GHSA-9mp4-77wg-rwx9
@clerk/backend Performs Insufficient Verification of Data Authenticity
Quick fix
GHSA-9mp4-77wg-rwx9 — @clerk/backend: upgrade to the fixed version with the command below.
npm install @clerk/backend@2.4.0Details
### Impact
Applications that use the `verifyWebhook()` helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events.
### Patches
* `@clerk/backend`: the helper has been patched as of `2.4.0` * `@clerk/astro`: the helper has been patched as of `2.10.2` * `@clerk/express`: the helper has been patched as of `1.7.4` * `@clerk/fastify`: the helper has been patched as of `2.4.4` * `@clerk/nextjs`: the helper has been patched as of `6.23.3` * `@clerk/nuxt`: the helper has been patched as of `1.7.5` * `@clerk/react-router`: the helper has been patched as of `1.6.4` * `@clerk/remix`: the helper has been patched as of `4.8.5` * `@clerk/tanstack-react-start`: the helper has been patched as of `0.18.3`
### Resolution
The issue was resolved in **`@clerk/backend` `2.4.0`** by:
* Properly parsing the webhook request's signatures and comparing them against the signature generated from the received event
### Workarounds
If unable to upgrade, developers can workaround this issue by verifying webhooks manually, per [this documentation](https://clerk.com/docs/webhooks/overview#protect-your-webhooks-from-abuse).
Are you affected?
Enter the version of the package you're using.
Affected packages
0.16.0Fixed in: 0.18.3npm install @clerk/tanstack-react-start@0.18.3