RHSA-2026:59372: Moderate: assertj-core security update
A rich and intuitive set of strongly-typed assertions to use for unit testing (either with JUnit or TestNG).Security Fix(es): assertj: AssertJ: Information disclosure and denial of service via XML External Entity (XXE) (CVE-2026-24400) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/assertj-coreto a version that resolves this vulnerability.Fixed in 3.24.2-9.el10_2.1 - Upgrade
Upgrade
redhat/assertj-core-javadocto a version that resolves this vulnerability.Fixed in 3.24.2-9.el10_2.1 - Upgrade
Upgrade
assertj: AssertJto a version that resolves this vulnerability.Patch CVE-2026-24400