Skip to content

Breadcrumbs bypass IExceptionFilter, leaking filtered exception messages into later events #5514

Description

@maxkatz6

Package

Sentry

.NET Flavor

.NET

.NET Version

10.0.400

OS

Any (not platform specific)

OS Version

10.0

Development Environment

Rider 2025.x (Windows)

Other Error Monitoring Solution

No

Other Error Monitoring Solution Name

No response

SDK Version

6.9.0

Self-Hosted Sentry Version

No response

Workload Versions

UseSentry or SentrySdk.Init call

SentrySdk.Init(o =>
{
    o.Dsn = "https://key@o0.ingest.sentry.io/0"; // any DSN; nothing is actually sent below
    o.AddExceptionFilterForType<MyException>();

    // Only here to inspect what would be sent
    o.SetBeforeSend((e, _) =>
    {
        Console.WriteLine($"BeforeSend: {e.Message?.Formatted ?? e.Message?.Message ?? e.Exception?.Message}");
        foreach (var b in e.Breadcrumbs ?? new List<Breadcrumb>())
        {
            Console.WriteLine($"  breadcrumb: [{b.Category}] {b.Message}");
        }
        return null;
    });
});

Steps to Reproduce

using Sentry;

class MyException : Exception
{
    public MyException(string m) : base(m) { }
}

class Program
{
    static void Main()
    {
        using var _ = SentrySdk.Init(o => { /* see above */ });

        // Doesn't have to be an explicit CaptureException, it can be reproduced with implicit unhandled exceptions too
        SentrySdk.CaptureException(new MyException("secret exception message"));

        SentrySdk.CaptureMessage("some later unrelated event");
    }
}
  1. Register an exception filter for MyException.
  2. Capture a MyException - it's filtered out as expected.
  3. Capture any later, unrelated event (message or more likely a span).

repro.zip

Expected Result

An exception dropped by an IExceptionFilter leaves no trace.
No breadcrumb carrying its message on subsequent events.

Actual Result

The later event carries a breadcrumb with the filtered exception's message:

BeforeSend: some later unrelated event
  breadcrumb: [Exception] secret exception message

Activity

  1. added
    BugSomething isn't working
    .NETPull requests that update .net code
    on Aug 27, 2026
  2. linear-code commented on Aug 27, 2026

    @linear-code
  3. moved this to Waiting for: Product Owner in GitHub Issues with 👀 3on Aug 27, 2026
  4. maxkatz6 commented on Aug 27, 2026

    @maxkatz6
    ContributorAuthor

    It is possible to filter/process breadcrumbs before they are sent. But at this point we lost exception context and its type, forcing filtering by a string alone.

    And speaking of that, Sentry Scrubbing doesn't have an option to scrub breadcrumbs as it seems - no $breadcrumb defined in the Source list. I tried to set [Mask] [Usernames in filepaths] from [$breadcrumb] blindly, but it didn't seem to scrub anything.

  5. jamescrosswell commented on Aug 31, 2026

    @jamescrosswell
    Collaborator

    Hi @maxkatz6 - interesting problem. I'll do some digging to see it there is already an established way to avoid this in other SDKs.

    Sentry Scrubbing doesn't have an option to scrub breadcrumbs as it seems - no $breadcrumb defined in the Source list.

    Not sure I follow... what are you configuring where and what are you seeing vs what you expect?

  6. moved this from Waiting for: Product Owner to No status in GitHub Issues with 👀 3on Aug 31, 2026
  7. jamescrosswell commented on Aug 31, 2026

    @jamescrosswell
    Collaborator

    @maxkatz6 I've added a solution roughly based on what we do in the sentry-java SDK... there, they don't actually create breadcrumbs for all exceptions but they do when the exception gets captured via one of the logging integrations. In that scenario, they pass the log into the BeforeBreadcrumb callback as a Hint.

    In sentry-dotnet we add breadcrumbs for exceptions regardless of whether these get captured via the logging API, by one of our integrations or whether you capture them manually. So for .NET I figured we could pass the Exception itself in to the callback as a Hint:

  8. maxkatz6 commented on Sep 1, 2026

    @maxkatz6
    ContributorAuthor

    @jamescrosswell thanks. Yes, BeforeBreadcrumb filtration + exception hint works for me.

    Not sure I follow... what are you configuring where and what are you seeing vs what you expect?

    I was talking about https://****.sentry.io/settings/security-and-privacy/ "Advanced Data Scrubbing" section. Doesn't seem to be possible to scrub breadcrumbs contents, unless I miss something. But it's not a .NET client issue.

  9. moved this to Waiting for: Product Owner in GitHub Issues with 👀 3on Sep 1, 2026
  10. jamescrosswell commented on Sep 1, 2026

    @jamescrosswell
    Collaborator

    BeforeBreadcrumb filtration + exception hint works for me.

    Cool, thanks for validating 👍🏻

    https://****.sentry.io/settings/security-and-privacy/ "Advanced Data Scrubbing" section. Doesn't seem to be possible to scrub breadcrumbs contents

    Aha, I see. Possibly something to raise with the core product team.

  11. moved this from Waiting for: Product Owner to No status in GitHub Issues with 👀 3on Sep 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    .NETPull requests that update .net codeBugSomething isn't workingLogs

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions