Sentry records
21 published records for vendor sentry.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 81%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-287 Improper Authentication2
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-269 Improper Privilege Management1
- CWE-284 Improper Access Control1
The weakness classes this vendor ships most often: where to look.
CWEAll records
21 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-42354No exploit | Sentry: Improper authentication on SAML SSO process allows user identity linkingsentry · sentry · CWE-290 | Critical9.8 | — | 0.7% | May 8, 2026 |
36Monitor | CVE-2026-27197No exploit | Sentry: Improper Authentication on SAML SSO process allows user identity linkingsentry · sentry · CWE-287 | Critical9.1 | — | 0.6% | Feb 21, 2026 |
34Monitor | CVE-2021-47935No exploit | Sentry 8.2.0 Remote Code Execution via Pickle Deserializationsentry · sentry · CWE-94 | High8.7 | — | 0.9% | May 10, 2026 |
32Monitor | CVE-2023-39349No exploit | Sentry vulnerable to privilege escalation via ApiTokensEndpointsentry · sentry · CWE-284 | High8.1 | — | 1.1% | Aug 7, 2023 |
30Monitor | CVE-2023-50249No exploit | Sentry's Astro SDK vulnerable to ReDoSsentry · astro · CWE-400 | High7.5 | — | 0.8% | Dec 20, 2023 |
30Monitor | CVE-2026-52794No exploit | Sentry: Inefficient Regular Expression Complexity in sentrysentry · sentry · CWE-1333 | High7.5 | — | 0.5% | Jun 24, 2026 |
27Monitor | CVE-2023-39531No exploit | Sentry vulnerable to incorrect credential validation on OAuth token requestssentry · sentry · CWE-287 | Medium6.8 | — | 0.4% | Aug 9, 2023 |
26Monitor | CVE-2023-28117No exploit | Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`sentry · sentry software development kit · CWE-201 | Medium6.5 | — | 0.6% | Mar 22, 2023 |
26Monitor | CVE-2023-36826No exploit | Sentry vulnerable to improper authorization on debug and artifact file downloadssentry · sentry · CWE-285 | Medium6.5 | — | 0.6% | Jul 25, 2023 |
26Monitor | CVE-2024-32474No exploit | Sentry's superuser cleartext password leaked in logssentry · sentry · CWE-117 | Medium6.5 | — | 0.4% | Apr 18, 2024 |
24Monitor | CVE-2023-46729No exploit | Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpointsentry · sentry software development kit · CWE-918 | Medium6.1 | — | 0.6% | Nov 9, 2023 |
22Monitor | CVE-2025-53099No exploit | Sentry Missing Invalidation of Authorization Codes During OAuth Exchange and Revocationsentry · sentry · CWE-288 | Medium5.5 | — | 0.7% | Jul 1, 2025 |
22Monitor | CVE-2026-26004No exploit | Sentry allows unauthorized access to event data across organizational boundariessentry · sentry · CWE-639 | Medium5.7 | — | 0.4% | Mar 17, 2026 |
21Monitor | CVE-2024-53253No exploit | Sentry's improper error handling leaks Application Integration Client Secretsentry · sentry · CWE-209 | Medium5.3 | — | 0.7% | Nov 22, 2024 |
21Monitor | CVE-2024-24829No exploit | SSRF in Sentry via Phabricator integrationsentry · sentry · CWE-918 | Medium5.3 | — | 0.5% | Feb 8, 2024 |
21Monitor | CVE-2024-41656No exploit | Sentry vulnerable to stored Cross-Site Scripting (XSS)sentry · sentry · CWE-79 | Medium5.4 | — | 0.5% | Jul 23, 2024 |
17Monitor | CVE-2023-49094No exploit | Symbolicator Server Side Request Forgery vulnerabilitysentry · symbolicator · CWE-918 | Medium4.3 | — | 0.7% | Nov 30, 2023 |
17Monitor | CVE-2023-51451No exploit | SSRF in symbolicator via invalid protocolsentry · symbolicator · CWE-918 | Medium4.3 | — | 0.5% | Dec 22, 2023 |
