CVE-2026-24400Disclosure(assertj / assertj)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and prior to version 3.27.7, an XML External Entity (XXE) vulnerability exists in `org.assertj.core.util.xml.XmlStringPrettyFormatter`: the `toXmlDocument(String)` method initializes `DocumentBuilderFactory` with default settings, without disabling DTDs or external entities. This formatter is used by the `isXmlEqualTo(CharSequence)` assertion for `CharSequence` values. An application is vulnerable only when it uses untrusted XML input with either `isXmlEqualTo(CharSequence)` from `org.assertj.core.api.AbstractCharSequenceAssert` or `xmlPrettyFormat(String)` from `org.assertj.core.util.xml.XmlStringPrettyFormatter`. If untrusted XML input is processed by tone of these methods, an attacker couldnread arbitrary local files via `file://` URIs (e.g., `/etc/passwd`, application configuration files); perform Server-Side Request Forgery (SSRF) via HTTP/HTTPS URIs, and/or cause Denial of Service via "Billion Laughs" entity expansion attacks. `isXmlEqualTo(CharSequence)` has been deprecated in favor of XMLUnit in version 3.18.0 and will be removed in version 4.0. Users of affected versions should, in order of preference: replace `isXmlEqualTo(CharSequence)` with XMLUnit, upgrade to version 3.27.7, or avoid using `isXmlEqualTo(CharSequence)` or `XmlStringPrettyFormatter` with untrusted input. `XmlStringPrettyFormatter` has historically been considered a utility for `isXmlEqualTo(CharSequence)` rather than a feature for AssertJ users, so it is deprecated in version 3.27.7 and removed in version 4.0, with no replacement.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • assertj

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
assertj

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-28: 1Mentions · 2026-03-09: 1Mentions · 2026-03-25: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-25: 101-2803-0903-25
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-01-281
General1
2026-03-091
Disclosure1
2026-03-251
Disclosure1
Full discourse3 posts
  • Muriizio@Muriizio
    General

    CVE-2026-24400 in version 3.5.10

    Post summary

    The text only states the CVE identifier and affected version, with no additional context.

    0001034
    571 followersView on X
  • White Rabbitx@TheRabbitPy
    Disclosure

    🚨 CVE-2026-24400 AssertJ XML XXE in XmlStringPrettyFormatter—GitHub advisory, arbitrary file read. Testing libs compromised! https://access.redhat.com/security/cve/cve-2026-24400

    Post summary

    The tweet discusses a newly disclosed CVE‑2026‑24400 involving an AssertJ XML XXE flaw that permits arbitrary file reads, referencing a GitHub advisory but providing no PoC, exploit, or patch information.

    0000046
    434 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 AssertJ Core, XML External Entity (XXE), #CVE-2026-24400 (High) https://dailycve.com/assertj-core-xml-external-entity-xxe-cve-2026-24400-high/

    Post summary

    The note announces CVE-2026-24400 as a high‑severity XML External Entity (XXE) vulnerability affecting AssertJ Core.

    0000043
    166 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appassertjassertj---

Explore more