{"api_version":"v1","generated_at":"2026-10-04T12:00:00+00:00","product":{"cve_count":4,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-clerk-javascript-2ae6d08ead5c","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"javascript","next_cursor":null,"observations":[{"affected":">= 5.22.0, < 5.125.10; >= 6.0.0, < 6.7.5; >= 3.0.0, <= 3.47.4; >= 4.0.0, <= 4.8.2; >= 2.0.0, <= 2.33.2; >= 3.0.0, <= 3.2.13; >= 6.0.0, <= 6.39.2; >= 7.0.0, <= 7.2.3","affected_versions_present":true,"cve_id":"CVE-2026-42349","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42349","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T18:19:38.735Z","patch_url":"https://github.com/clerk/javascript/security/advisories/GHSA-w24r-5266-9c3c","primary_source":"","published":"2026-05-11T16:08:27.869Z"},{"affected":"@clerk/hono >= 0.1.0, < 0.1.5; @clerk/express >= 2.0.0, < 2.0.7; @clerk/backend >= 3.0.0, < 3.2.3; @clerk/fastify >= 3.1.0, < 3.1.5","affected_versions_present":true,"cve_id":"CVE-2026-34076","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34076","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-01T18:00:23.118Z","patch_url":"","primary_source":"","published":"2026-04-01T16:59:21.828Z"},{"affected":"< 2.4.0","affected_versions_present":true,"cve_id":"CVE-2025-53548","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-53548","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-07-09T17:34:36.765Z","patch_url":"","primary_source":"","published":"2025-07-09T17:12:10.483Z"},{"affected":">= 4.7.0, < 4.29.3","affected_versions_present":true,"cve_id":"CVE-2024-22206","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-22206","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-11-14T15:42:39.402Z","patch_url":"https://github.com/clerk/javascript/security/advisories/GHSA-q6w5-jg5q-47vg","primary_source":"","published":"2024-01-12T20:07:40.402Z"}],"source_generated_at":"2026-10-04T06:24:23.053Z","vendor":"clerk"}}
