Sentry provides application performance monitoring and error-tracking infrastructure that sits in the deployment pipelines of development teams across a broad range of hosted and cloud environments. Its vulnerability profile, while modest in volume, concentrates in its core platform and SDK offerings and skews toward serious outcomes, reflecting the sensitive nature of the data flowing through its services—error logs, user context, and stack traces that often contain secrets, credentials, and system topology. The recurring weakness classes, including server-side request forgery, authorization bypass through user-controlled keys, improper authentication, error messages leaking sensitive information, and improper access control, reflect the common challenges of an internet-facing aggregation and analytics platform that must parse untrusted input and enforce multi-tenant isolation. Defenders should treat authentication and data-leakage flaws in this vendor as material to their application instrumentation pipeline and inventory which SDKs and versions are in use across their codebases. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sentry over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42354CRITICAL Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical vulnerability was discovered in the SAML SSO implementation o | May 8, 2026 | 9.8 | 40 | NO | NO |
CVE-2021-47935HIGH Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects thro | May 10, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-27197CRITICAL Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allo | Feb 21, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-52794HIGH Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingesti | Jun 24, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-26004MEDIUM Sentry is a developer-first error tracking and performance monitoring tool. Versions prior to 26.1.0 have a cross-organization Insecure Direct Object Reference (IDOR) vulnerability | Mar 18, 2026 | 6.5 | 23 | NO | NO |
CVE-2023-39349HIGH Sentry is an error tracking and performance monitoring platform. Starting in version 22.1.0 and prior to version 23.7.2, an attacker with access to a token with few or no scopes ca | Aug 7, 2023 | 8.1 | 23 | NO | NO |
CVE-2023-46729MEDIUM sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the respons | Nov 10, 2023 | 6.1 | 22 | NO | NO |
CVE-2025-53099HIGH Sentry is a developer-first error tracking and performance monitoring tool. Prior to version 25.5.0, an attacker with a malicious OAuth application registered with Sentry can take | Jul 1, 2025 | 7.5 | 21 | NO | NO |
CVE-2023-28117MEDIUM Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the Django integration of versions prior to 1.14.0 of the Sentry SDK in a specific | Mar 22, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-50249HIGH Sentry-Javascript is official Sentry SDKs for JavaScript. A ReDoS (Regular expression Denial of Service) vulnerability has been identified in Sentry's Astro SDK 7.78.0-7.86.0. Unde | Dec 20, 2023 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sentry.
Media articles that mention a CVE ID that affects a product developed by Sentry — matched by CVE ID, not by vendor name.