CVE-2026-52794
- EPSS 0.27%
- Veröffentlicht 24.06.2026 21:26:26
- Zuletzt bearbeitet 27.06.2026 20:45:54
Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingestion pipeline, where a regex applied to attacker-controlled fields on in...
CVE-2021-47935
- EPSS 0.93%
- Veröffentlicht 10.05.2026 13:16:29
- Zuletzt bearbeitet 20.07.2026 20:10:00
Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter. Attackers can submit crafted P...
CVE-2026-42354
- EPSS 0.62%
- Veröffentlicht 08.05.2026 22:58:33
- Zuletzt bearbeitet 24.07.2026 21:10:00
Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation of Sentry. The vulnerability allows an attacker to take over any user a...
CVE-2026-26004
- EPSS 0.24%
- Veröffentlicht 17.03.2026 23:21:35
- Zuletzt bearbeitet 23.03.2026 18:12:48
Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object Reference (IDOR) vulnerability in Sentry's GroupEventJsonView endpoint. Version 26.1.0 patches the i...
CVE-2026-27197
- EPSS 0.44%
- Veröffentlicht 21.02.2026 04:35:14
- Zuletzt bearbeitet 23.02.2026 20:45:01
Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to take over any user account by using a malicious SAML...
CVE-2025-53099
- EPSS 0.69%
- Veröffentlicht 01.07.2025 14:53:16
- Zuletzt bearbeitet 15.09.2025 18:03:33
Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a malicious OAuth application registered with Sentry can take advantage of a race condition and improper handling of authorization c...
CVE-2025-53073
- EPSS 0.2%
- Veröffentlicht 24.06.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the project's team. A seven-digit issue ID must be known (it is not...
CVE-2024-53253
- EPSS 0.63%
- Veröffentlicht 22.11.2024 20:15:09
- Zuletzt bearbeitet 15.09.2025 18:03:56
Sentry is an error tracking and performance monitoring platform. Version 24.11.0, and only version 24.11.0, is vulnerable to a scenario where a specific error message generated by the Sentry platform could include a plaintext Client ID and Client Sec...
CVE-2024-45606
- EPSS 0.36%
- Veröffentlicht 17.09.2024 20:15:05
- Zuletzt bearbeitet 26.09.2024 19:16:40
Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user can mute alert rules from arbitrary organizations and projects with a know rule ID. The user does not need to be a member of the organization or hav...
CVE-2024-45605
- EPSS 0.39%
- Veröffentlicht 17.09.2024 20:15:05
- Zuletzt bearbeitet 26.09.2024 19:14:00
Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user issue alert notifications for arbitrary users given a know alert ID. A patch was issued to ensure authorization checks are properly ...