Skip to content

[FP]: io.sentry:sentry matched to getsentry:sentry CPE #8519

@wagnerlee

Description

@wagnerlee

Package URl

pkg:maven/io.sentry/sentry@8.16.0

CPE

cpe:2.3:a:sentry:sentry:8.41.0:::::::*

CVE

CVE-2023-36826
CVE-2026-26004
CVE-2025-53099

ODC Integration

None

ODC Version

dependency-check:12.2.0

Description

The Maven artifact io.sentry:sentry represents the Java SDK and not the Sentry platform/server product.

The reported CVEs affect the Sentry server/platform (getsentry:sentry) and are not applicable to the Java SDK artifact.

This appears to be a false positive caused by overly broad CPE matching due to the shared product name "sentry".

Please refine the CPE matching logic or provide official suppression guidance.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions