sentry has 10 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 7.1 (high), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Products
- sentry 10
Worst active — by depth score
CVE-2026-27197Critical· 9.1Sentry: Improper authentication on SAML SSO process allows user identity linking50CVE-2023-39349High· 8.1Privilege escalation via ApiTokensEndpoint45CVE-2023-36826High· 7.7Improper authorization on debug and artifact file downloads42CVE-2024-32474High· 7.3Sentry vulnerable to leaking superuser cleartext password in logs40CVE-2024-45606High· 7.1Sentry improperly authorizes muting of alert rules39
sentry vulnerabilities
CVEs affecting sentry, newest first. Open any entry for full detail, references, and exploit status.
10 CVEsRSS
CVE-2026-27197Critical· 9.1Sentry: Improper authentication on SAML SSO process allows user identity linking
Sentry: Improper authentication on SAML SSO process allows user identity linking
CVE-2024-45606High· 7.1Sentry improperly authorizes muting of alert rules
Sentry improperly authorizes muting of alert rules
CVE-2024-45605Medium· 6.5Sentry improperly authorizes deletion of user issue alert notifications
Sentry improperly authorizes deletion of user issue alert notifications
CVE-2024-41656High· 7.1Sentry vulnerable to stored Cross-Site Scripting (XSS)
Sentry vulnerable to stored Cross-Site Scripting (XSS)
CVE-2024-35196Low· 2.0Slack integration leaks sensitive information in logs
Slack integration leaks sensitive information in logs
CVE-2024-32474High· 7.3Sentry vulnerable to leaking superuser cleartext password in logs
Sentry vulnerable to leaking superuser cleartext password in logs
CVE-2023-39531Medium· 6.5Sentry vulnerable to incorrect credential validation on OAuth token requests
Sentry vulnerable to incorrect credential validation on OAuth token requests
CVE-2023-39349High· 8.1Privilege escalation via ApiTokensEndpoint
Privilege escalation via ApiTokensEndpoint
CVE-2023-36826High· 7.7Improper authorization on debug and artifact file downloads
Improper authorization on debug and artifact file downloads
CVE-2023-36829Medium· 6.8Sentry CORS misconfiguration
Sentry CORS misconfiguration