{"id":"GHSA-gjxx-92w9-8v8f","summary":"Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host","details":"## Summary\n\nThe `clerkFrontendApiProxy` function in `@clerk/backend` is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can craft a request path that causes the proxy to send the application's `Clerk-Secret-Key` to an attacker-controlled server.\n\n## Affected packages\n\nOnly applications that have opted into the `frontendApiProxy` feature are affected. This feature is not enabled by default. **Users of `@clerk/nextjs` are not affected** due to how the framework handles repeated `/` in request paths.\n\n| Package | Affected versions | Fixed version |\n|---|---|---|\n| `@clerk/backend` | `\u003e= 3.0.0, \u003c= 3.2.2` | `3.2.3` |\n| `@clerk/express` | `\u003e= 2.0.0, \u003c= 2.0.6` | `2.0.7` |\n| `@clerk/hono` | `\u003e= 0.1.0, \u003c= 0.1.4` | `0.1.5` |\n| `@clerk/fastify` | `\u003e= 3.1.0, \u003c= 3.1.4` | `3.1.5` |\n\nSearch your codebase for the `frontendApiProxy` option. If none of the patterns below appear in your code, you are not affected.\n\n**@clerk/express**\n```ts\napp.use(clerkMiddleware({ frontendApiProxy: { enabled: true } }));\n```\n\n**@clerk/hono**\n```ts\napp.use('*', clerkMiddleware({ frontendApiProxy: { enabled: true } }));\n```\n\n**@clerk/fastify**\n```ts\nfastify.register(clerkPlugin, { frontendApiProxy: { enabled: true } });\n```\n\n**@clerk/backend**\n```ts\nimport { clerkFrontendApiProxy } from '@clerk/backend/proxy';\n```\n\nA quick way to check across your entire project:\n\n```sh\ngrep -r \"frontendApiProxy\\|clerkFrontendApiProxy\" .\n```\n\nIf there are no matches, you are not using this feature.\n\n\n## Recommended actions\n\nClerk's internal logs show no evidence of users utilizing the built-in proxy with the impacted versions. Despite that, if you are on an impacted version and use the built-in proxy we recommend upgrading and rotating your Clerk Secret Key immediately.\n\n1. **Upgrade** to the patched version of `@clerk/backend` (and `@clerk/express`, `@clerk/hono`, etc.)\n2. **Rotate your Clerk Secret Key** after upgrading - if an attacker exploited this vulnerability, they may have captured your key. Rotate it in the [Clerk Dashboard](https://dashboard.clerk.com) under **API Keys**.  You should deploy your application with the updated key before revoking the existing key.\n3. **Audit access logs** for requests to your proxy endpoint (`/__clerk/` by default) containing double slashes in the path.\n\n\n\n## Credit\n\nDiscovered during an internal code audit.","aliases":["CVE-2026-34076"],"modified":"2026-04-06T17:04:07.972168Z","published":"2026-03-27T19:58:19Z","database_specific":{"cwe_ids":["CWE-918"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-27T19:58:19Z","nvd_published_at":"2026-04-01T18:16:29Z"},"references":[{"type":"WEB","url":"https://github.com/clerk/javascript/security/advisories/GHSA-gjxx-92w9-8v8f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34076"},{"type":"PACKAGE","url":"https://github.com/clerk/javascript"}],"affected":[{"package":{"name":"@clerk/backend","ecosystem":"npm","purl":"pkg:npm/%40clerk/backend"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.2.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.2.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-gjxx-92w9-8v8f/GHSA-gjxx-92w9-8v8f.json"}},{"package":{"name":"@clerk/express","ecosystem":"npm","purl":"pkg:npm/%40clerk/express"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0"},{"fixed":"2.0.7"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.0.6","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-gjxx-92w9-8v8f/GHSA-gjxx-92w9-8v8f.json"}},{"package":{"name":"@clerk/hono","ecosystem":"npm","purl":"pkg:npm/%40clerk/hono"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.1.0"},{"fixed":"0.1.5"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.1.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-gjxx-92w9-8v8f/GHSA-gjxx-92w9-8v8f.json"}},{"package":{"name":"@clerk/fastify","ecosystem":"npm","purl":"pkg:npm/%40clerk/fastify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.1.0"},{"fixed":"3.1.5"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.1.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-gjxx-92w9-8v8f/GHSA-gjxx-92w9-8v8f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}