
CVE-2026-24400 in version 3.5.10
Post summary
The text only states the CVE identifier and affected version, with no additional context.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and prior to version 3.27.7, an XML External Entity (XXE) vulnerability exists in `org.assertj.core.util.xml.XmlStringPrettyFormatter`: the `toXmlDocument(String)` method initializes `DocumentBuilderFactory` with default settings, without disabling DTDs or external entities. This formatter is used by the `isXmlEqualTo(CharSequence)` assertion for `CharSequence` values. An application is vulnerable only when it uses untrusted XML input with either `isXmlEqualTo(CharSequence)` from `org.assertj.core.api.AbstractCharSequenceAssert` or `xmlPrettyFormat(String)` from `org.assertj.core.util.xml.XmlStringPrettyFormatter`. If untrusted XML input is processed by tone of these methods, an attacker couldnread arbitrary local files via `file://` URIs (e.g., `/etc/passwd`, application configuration files); perform Server-Side Request Forgery (SSRF) via HTTP/HTTPS URIs, and/or cause Denial of Service via "Billion Laughs" entity expansion attacks. `isXmlEqualTo(CharSequence)` has been deprecated in favor of XMLUnit in version 3.18.0 and will be removed in version 4.0. Users of affected versions should, in order of preference: replace `isXmlEqualTo(CharSequence)` with XMLUnit, upgrade to version 3.27.7, or avoid using `isXmlEqualTo(CharSequence)` or `XmlStringPrettyFormatter` with untrusted input. `XmlStringPrettyFormatter` has historically been considered a utility for `isXmlEqualTo(CharSequence)` rather than a feature for AssertJ users, so it is deprecated in version 3.27.7 and removed in version 4.0, with no replacement.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-01-28 | 1 | General1 |
| 2026-03-09 | 1 | Disclosure1 |
| 2026-03-25 | 1 | Disclosure1 |

CVE-2026-24400 in version 3.5.10
Post summary
The text only states the CVE identifier and affected version, with no additional context.

🚨 CVE-2026-24400 AssertJ XML XXE in XmlStringPrettyFormatter—GitHub advisory, arbitrary file read. Testing libs compromised! https://access.redhat.com/security/cve/cve-2026-24400
Post summary
The tweet discusses a newly disclosed CVE‑2026‑24400 involving an AssertJ XML XXE flaw that permits arbitrary file reads, referencing a GitHub advisory but providing no PoC, exploit, or patch information.

🔴 AssertJ Core, XML External Entity (XXE), #CVE-2026-24400 (High) https://dailycve.com/assertj-core-xml-external-entity-xxe-cve-2026-24400-high/
Post summary
The note announces CVE-2026-24400 as a high‑severity XML External Entity (XXE) vulnerability affecting AssertJ Core.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | assertj | assertj | - | - | - |