RHSA-2026:58956: Moderate: assertj-core security update
A rich and intuitive set of strongly-typed assertions to use for unit testing (either with JUnit or TestNG).Security Fix(es): assertj: AssertJ: Information disclosure and denial of service via XML External Entity (XXE) (CVE-2026-24400) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/assertj-coreto a version that resolves this vulnerability.Fixed in 3.19.0-5.el9_2.2 - Upgrade
Upgrade
assertj/assertj-coreto a version that resolves this vulnerability.Patch CVE-2026-24400
Event History
Frequently Asked Questions
What is the impact of this issue?
The flaw can allow information disclosure and denial of service through XML External Entity (XXE) processing in AssertJ.
Which environments are identified as affected by this advisory?
The advisory lists Red Hat assertj-core and Red Hat Enterprise Linux offerings for ARM 64, x86_64, Power LE, and IBM z Systems, including Extended Life Cycle, AUS, SAP Update Services, and 4-year update variants.