GHSL-2025-130: Unauthorized access to event data across organizational boundaries in Sentry - CVE-2026-26004
Published Feb 20, 2026
·Updated
A cross-organization Insecure Direct Object Reference (IDOR) vulnerability has been identified in Sentry’s GroupEventJsonView endpoint.
Affected Software
1 affected component
Sentry sentry
Event History
Feb 20, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of GHSL-2025-130?
GHSL-2025-130 has a risk score of 65, indicating a medium severity level in terms of security threats.
2
How do I fix GHSL-2025-130?
To mitigate GHSL-2025-130, upgrade Sentry to version 25.12.0 or later, where the vulnerability is addressed.
3
What type of vulnerability is GHSL-2025-130?
GHSL-2025-130 is classified as an Insecure Direct Object Reference (IDOR) vulnerability.
4
What endpoint is affected by GHSL-2025-130?
The vulnerability affects the GroupEventJsonView endpoint in Sentry.
5
What potential impact does GHSL-2025-130 have?
GHSL-2025-130 allows unauthorized access to event data across organizational boundaries, posing a risk to sensitive information.