Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events. The issue was resolved in @clerk/backend 2.4.0.
| Software | From | Fixed in |
|---|---|---|
@clerk / backend
|
2.0.0 | 2.4.0 |
@clerk / astro
|
2.9.0 | 2.10.2 |
@clerk / express
|
1.6.0 | 1.7.4 |
@clerk / fastify
|
2.3.0 | 2.4.4 |
@clerk / nextjs
|
6.2.10 | 6.23.3 |
@clerk / nuxt
|
1.7.0 | 1.7.5 |
@clerk / react-router
|
1.5.0 | 1.6.4 |
@clerk / remix
|
4.8.0 | 4.8.5 |
@clerk / tanstack-react-start
|
0.16.0 | 0.18.3 |