sentry
A realtime logging and aggregation server.
Activity
- Latest release
- 3y ago
- Total releases
- 371
- Cadence
- ~27 days
- Last 12 months
- 0
Details
- License
- unknown
- First release
- Jan 04, 2012
| Version | Released | |
|---|---|---|
23.7.1
patch
7 CVEs
CVE-2024-45606
PYSEC-2026-1916
GHSA-v345-w9f2-mpm5
Jul 07, 2026
Sentry improperly authorizes muting of alert rules
High
Network
Low
Low
None
ImpactAn authenticated user can mute alert rules from arbitrary organizations and projects given a known given rule ID. The user does not need to be a member of the organization or have permissions on the project. In our review, we have identified no instances where alerts have been muted by unauthorized parties. PatchesA patch was issued to ensure authorization checks are properly scoped on requests to mute alert rules. Authenticated users who do not have the necessary permissions are no longer able to mute alerts. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher. Affected VersionsThe rule mute feature was generally available as of 23.6.0 but users with early access may have had the feature as of 23.4.0. UpdateAs of 2024-10-25 and after additional we've updated the Severity scoring to reduce Privileged Required from Low to None and Integrity from High to Low. Thanks again to @emanuelbeni for the correction on Privileges Required. ReferencesAffected versions
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev |
23.7.1
patch
Dependencies (141)
+ 133 more |
|
23.7.0
minor
7 CVEs
CVE-2024-45606
PYSEC-2026-1916
GHSA-v345-w9f2-mpm5
Jul 07, 2026
Sentry improperly authorizes muting of alert rules
High
Network
Low
Low
None
ImpactAn authenticated user can mute alert rules from arbitrary organizations and projects given a known given rule ID. The user does not need to be a member of the organization or have permissions on the project. In our review, we have identified no instances where alerts have been muted by unauthorized parties. PatchesA patch was issued to ensure authorization checks are properly scoped on requests to mute alert rules. Authenticated users who do not have the necessary permissions are no longer able to mute alerts. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher. Affected VersionsThe rule mute feature was generally available as of 23.6.0 but users with early access may have had the feature as of 23.4.0. UpdateAs of 2024-10-25 and after additional we've updated the Severity scoring to reduce Privileged Required from Low to None and Integrity from High to Low. Thanks again to @emanuelbeni for the correction on Privileges Required. ReferencesAffected versions
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev |
23.7.0
minor
Dependencies (141)
+ 133 more |
|
23.6.2
patch
7 CVEs
CVE-2024-45606
PYSEC-2026-1916
GHSA-v345-w9f2-mpm5
Jul 07, 2026
Sentry improperly authorizes muting of alert rules
High
Network
Low
Low
None
ImpactAn authenticated user can mute alert rules from arbitrary organizations and projects given a known given rule ID. The user does not need to be a member of the organization or have permissions on the project. In our review, we have identified no instances where alerts have been muted by unauthorized parties. PatchesA patch was issued to ensure authorization checks are properly scoped on requests to mute alert rules. Authenticated users who do not have the necessary permissions are no longer able to mute alerts. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher. Affected VersionsThe rule mute feature was generally available as of 23.6.0 but users with early access may have had the feature as of 23.4.0. UpdateAs of 2024-10-25 and after additional we've updated the Severity scoring to reduce Privileged Required from Low to None and Integrity from High to Low. Thanks again to @emanuelbeni for the correction on Privileges Required. ReferencesAffected versions
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev |
23.6.2
patch
Dependencies (140)
+ 132 more |
|
23.6.1
patch
8 CVEs
CVE-2024-45606
PYSEC-2026-1916
GHSA-v345-w9f2-mpm5
Jul 07, 2026
Sentry improperly authorizes muting of alert rules
High
Network
Low
Low
None
ImpactAn authenticated user can mute alert rules from arbitrary organizations and projects given a known given rule ID. The user does not need to be a member of the organization or have permissions on the project. In our review, we have identified no instances where alerts have been muted by unauthorized parties. PatchesA patch was issued to ensure authorization checks are properly scoped on requests to mute alert rules. Authenticated users who do not have the necessary permissions are no longer able to mute alerts. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher. Affected VersionsThe rule mute feature was generally available as of 23.6.0 but users with early access may have had the feature as of 23.4.0. UpdateAs of 2024-10-25 and after additional we've updated the Severity scoring to reduce Privileged Required from Low to None and Integrity from High to Low. Thanks again to @emanuelbeni for the correction on Privileges Required. ReferencesAffected versions
