RHSA-2026:60215: Moderate: assertj-core security update
A rich and intuitive set of strongly-typed assertions to use for unit testing (either with JUnit or TestNG).Security Fix(es): assertj: AssertJ: Information disclosure and denial of service via XML External Entity (XXE) (CVE-2026-24400) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/assertj-coreto a version that resolves this vulnerability.Fixed in 3.19.0-9.el9_8.1 - Upgrade
Upgrade
assertj-core security updateto a version that resolves this vulnerability.Patch CVE-2026-24400
Event History
Frequently Asked Questions
What security impacts are addressed by this update?
The update addresses CVE-2026-24400, an XML External Entity (XXE) issue in AssertJ that can lead to information disclosure and denial of service.
Which software component is covered by this advisory?
This advisory applies to the Red Hat assertj-core package.