RHSA-2026:58949: Moderate: assertj-core security update
A rich and intuitive set of strongly-typed assertions to use for unit testing (either with JUnit or TestNG).Security Fix(es): assertj: AssertJ: Information disclosure and denial of service via XML External Entity (XXE) (CVE-2026-24400) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/assertj-coreto a version that resolves this vulnerability.Fixed in 3.19.0-9.el9_6.1
Event History
Frequently Asked Questions
Which Red Hat environments are covered by this advisory?
The advisory lists assertj-core for Red Hat Enterprise Linux on x86_64, ARM 64, Power little endian, and IBM z Systems. It includes Extended Update Support, Extended Life Cycle, and Power LE Update Services for SAP Solutions offerings.
Does the supplied advisory data identify a fixed package version?
No fixed assertj-core package version is included in the supplied data. Teams should consult the referenced Red Hat erratum for the applicable update details.