5.7 (fixed in 1.5.7); from 2.0.0-snapshot.v20241206174604, up to and including 2.17.9; from 3.0.0, before 3.0.15 (fixed in 3.0.15)
- Clerk Nextjs: from 5.0.0, before 5.7.6 (fixed in 5.7.6); from 6.0.0-snapshot.vb87a27f, before 6.39.2 (fixed in 6.39.2); from 7.0.0, before 7.2.1 (fixed in 7.2.1)
- Clerk Nuxt: from 1.1.0, before 1.13.28 (fixed in 1.13.28); from 2.0.0, before 2.2.2 (fixed in 2.2.2)
- Clerk Shared: from 2.20.17, before 2.22.1 (fixed in 2.22.1); from 3.0.0-canary.v20250225091530, before 3.47.4 (fixed in 3.47.4); from 4.0.0, before 4.8.1 (fixed in 4.8.1)
Published 2026-04-24. Last modified 2026-06-17.