CVE-2026-52794: Sentry: Inefficient Regular Expression Complexity in sentry
Published Jun 24, 2026
·Updated
Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingestion pipeline, where a regex applied to attacker-controlled fields on incoming events can be made to consume disproportionate CPU time. This vulnerability is fixed in 26.5.2.
Affected Software
2 affected components
Sentry sentry>=24.4.0<26.5.2
Sentry sentry>=24.4.0<26.5.2
Remediation
Patch Available
Event History
Jun 24, 2026
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-52794?
CVE-2026-52794 has a high severity score of 7.5.
2
How do I fix CVE-2026-52794?
To fix CVE-2026-52794, upgrade Sentry to version 26.5.3 or later.
3
What type of vulnerability is CVE-2026-52794?
CVE-2026-52794 is a Regular Expression Denial of Service (ReDoS) vulnerability.
4
What versions of Sentry are affected by CVE-2026-52794?
CVE-2026-52794 affects Sentry versions from 24.4.0 to 26.5.2.
5
How can CVE-2026-52794 impact my application?
CVE-2026-52794 can lead to denial of service due to inefficient regex processing on attacker-controlled fields.