GHSA-6465-jgvq-jhgp

Suggest an improvement
Source
https://github.com/advisories/GHSA-6465-jgvq-jhgp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/11/GHSA-6465-jgvq-jhgp/GHSA-6465-jgvq-jhgp.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-6465-jgvq-jhgp
Aliases
Related
Published
2025-11-24T21:52:45Z
Modified
2025-11-27T20:42:49.064371Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:L CVSS Calculator
Summary
Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true`
Details

Impact

In version 10.11.0, a change to how the SDK collects request data in Node.js applications caused certain incoming HTTP headers to be added as trace span attributes. When sendDefaultPii: true was set, a few headers that were previously redacted - including Authorization and Cookie - were unintentionally allowed through.

Sentry’s server-side scrubbing (handled by Sentry's Relay edge proxy) normally serves as a second layer of protection. However, because it relied on the same matching logic as the SDK, it also failed to catch these headers in this case.

Users may be impacted if:

  1. Their Sentry SDK configuration has sendDefaultPii set to true
  2. Their application uses one of the Node.js Sentry SDKs with version from 10.11.0 to 10.26.0 inclusively:
  • @sentry/astro
  • @sentry/aws-serverless
  • @sentry/bun
  • @sentry/google-cloud-serverless
  • @sentry/nestjs
  • @sentry/nextjs
  • @sentry/node
  • @sentry/node-core
  • @sentry/nuxt
  • @sentry/remix
  • @sentry/solidstart
  • @sentry/sveltekit

Users can check if their project was affected, by visiting Explore → Traces and searching for “http.request.header.authorization”, “http.request.header.cookie” or similar. Any potentially sensitive values will be specific to users' applications and configurations.

Patches

The issue has been patched in all Sentry JavaScript SDKs starting from the 10.27.0 version.

Workarounds

Sentry strongly encourage customers to upgrade the SDK to the latest available version, 10.27.0 or later. If it is not possible, consider setting sendDefaultPii: false to avoid unintentionally sending sensitive headers. See here for documentation.

Resources

  • https://develop.sentry.dev/sdk/expected-features/data-handling/#sensitive-data
  • https://github.com/getsentry/sentry-javascript/releases/tag/10.11.0
  • https://github.com/getsentry/sentry-javascript/pull/17475
  • https://docs.sentry.io/platforms/javascript/guides/node/data-management/data-collected/#cookies
Database specific
{
    "cwe_ids": [
        "CWE-201"
    ],
    "github_reviewed": true,
    "severity": "MODERATE",
    "nvd_published_at": "2025-11-25T01:15:46Z",
    "github_reviewed_at": "2025-11-24T21:52:45Z"
}
References

Affected packages

npm

@sentry/node

Package

Name
@sentry/node
View open source insights on deps.dev
Purl
pkg:npm/%40sentry/node

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.27.0

@sentry/astro

Package

Name
@sentry/astro
View open source insights on deps.dev
Purl
pkg:npm/%40sentry/astro

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.27.0

@sentry/aws-serverless

Package

Name
@sentry/aws-serverless
View open source insights on deps.dev
Purl
pkg:npm/%40sentry/aws-serverless

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.27.0

@sentry/bun

Package

Name
@sentry/bun
View open source insights on deps.dev
Purl
pkg:npm/%40sentry/bun

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.27.0

@sentry/google-cloud-serverless

Package

Name
@sentry/google-cloud-serverless
View open source insights on deps.dev
Purl
pkg:npm/%40sentry/google-cloud-serverless

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.27.0

@sentry/nestjs

Package

Name
@sentry/nestjs
View open source insights on deps.dev
Purl
pkg:npm/%40sentry/nestjs

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.27.0

@sentry/nextjs

Package

Name
@sentry/nextjs
View open source insights on deps.dev
Purl
pkg:npm/%40sentry/nextjs

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.27.0

@sentry/node-core

Package

Name
@sentry/node-core
View open source insights on deps.dev
Purl
pkg:npm/%40sentry/node-core

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.27.0

@sentry/nuxt

Package

Name
@sentry/nuxt
View open source insights on deps.dev
Purl
pkg:npm/%40sentry/nuxt

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.27.0

@sentry/remix

Package

Name
@sentry/remix
View open source insights on deps.dev
Purl
pkg:npm/%40sentry/remix

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.27.0

@sentry/solidstart

Package

Name
@sentry/solidstart
View open source insights on deps.dev
Purl
pkg:npm/%40sentry/solidstart

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.27.0

@sentry/sveltekit

Package

Name
@sentry/sveltekit
View open source insights on deps.dev
Purl
pkg:npm/%40sentry/sveltekit

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.27.0