CVE-2023-39531Medium· 6.5▾ SunlitSentry vulnerable to incorrect credential validation on OAuth token requests
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.4%
An attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account.
There are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed.
sentry >= 10.0.0, < 23.7.2Upgrade to a patched release:
sentry 23.7.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-27197Critical· 9.1Sentry: Improper authentication on SAML SSO process allows user identity linking
CVE-2023-36826High· 7.7Improper authorization on debug and artifact file downloads
CVE-2023-36829Medium· 6.8Sentry CORS misconfiguration
CVE-2024-45606High· 7.1Sentry improperly authorizes muting of alert rules
CVE-2024-41656High· 7.1Sentry vulnerable to stored Cross-Site Scripting (XSS)
CVE-2024-35196Low· 2.0Slack integration leaks sensitive information in logs