This release includes 3 security fixes for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summarySecurity fixes for Clerk route bypass, Next.js RSC DoS, and multiple critical vulnerabilities including an Axios backdoor and Drizzle SQL injection.
Full changelog
- VG925: Clerk middleware route protection bypass (GHSA-vqx2)
- VG926: Next.js / React RSC DoS (CVE-2026-23869)
- VG923/924/1010/1011: Axios backdoor, Hono CRLF, React Server Action validation, Drizzle SQL injection (CVE-2026-39356)
Security Fixes
- VG925 – Clerk middleware route protection bypass (GHSA-vqx2)
- VG926 – Next.js / React RSC Denial‑of‑Service (CVE-2026-23869)
- VG923/924/1010/1011 – Axios backdoor, Hono CRLF injection, React Server Action validation flaw, Drizzle SQL injection (CVE-2026-39356)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About goklab/guardvibe
Security MCP for vibe coding with 330 rules and 29 tools. Purpose-built for AI-generated code — scans Next.js, Supabase, Clerk, Stripe, Prisma, Hono, GraphQL, and 25+ modules. Cross-file taint analysis, host security audit, auto-fix, SARIF export, pre-commit hook, and CVE version detection. Zero config, runs locally.
Related context
Beta — feedback welcome: [email protected]