CVE-2026-52794 Details
Description
Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingestion pipeline, where a regex applied to attacker-controlled fields on incoming events can be made to consume disproportionate CPU time. This vulnerability is fixed in 26.5.2.
A Regular Expression Denial-of-Service (ReDoS) vulnerability has been identified in Sentry's event ingestion pipeline, affecting versions 24.4.0 prior to 26.5.2. This vulnerability allows a regex applied to attacker-controlled fields in incoming events to consume excessive CPU time, degrading performance. While Sentry's SaaS platform has already addressed this issue, self-hosted users may experience reduced event ingestion throughput, impacting unrelated projects on the same instance.
Users are encouraged to upgrade to Sentry version 26.5.2 or later. For self-hosted instances, it is recommended to tighten per-DSN ingest rate limits on publicly exposed projects and to monitor for high CPU usage on taskworker processes and the events-consumer.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/getsentry/sentry/pull/116587 | [email protected] | Issue TrackingPatch |
| https://github.com/getsentry/sentry/security/advisories/GHSA-jjqr-wqg2-p856 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1333 | Inefficient Regular Expression Complexity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sentry sentry | >= 24.4.0, < 26.5.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 27, 2026 | Initial Analysis | [email protected] |
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 24, 2026 | New CVE Received | [email protected] |