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36829
PYSEC-2023-115
GHSA-4xqm-4p72-87h6
Jul 06, 2023
Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2, the Sentry API incorrectly returns the Affected versions
23.6.0
23.6.1
Fixed in
23.6.2
References Updated Nov 08, 2023 · Source: OSV.dev |
23.6.1
patch
Dependencies (141)
+ 133 more |
|
23.6.0
minor
8 CVEs
CVE-2024-45606
PYSEC-2026-1916
GHSA-v345-w9f2-mpm5
Jul 07, 2026
Sentry improperly authorizes muting of alert rules
High
Network
Low
Low
None
ImpactAn authenticated user can mute alert rules from arbitrary organizations and projects given a known given rule ID. The user does not need to be a member of the organization or have permissions on the project. In our review, we have identified no instances where alerts have been muted by unauthorized parties. PatchesA patch was issued to ensure authorization checks are properly scoped on requests to mute alert rules. Authenticated users who do not have the necessary permissions are no longer able to mute alerts. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher. Affected VersionsThe rule mute feature was generally available as of 23.6.0 but users with early access may have had the feature as of 23.4.0. UpdateAs of 2024-10-25 and after additional we've updated the Severity scoring to reduce Privileged Required from Low to None and Integrity from High to Low. Thanks again to @emanuelbeni for the correction on Privileges Required. ReferencesAffected versions
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36829
PYSEC-2023-115
GHSA-4xqm-4p72-87h6
Jul 06, 2023
Sentry is an error tracking and performance monitoring platform. Starting in version 23.6.0 and prior to version 23.6.2, the Sentry API incorrectly returns the Affected versions
23.6.0
23.6.1
Fixed in
23.6.2
References Updated Nov 08, 2023 · Source: OSV.dev |
23.6.0
minor
Dependencies (141)
+ 133 more |
|
23.5.2
patch
7 CVEs
CVE-2024-45606
PYSEC-2026-1916
GHSA-v345-w9f2-mpm5
Jul 07, 2026
Sentry improperly authorizes muting of alert rules
High
Network
Low
Low
None
ImpactAn authenticated user can mute alert rules from arbitrary organizations and projects given a known given rule ID. The user does not need to be a member of the organization or have permissions on the project. In our review, we have identified no instances where alerts have been muted by unauthorized parties. PatchesA patch was issued to ensure authorization checks are properly scoped on requests to mute alert rules. Authenticated users who do not have the necessary permissions are no longer able to mute alerts. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher. Affected VersionsThe rule mute feature was generally available as of 23.6.0 but users with early access may have had the feature as of 23.4.0. UpdateAs of 2024-10-25 and after additional we've updated the Severity scoring to reduce Privileged Required from Low to None and Integrity from High to Low. Thanks again to @emanuelbeni for the correction on Privileges Required. ReferencesAffected versions
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev |
23.5.2
patch
Dependencies (141)
+ 133 more |
|
23.5.1
patch
8 CVEs
CVE-2024-45606
PYSEC-2026-1916
GHSA-v345-w9f2-mpm5
Jul 07, 2026
Sentry improperly authorizes muting of alert rules
High
Network
Low
Low
None
ImpactAn authenticated user can mute alert rules from arbitrary organizations and projects given a known given rule ID. The user does not need to be a member of the organization or have permissions on the project. In our review, we have identified no instances where alerts have been muted by unauthorized parties. PatchesA patch was issued to ensure authorization checks are properly scoped on requests to mute alert rules. Authenticated users who do not have the necessary permissions are no longer able to mute alerts. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher. Affected VersionsThe rule mute feature was generally available as of 23.6.0 but users with early access may have had the feature as of 23.4.0. UpdateAs of 2024-10-25 and after additional we've updated the Severity scoring to reduce Privileged Required from Low to None and Integrity from High to Low. Thanks again to @emanuelbeni for the correction on Privileges Required. ReferencesAffected versions
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev |
23.5.1
patch
Dependencies (141)
+ 133 more |
|
23.5.0
minor
8 CVEs
CVE-2024-45606
PYSEC-2026-1916
GHSA-v345-w9f2-mpm5
