CVE-2026-52794: Sentry

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingestion pipeline, where a regex applied to attacker-controlled fields on incoming events can be made to consume disproportionate CPU time. This vulnerability is fixed in 26.5.2.

Affected products

  • Sentry Sentry: from 24.4.0, before 26.5.2 (fixed in 26.5.2)

Published 2026-06-24. Last modified 2026-06-27.