VYPR

npm package

@sentry/nextjs

pkg:npm/%40sentry/nextjs

Vulnerabilities (2)

  • CVE-2025-65944MedNov 25, 2025
    affected >= 10.11.0, < 10.27.0fixed 10.27.0

    Sentry-Javascript is an official Sentry SDKs for JavaScript. From version 10.11.0 to before 10.27.0, when a Node.js application using the Sentry SDK has sendDefaultPii: true it is possible to inadvertently send certain sensitive HTTP headers, including the Cookie header, to Sentr

  • CVE-2023-46729Nov 10, 2023
    affected >= 7.26.0, < 7.77.0fixed 7.77.0

    sentry-javascript provides Sentry SDKs for JavaScript. An unsanitized input of Next.js SDK tunnel endpoint allows sending HTTP requests to arbitrary URLs and reflecting the response back to the user. This issue only affects users who have Next.js SDK tunneling feature enabled. Th