Jul 07, 2026
Sentry improperly authorizes muting of alert rules
High
Network
Low
Low
None
ImpactAn authenticated user can mute alert rules from arbitrary organizations and projects given a known given rule ID. The user does not need to be a member of the organization or have permissions on the project. In our review, we have identified no instances where alerts have been muted by unauthorized parties. PatchesA patch was issued to ensure authorization checks are properly scoped on requests to mute alert rules. Authenticated users who do not have the necessary permissions are no longer able to mute alerts. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher. Affected VersionsThe rule mute feature was generally available as of 23.6.0 but users with early access may have had the feature as of 23.4.0. UpdateAs of 2024-10-25 and after additional we've updated the Severity scoring to reduce Privileged Required from Low to None and Integrity from High to Low. Thanks again to @emanuelbeni for the correction on Privileges Required. ReferencesAffected versions
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev |
23.5.0
minor
Dependencies (141)
+ 133 more |
|
23.4.0
minor
8 CVEs
CVE-2024-45606
PYSEC-2026-1916
GHSA-v345-w9f2-mpm5
Jul 07, 2026
Sentry improperly authorizes muting of alert rules
High
Network
Low
Low
None
ImpactAn authenticated user can mute alert rules from arbitrary organizations and projects given a known given rule ID. The user does not need to be a member of the organization or have permissions on the project. In our review, we have identified no instances where alerts have been muted by unauthorized parties. PatchesA patch was issued to ensure authorization checks are properly scoped on requests to mute alert rules. Authenticated users who do not have the necessary permissions are no longer able to mute alerts. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 24.9.0 or higher. Affected VersionsThe rule mute feature was generally available as of 23.6.0 but users with early access may have had the feature as of 23.4.0. UpdateAs of 2024-10-25 and after additional we've updated the Severity scoring to reduce Privileged Required from Low to None and Integrity from High to Low. Thanks again to @emanuelbeni for the correction on Privileges Required. ReferencesAffected versions
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.9.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev |
23.4.0
minor
Dependencies (139)
+ 131 more |
|
23.3.1
patch
7 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev |
23.3.1
patch
Dependencies (128)
+ 120 more |
|
23.3.0
minor
7 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev |
23.3.0
minor
Dependencies (128)
+ 120 more |
|
23.2.0
minor
7 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev |
23.2.0
minor
Dependencies (128)
+ 120 more |
|
23.1.1
patch
7 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev |
23.1.1
patch
Dependencies (128)
+ 120 more |
|
23.1.0
major
7 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev |
23.1.0
major
Dependencies (130)
+ 122 more |
|
22.12.0
minor
7 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev |
22.12.0
minor
Dependencies (128)
+ 120 more |
|
22.11.0
minor
7 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev |
22.11.0
minor
Dependencies (128)
+ 120 more |
|
22.10.0
minor
8 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
22.10.0
minor
Dependencies (122)
+ 114 more |
|
22.9.0
minor
8 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
22.9.0
minor
Dependencies (124)
+ 116 more |
|
22.8.0
minor
8 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
22.8.0
minor
Dependencies (124)
+ 116 more |
|
22.7.0
minor
8 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
22.7.0
minor
Dependencies (122)
+ 114 more |
|
22.6.0
minor
8 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
22.6.0
minor
Dependencies (80)
+ 72 more |
|
22.5.0
minor
8 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
22.5.0
minor
Dependencies (79)
+ 71 more |
|
22.4.0
minor
8 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
22.4.0
minor
Dependencies (79)
+ 71 more |
|
22.3.0
minor
8 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
22.3.0
minor
Dependencies (78)
+ 70 more |
|
22.2.0
minor
8 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
22.2.0
minor
Dependencies (77)
+ 69 more |
|
22.1.0
major
8 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39349
PYSEC-2026-1912
GHSA-9jcq-jf57-c62c
Jul 07, 2026
Privilege escalation via ApiTokensEndpoint
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactAn attacker with access to a token with few or no scopes can query There is no evidence that the issue was exploited on https://sentry.io. For self-hosted users, it is advised to rotate user auth tokens via PatchesThe issue was fixed in https://github.com/getsentry/sentry/pull/53850 and is available in the release 23.7.2 of sentry and self-hosted. WorkaroundsThere are no known workarounds. Affected versions