17Monitor | CVE-2024-45605No exploit | Improper authorization on deletion of user issue alert notifications in sentrysentry · sentry · CWE-639 | Medium4.3 | — | 0.4% | Sep 17, 2024 |
17Monitor | CVE-2024-45606No exploit | Improper authorization on muting of alert rules in sentrysentry · sentry · CWE-639 | Medium4.3 | — | 0.4% | Sep 17, 2024 |
14Monitor | CVE-2022-23485No exploit | Invite code reuse via cookie manipulation in sentrysentry · sentry · CWE-269 | Low3.7 | — | 0.4% | Dec 9, 2022 |
- CVE-2026-4235439Monitor
Sentry: Improper authentication on SAML SSO process allows user identity linking
CriticalCVSS 9.8No exploitEPSS 1%sentry · sentryMay 8, 2026
- CVE-2026-2719736Monitor
Sentry: Improper Authentication on SAML SSO process allows user identity linking
CriticalCVSS 9.1No exploitEPSS 1%sentry · sentryFeb 21, 2026
- CVE-2021-4793534Monitor
Sentry 8.2.0 Remote Code Execution via Pickle Deserialization
HighCVSS 8.7No exploitEPSS 1%sentry · sentryMay 10, 2026
- CVE-2023-3934932Monitor
Sentry vulnerable to privilege escalation via ApiTokensEndpoint
HighCVSS 8.1No exploitEPSS 1%sentry · sentryAug 7, 2023
- CVE-2023-5024930Monitor
Sentry's Astro SDK vulnerable to ReDoS
HighCVSS 7.5No exploitEPSS 1%sentry · astroDec 20, 2023
- CVE-2026-5279430Monitor
Sentry: Inefficient Regular Expression Complexity in sentry
HighCVSS 7.5No exploitEPSS 0%sentry · sentryJun 24, 2026
- CVE-2023-3953127Monitor
Sentry vulnerable to incorrect credential validation on OAuth token requests
MediumCVSS 6.8No exploitEPSS 0%sentry · sentryAug 9, 2023
- CVE-2023-2811726Monitor
Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`
MediumCVSS 6.5No exploitEPSS 1%sentry · sentry software development kitMar 22, 2023
- CVE-2023-3682626Monitor
Sentry vulnerable to improper authorization on debug and artifact file downloads
MediumCVSS 6.5No exploitEPSS 1%sentry · sentryJul 25, 2023
- CVE-2024-3247426Monitor
Sentry's superuser cleartext password leaked in logs
MediumCVSS 6.5No exploitEPSS 0%sentry · sentryApr 18, 2024
- CVE-2023-4672924Monitor
Sentry Next.js vulnerable to SSRF via Next.js SDK tunnel endpoint
MediumCVSS 6.1No exploitEPSS 1%sentry · sentry software development kitNov 9, 2023
- CVE-2025-5309922Monitor
Sentry Missing Invalidation of Authorization Codes During OAuth Exchange and Revocation
MediumCVSS 5.5No exploitEPSS 1%sentry · sentryJul 1, 2025
- CVE-2026-2600422Monitor
Sentry allows unauthorized access to event data across organizational boundaries
MediumCVSS 5.7No exploitEPSS 0%sentry · sentryMar 17, 2026
- CVE-2024-5325321Monitor
Sentry's improper error handling leaks Application Integration Client Secret
MediumCVSS 5.3No exploitEPSS 1%sentry · sentryNov 22, 2024
- CVE-2024-2482921Monitor
SSRF in Sentry via Phabricator integration
MediumCVSS 5.3No exploitEPSS 0%sentry · sentryFeb 8, 2024
- CVE-2024-4165621Monitor
Sentry vulnerable to stored Cross-Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%sentry · sentryJul 23, 2024
- CVE-2023-4909417Monitor
Symbolicator Server Side Request Forgery vulnerability
MediumCVSS 4.3No exploitEPSS 1%sentry · symbolicatorNov 30, 2023
- CVE-2023-5145117Monitor
SSRF in symbolicator via invalid protocol
MediumCVSS 4.3No exploitEPSS 0%sentry · symbolicatorDec 22, 2023
- CVE-2024-4560517Monitor
Improper authorization on deletion of user issue alert notifications in sentry
MediumCVSS 4.3No exploitEPSS 0%sentry · sentrySep 17, 2024
- CVE-2024-4560617Monitor
Improper authorization on muting of alert rules in sentry
MediumCVSS 4.3No exploitEPSS 0%sentry · sentrySep 17, 2024
- CVE-2022-2348514Monitor
Invite code reuse via cookie manipulation in sentry
LowCVSS 3.7No exploitEPSS 0%sentry · sentryDec 9, 2022