sentry vulnerabilities
CVEs whose affected-version data names the sentry package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
11 CVEsRSS
CVE-2026-83527High· 8.1An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.
An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.
CVE-2026-27197Critical· 9.1Sentry: Improper authentication on SAML SSO process allows user identity linking
Sentry: Improper authentication on SAML SSO process allows user identity linking
CVE-2024-45606High· 7.1Sentry improperly authorizes muting of alert rules
Sentry improperly authorizes muting of alert rules
CVE-2024-45605Medium· 6.5Sentry improperly authorizes deletion of user issue alert notifications
Sentry improperly authorizes deletion of user issue alert notifications
CVE-2024-41656High· 7.1Sentry vulnerable to stored Cross-Site Scripting (XSS)
Sentry vulnerable to stored Cross-Site Scripting (XSS)
CVE-2024-35196Low· 2.0Slack integration leaks sensitive information in logs
Slack integration leaks sensitive information in logs
CVE-2024-32474High· 7.3Sentry vulnerable to leaking superuser cleartext password in logs
Sentry vulnerable to leaking superuser cleartext password in logs
CVE-2023-39531Medium· 6.5Sentry vulnerable to incorrect credential validation on OAuth token requests
Sentry vulnerable to incorrect credential validation on OAuth token requests
CVE-2023-39349High· 8.1Privilege escalation via ApiTokensEndpoint
Privilege escalation via ApiTokensEndpoint
CVE-2023-36826High· 7.7Improper authorization on debug and artifact file downloads
Improper authorization on debug and artifact file downloads
CVE-2023-36829Medium· 6.8Sentry CORS misconfiguration
Sentry CORS misconfiguration