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
+ 14 more Show less
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
22.1.0
major
Dependencies (74)
+ 66 more |
|
21.12.0
minor
7 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-27197
PYSEC-2026-533
GHSA-ggmg-cqg6-j45g
Jun 29, 2026
Sentry: Improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. For self-hosted users, you are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. You can manage your two-factor authentication settings on your Account Settings > Security page. For step-by-step details, please see our helpdesk article. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.2.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42354
PYSEC-2026-534
GHSA-rcmw-7mc7-3rj7
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via Sentry's private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Self-hosted users are only vulnerable if the following conditions are met:
Patches
WorkaroundsUser account-based two-factor authentication prevents an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account. Users can manage their two-factor authentication settings through Account Settings > Security page. For step-by-step details, please see the Sentry helpdesk article. Resources
Please note that this is distinct vulnerability from the similar https://github.com/getsentry/sentry/security/advisories/GHSA-7pq6-v88g-wf3w from 2025. Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
26.4.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-22146
PYSEC-2026-532
GHSA-7pq6-v88g-wf3w
Jun 29, 2026
Sentry's improper authentication on SAML SSO process allows user impersonation
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactA critical vulnerability was discovered in the SAML SSO implementation of Sentry. It was reported to us via our private bug bounty program. The vulnerability allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. The victim email address must be known in order to exploit this vulnerability. Patches
WorkaroundsNo known workarounds. References
Affected versions
21.12.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
+ 15 more Show less
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
25.1.0
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.12.0
minor
Dependencies (73)
+ 65 more |
|
21.11.0
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.11.0
minor
Dependencies (72)
+ 64 more |
|
21.10.0
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.10.0
minor
Dependencies (75)
+ 67 more |
|
21.9.0
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.9.0
minor
Dependencies (74)
+ 66 more |
|
21.8.0
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.8.0
minor
Dependencies (73)
+ 65 more |
|
21.7.0
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.7.0
minor
Dependencies (73)
+ 65 more |
|
21.6.3
patch
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.6.3
patch
Dependencies (72)
+ 64 more |
|
21.6.2
patch
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.6.2
patch
Dependencies (73)
+ 65 more |
|
21.6.1
patch
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.6.1
patch
Dependencies (74)
+ 66 more |
|
21.6.0
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.6.0
minor
Dependencies (74)
+ 66 more |
|
21.5.1
patch
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.5.1
patch
Dependencies (73)
+ 65 more |
|
21.5.0
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.5.0
minor
Dependencies (73)
+ 65 more |
|
21.4.1
patch
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.4.1
patch
Dependencies (72)
+ 64 more |
|
21.4.0
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.4.0
minor
Dependencies (71)
+ 63 more |
|
21.3.1
patch
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.3.1
patch
Dependencies (71)
+ 63 more |
|
21.3.0
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.3.0
minor
Dependencies (70)
+ 62 more |
|
21.2.0
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.2.0
minor
Dependencies (73)
+ 65 more |
|
21.1.0
major
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
21.1.0
major
Dependencies (77)
+ 69 more |
|
20.12.1
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
20.12.1
minor
Dependencies (76)
+ 68 more |
|
20.11.1
patch
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
20.11.1
patch
Dependencies (76)
+ 68 more |
|
20.11.0
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
20.11.0
minor
Dependencies (76)
+ 68 more |
|
20.10.1
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
20.10.1
minor
Dependencies (76)
+ 68 more |
|
20.8.0
minor
