Getsentry / Sentry
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-83803 | Sentry: Unsafe pickle deserialization in Relocation Feature | HIGH | 7.7 | Sep 22, 2026 |
| CVE-2026-52794 | Sentry: Inefficient Regular Expression Complexity in sentry | HIGH | 7.5 | Jun 24, 2026 |
| CVE-2026-42354 | Sentry: Improper authentication on SAML SSO process allows user identity linking | CRITICAL | 9.8 | May 8, 2026 |
| CVE-2026-26004 | Sentry allows unauthorized access to event data across organizational boundaries | MEDIUM | 5.7 | Mar 17, 2026 |
| CVE-2026-27197 | Sentry: Improper Authentication on SAML SSO process allows user identity linking | CRITICAL | 9.1 | Feb 21, 2026 |
| CVE-2025-53099 | Sentry Missing Invalidation of Authorization Codes During OAuth Exchange and Revocation | MEDIUM | 5.5 | Jul 1, 2025 |
| CVE-2025-22146 | Improper authentication on SAML SSO process allows user impersonation in sentry | CRITICAL | 9.1 | Jan 15, 2025 |
| CVE-2024-53253 | Sentry's improper error handling leaks Application Integration Client Secret | MEDIUM | 5.3 | Nov 22, 2024 |
| CVE-2024-45605 | Improper authorization on deletion of user issue alert notifications in sentry | HIGH | 7.1 | Sep 17, 2024 |
| CVE-2024-45606 | Improper authorization on muting of alert rules in sentry | HIGH | 7.1 | Sep 17, 2024 |
| CVE-2024-41656 | Sentry vulnerable to stored Cross-Site Scripting (XSS) | HIGH | 7.1 | Jul 23, 2024 |
| CVE-2024-35196 | Slack integration leaks sensitive information in logs in Sentry | LOW | 2.0 | May 31, 2024 |
| CVE-2024-32474 | Sentry's superuser cleartext password leaked in logs | HIGH | 7.3 | Apr 18, 2024 |
| CVE-2024-24829 | SSRF in Sentry via Phabricator integration | MEDIUM | 5.3 | Feb 8, 2024 |
| CVE-2023-39531 | Sentry vulnerable to incorrect credential validation on OAuth token requests | MEDIUM | 6.8 | Aug 9, 2023 |
| CVE-2023-39349 | Sentry vulnerable to privilege escalation via ApiTokensEndpoint | HIGH | 8.1 | Aug 7, 2023 |
| CVE-2023-36826 | Sentry vulnerable to improper authorization on debug and artifact file downloads | HIGH | 8.3 | Jul 25, 2023 |
| CVE-2023-36829 | Sentry CORS misconfiguration vulnerability | MEDIUM | 6.8 | Jul 6, 2023 |
| CVE-2022-23485 | Invite code reuse via cookie manipulation in sentry | MEDIUM | 6.4 | Dec 10, 2022 |
Showing 1 to 19 of 19 CVEs