PT-2026-52105 · Sentry · Sentry
CVE-2026-52794
·
Published
2026-06-24
·
Updated
2026-06-27
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Sentry versions 24.4.0 through 26.5.1
Description
A Regular Expression Denial of Service (ReDoS) exists in the event ingestion pipeline. This occurs when a regular expression is applied to attacker-controlled fields on incoming events, allowing the system to consume disproportionate CPU time. ReDoS is a type of attack where a complex regular expression is processed against a specifically crafted input string, causing the engine to take an exponential amount of time to complete the match.
Recommendations
Update to version 26.5.2.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sentry