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
20.8.0
minor
Dependencies (87)
+ 79 more |
|
20.7.2
patch
4 CVEs
CVE-2024-41656
PYSEC-2026-1914
GHSA-fm88-hc3v-3www
Jul 07, 2026
Sentry vulnerable to stored Cross-Site Scripting (XSS)
7.1
/ 10
High
Network
High
Low
Required
Unchanged
High
High
High
ImpactAn unsanitized payload sent by an Integration platform integration allows the storage of arbitrary HTML tags on the Sentry side. This payload could subsequently be rendered on the Issues page, creating a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability might lead to the execution of arbitrary scripts in the context of a user’s browser. Self-hosted Sentry users may be impacted if untrustworthy Integration platform integrations send external issues to their Sentry instance. PatchesThe patch has been released in Sentry 24.7.1 WorkaroundsFor Sentry SaaS customers, no action is needed. This has been patched on July 22, and even prior to the fix, the exploitation was not possible due to the strict Content Security Policy deployed on sentry.io site. For self-hosted users, we strongly recommend upgrading Sentry to the latest version. If it is not possible, you could enable CSP on your self-hosted installation with References
Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
24.7.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-39531
PYSEC-2026-1915
GHSA-hgj4-h2x3-rfx4
Jul 07, 2026
Sentry vulnerable to incorrect credential validation on OAuth token requests
6.5
/ 10
Medium
Network
High
Low
Required
Changed
High
Low
None
ImpactAn attacker with sufficient client-side exploits could retrieve a valid access token for another user during the OAuth token exchange due to incorrect credential validation. The client ID must be known and the API application must have already been authorized on the targeted user account. Remediation
WorkaroundsThere are no direct workarounds, but users should review applications authorized on their account (User Settings > Authorized Applications) and remove any that are no longer needed. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 44 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
23.5.2
23.6.0
23.6.1
23.6.2
23.7.0
23.7.1
Fixed in
23.7.2
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2023-36826
PYSEC-2023-130
GHSA-m4hc-m2v6-hfw8
Jul 25, 2023
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
Sentry is an error tracking and performance monitoring platform. Starting in version 8.21.0 and prior to version 23.5.2, an authenticated user can download a debug or artifact bundle from arbitrary organizations and projects with a known bundle ID. The user does not need to be a member of the organization or have permissions on the project. A patch was issued in version 23.5.2 to ensure authorization checks are properly scoped on requests to retrieve debug or artifact bundles. Authenticated users who do not have the necessary permissions on the particular project are no longer able to download them. Sentry SaaS users do not need to take any action. Self-Hosted Sentry users should upgrade to version 23.5.2 or higher. Affected versions
10.0.0
10.0.1
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
+ 45 more Show less
21.1.0
21.10.0
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.11.0
22.12.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
23.1.0
23.1.1
23.2.0
23.3.0
23.3.1
23.4.0
23.5.0
23.5.1
8.21.0
8.22.0
9.0.0
9.0.0rc1
9.1.0
9.1.1
9.1.2
Fixed in
23.5.2
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2022-23485
GHSA-jv85-mqxj-3f9j
PYSEC-2022-43011
Dec 12, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
6.4
/ 10
Medium
Network
High
None
Required
Unchanged
High
Low
Low
With a known valid invite link (i.e. not already accepted or expired) an unauthenticated attacker can manipulate the cookie to allow the same invite link to be reused on multiple accounts when joining an organization. ImpactAn attacker with a valid invite link can create multiple users and join the organization from which the invite link was generated. PatchesThis issue was patched in version 22.11.0. WorkaroundsSentry SaaS customers do not need to take action. Self-hosted Sentry installs can disable the invite functionality until they are ready to deploy the patched version by editing their
For more informationIf you have any questions or comments about this advisory:
Affected versions
20.10.1
20.11.0
20.11.1
20.12.0
20.12.1
20.6.0
20.7.0
20.7.1
20.7.2
20.8.0
21.1.0
21.10.0
+ 26 more Show less
21.11.0
21.12.0
21.2.0
21.3.0
21.3.1
21.4.0
21.4.1
21.5.0
21.5.1
21.6.0
21.6.1
21.6.2
21.6.3
21.7.0
21.8.0
21.9.0
22.1.0
22.10.0
22.2.0
22.3.0
22.4.0
22.5.0
22.6.0
22.7.0
22.8.0
22.9.0
Fixed in
22.11.0
References
Updated Oct 22, 2024 · Source: OSV.dev |
20.7.2
patch
Dependencies (87)
+ 79 more |