RHSA-2026:58957: Moderate: assertj-core security update
Published Aug 24, 2026
·Updated
A rich and intuitive set of strongly-typed assertions to use for unit testing (either with JUnit or TestNG).Security Fix(es): assertj: AssertJ: Information disclosure and denial of service via XML External Entity (XXE) (CVE-2026-24400) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
11 affected componentsFixes available
Red Hat Red Hat Enterprise Linux Server - AUS
Red Hat Red Hat Enterprise Linux for x86_64 - Extended Life Cycle
Red Hat Red Hat Enterprise Linux for ARM 64 - 4 years of updates
Red Hat Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle
Red Hat Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle
Red Hat Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle
Red Hat Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions
Red Hat Red Hat Enterprise Linux for IBM z Systems - 4 years of updates
redhat/assertj-core<3.19.0-5.el9_4.2
3.19.0-5.el9_4.2
redhat/assertj-core<3.19.0-5.el9_4.2
3.19.0-5.el9_4.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/assertj-coreto a version that resolves this vulnerability.Fixed in 3.19.0-5.el9_4.2 - Upgrade
Upgrade
assertj:assertjto a version that resolves this vulnerability.Patch CVE-2026-24400
Event History
Aug 24, 2026
Advisory Published
via Red Hat·12:00 AM
Data Sourced
via Red Hat·12:00 AM
RemedyDescriptionAffected Software
Advisory Published
via Red Hat·09:00 AM
Data Sourced
via Red Hat·09:00 AM
Severity