Sentry
Sentry: vulnerabilidades y CVE
Sentry tiene 21 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses7
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-83803 | Alta (7.7) | 0.60% | — | 22 sept 2026 | Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with the relocation feature enabled unsafely deserialize a legacy database field while importing a user-supplied… |
| CVE-2026-83527 | Alta (8.1) | 1.8% | — | 8 sept 2026 | An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access. |
| CVE-2026-52794 | Alta (7.5) | 0.47% | — | 24 jun 2026 | Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingestion pipeline, where a regex applied to… |
| CVE-2021-47935 | Alta (8.7) | 0.93% | — | 10 may 2026 | Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter.… |
| CVE-2026-42354 | Crítica (9.8) | 0.73% | — | 8 may 2026 | Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation of Sentry. The vulnerability allows an… |
| CVE-2026-26004 | Media (5.7) | 0.40% | — | 18 mar 2026 | Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object Reference (IDOR) vulnerability in Sentry's GroupEventJsonView… |
| CVE-2026-27197 | Crítica (9.1) | 0.58% | — | 21 feb 2026 | Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to take over any user… |
| CVE-2025-53099 | Media (5.5) | 0.74% | — | 1 jul 2025 | Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a malicious OAuth application registered with Sentry can take advantage of a race condition and… |
| CVE-2025-53073 | Media (4.2) | 0.24% | — | 24 jun 2025 | In Sentry 25.1.0 through 25.5.1, an authenticated attacker can access a project's issue endpoint and perform unauthorized actions (such as adding a comment) without being a member of the project's team. A seven-digit… |
| CVE-2025-22146 | Crítica (9.1) | 0.61% | — | 15 ene 2025 | Sentry is a developer-first error tracking and performance monitoring tool. A critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The… |
| CVE-2024-53253 | Media (5.3) | 0.65% | — | 22 nov 2024 | Sentry is an error tracking and performance monitoring platform. Version 24.11.0, and only version 24.11.0, is vulnerable to a scenario where a specific error message generated by the Sentry platform could include a… |
| CVE-2024-45606 | Media (4.3) | 0.36% | — | 17 sept 2024 | Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user can mute alert rules from arbitrary organizations and projects with a know rule ID. The user does not need to be a… |
| CVE-2024-45605 | Media (4.3) | 0.39% | — | 17 sept 2024 | Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user issue alert notifications for arbitrary users given a know alert ID. A patch was issued to ensure… |
| CVE-2024-41656 | Media (5.4) | 0.47% | — | 23 jul 2024 | Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 24.7.1, an unsanitized payload sent by an Integration platform integration allows storing arbitrary HTML… |
| CVE-2024-35196 | Baja (2) | 0.57% | — | 31 may 2024 | Sentry is a developer-first error tracking and performance monitoring platform. Sentry's Slack integration incorrectly records the incoming request body in logs. This request data can contain sensitive information,… |
| CVE-2024-32474 | Media (6.5) | 0.43% | — | 18 abr 2024 | Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to Sentry with a username and password, the password is leaked as cleartext in logs under the _event_:… |
| CVE-2024-24829 | Media (5.3) | 0.47% | — | 9 feb 2024 | Sentry is an error tracking and performance monitoring platform. Sentry’s integration platform provides a way for external services to interact with Sentry. One of such integrations, the Phabricator integration… |
| CVE-2023-39531 | Media (6.8) | 0.36% | — | 9 ago 2023 | Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 23.7.2, an attacker with sufficient client-side exploits could retrieve a valid access token for another… |
| CVE-2023-39349 | Alta (8.1) | 1.1% | — | 7 ago 2023 | Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes can query `/api/0/api-tokens/` for a list… |
| CVE-2023-36826 | Media (6.5) | 0.63% | — | 25 jul 2023 | Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and… |
| CVE-2022-23485 | Baja (3.7) | 0.43% | — | 10 dic 2022 | Sentry is an error tracking and performance monitoring platform. In versions of the sentry python library prior to 22.11.0 an attacker with a known valid invite link could manipulate a cookie to allow the same invite… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.