Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingestion pipeline, where a regex applied to attacker-controlled fields on incoming events can be made to consume disproportionate CPU time. This vulnerability is fixed in 26.5.2.
References
| Link | Resource |
|---|---|
| https://github.com/getsentry/sentry/pull/116587 | Issue Tracking Patch |
| https://github.com/getsentry/sentry/security/advisories/GHSA-jjqr-wqg2-p856 | Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-06-24 22:16
Updated : 2026-06-27 20:45
NVD link : CVE-2026-52794
Mitre link : CVE-2026-52794
CVE.ORG link : CVE-2026-52794
JSON object : View
Products Affected
sentry
- sentry
CWE
CWE-1333
Inefficient Regular Expression Complexity
