Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sentry

First CVE: Dec 10, 2022Active for: 4 yearsTotal CVEs: 22
23.2
VTI Score
Low

Sentry provides application performance monitoring and error-tracking infrastructure that sits in the deployment pipelines of development teams across a broad range of hosted and cloud environments. Its vulnerability profile, while modest in volume, concentrates in its core platform and SDK offerings and skews toward serious outcomes, reflecting the sensitive nature of the data flowing through its services—error logs, user context, and stack traces that often contain secrets, credentials, and system topology. The recurring weakness classes, including server-side request forgery, authorization bypass through user-controlled keys, improper authentication, error messages leaking sensitive information, and improper access control, reflect the common challenges of an internet-facing aggregation and analytics platform that must parse untrusted input and enforce multi-tenant isolation. Defenders should treat authentication and data-leakage flaws in this vendor as material to their application instrumentation pipeline and inventory which SDKs and versions are in use across their codebases. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sentry over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 10, 2022
3 years ago
Most Recent CVE
Jun 24, 2026
30 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-42354CRITICAL
Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation o
May 8, 20269.840NONO
CVE-2021-47935HIGH
Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects thro
May 10, 20268.835NONO
CVE-2026-27197CRITICAL
Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allo
Feb 21, 20269.132NONO
CVE-2026-52794HIGH
Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingesti
Jun 24, 20267.530NONO
CVE-2026-26004MEDIUM
Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object Reference (IDOR) vulnerability
Mar 18, 20266.523NONO
CVE-2023-39349HIGH
Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes ca
Aug 7, 20238.123NONO
CVE-2023-46729MEDIUM
sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the respons
Nov 10, 20236.122NONO
CVE-2025-53099HIGH
Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a malicious OAuth application registered with Sentry can take
Jul 1, 20257.521NONO
CVE-2023-28117MEDIUM
Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the Django integration of versions prior to 1.14.0 of the Sentry SDK in a specific
Mar 22, 20236.521NONO
CVE-2023-50249HIGH
Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Regular expression Denial of Service) vulnerability has been identified in Sentry's Astro SDK 7.78.0-7.86.0. Unde
Dec 20, 20237.520NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
64%
23%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (81.8%)
High4 (18.2%)
Unknown0 (0.0%)
User Interaction
None20 (90.9%)
Unknown0 (0.0%)
Required2 (9.1%)
Privileges Required
Low14 (63.6%)
High0 (0.0%)
None8 (36.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sentry.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sentry — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sentry's Products

View all 3 CNAs →

Top CWEs