Skip to content
GSSA-2026-05-JHA9SZGITLAB-GSSA-2026-05-JHA9SZMay 4, 2026
5.1 Medium

Bearer tokens and webhook signatures could leak to Sentry

Sentry capture ran without a beforeSend filter, so caught errors carrying request metadata (Authorization headers, x-hub-signature-256, GitHub installation tokens, JWT bodies) could be serialized into Sentry events. Fixed by adding a recursive scrubber on both server and edge runtimes.

Affected (1)

  • gelhaus-solutionscontributer-checker
    • ≥ 0.0.0Fixed in 0.0.1

Mitigations

Workarounds

  • Set Sentry project-level data scrubbing rules to redact Authorization headers, Cookie, and any keys ending in _token/_secret/_password before events are stored.
  • Lower `sendDefaultPii` to false at the SDK level until 0.0.1 is deployed (loses some debugging fidelity but stops the Authorization header from being attached).
  • Restrict Sentry organization access to the smallest possible group of operators.

Solutions

  • Upgrade to 0.0.1: a new scrubSensitive helper runs in beforeSend AND beforeBreadcrumb on both the server and edge runtimes. It drops keys by name (authorization, cookie, x-hub-signature*, *_token, *_secret, *_password) and scrubs string content (Bearer ..., JWTs, ghs_*, ghp_/gho_/ghu_/ghr_*, sha256=<64-hex>) before transport.

Exploits

  • Passive: an operator with read access to the Sentry organization browses recent events. GitHub installation tokens (`ghs_*`), OIDC bearer tokens (`eyJ...`), and webhook HMAC signatures appear in event headers / breadcrumbs. The installation token can then be used against the GitHub API for any action the App is authorized for, until the token expires (~1 hour).

Configurations

  • All deployments of 0.0.0 with Sentry configured (SENTRY_DSN set). Browser SDK is intentionally unaffected — the leak is server-side only.

Overview

Sentry events could include OIDC bearer tokens, GitHub installation tokens, or webhook signatures because no scrubber was configured.

Severity

CVSS v4
5.1 Medium
5.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N
Attack vector
Network
Attack complexity
Low
Attack requirements
Present
Privileges required
High
User interaction
None
Confidentiality (vulnerable system)
None
Integrity (vulnerable system)
None
Availability (vulnerable system)
None
Confidentiality (subsequent system)
High
Integrity (subsequent system)
Low
Availability (subsequent system)
None
CVSS v3
6.0 Medium
6.0
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N
Attack vector
Network
Attack complexity
High
Privileges required
High
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None

Weaknesses (2)

References (4)

Credits (2)

  • Enno Gelhaus
    Remediation developer · egelhaus@ennogelhaus.de
  • Enno Gelhaus
    Finder · egelhaus@ennogelhaus.de

Context

Impacts

  • GitHub App installation tokens leak into Sentry, granting any Sentry reader the Apps full repo permissions for the tokens lifetime.

    CAPEC-37
  • GitHub Actions OIDC bearer tokens for the CI mode endpoint leak into Sentry, allowing replay against /api/ci/check-pr until token expiry.

  • Webhook HMAC signatures (`x-hub-signature-256`) leak into Sentry — does not directly forge new webhooks but reveals the HMAC of received payloads.

© 2026 Gelhaus Solutions