Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20865 | @clerk/backend Performs Insufficient Verification of Data Authenticity |
Github GHSA |
GHSA-9mp4-77wg-rwx9 | @clerk/backend Performs Insufficient Verification of Data Authenticity |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 09 Jul 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events. The issue was resolved in @clerk/backend 2.4.0. | |
| Title | @clerk/backend Performs Insufficient Verification of Data Authenticity | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-09T17:34:36.765Z
Reserved: 2025-07-02T15:15:11.516Z
Link: CVE-2025-53548
Updated: 2025-07-09T17:34:28.635Z
Status : Deferred
Published: 2025-07-09T18:15:24.157
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-53548
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA