Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-24400

32
FAUCET Score

CVE-2026-24400 is an XML External Entity (XXE) vulnerability in AssertJ versions 1.4.0 through 3.27.6, specifically within the XmlStringPrettyFormatter and isXmlEqualTo(CharSequence) methods. This vulnerability allows an attacker to read local files, perform Server-Side Request Forgery (SSRF), or cause Denial of Service (DoS) if untrusted XML input is processed by these methods. With a CVSS score of 8.2 (High), the vulnerability has a low attack complexity and requires no user interaction, potentially leading to high confidentiality and availability impacts. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and concern.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.4.0, < 3.27.7CPE matchmatch criteria
cpe:2.3:a:assertj:assertj:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.2HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
HIGH
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.54%
Probability of exploitation in next 30 days
EPSS Percentile
42.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0054 is in the 22nd percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (38)

mavenpatch availablevia ghsa
Product: org.assertj:assertj-coreFixed in: 3.27.7
redhatvendor investigatingvia redhat_api
Product: AMQ ClientsFixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: OpenShift ServerlessFixed in: openshift-serverless-1/kn-ekb-dispatcher-rhel9
redhatvendor investigatingvia redhat_api
Product: OpenShift ServerlessFixed in: openshift-serverless-1/kn-ekb-receiver-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat AMQ Broker 7Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apache Camel 4 for Quarkus 3Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apache Camel for Spring Boot 4Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apache Camel - HawtIO 4Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apicurio Registry 3Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Debezium 2Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Debezium 3Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat build of OptaPlanner 8Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat Data Grid 8Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: moditect
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: javapackages-tools:201801/assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: javapackages-tools:201801/maven-surefire
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: javapackages-tools:201801/powermock
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: log4j:2/log4j
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: log4j
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: maven-enforcer
redhatvendor investigatingvia redhat_api
Product: Red Hat Fuse 7Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-trustyai-service-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-trustyai-service-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/dashboard-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/devspaces-operator-bundle
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/udi-base-rhel10
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/udi-base-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/udi-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Process Automation 7Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: Red Hat Single Sign-On 7Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: streams for Apache Kafka 2Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: streams for Apache Kafka 3Fixed in: assertj-core
redhatvendor investigatingvia redhat_api
Product: streams for Apache Kafka 3Fixed in: rocksdbjni

Vendor Advisories (2)

redhatCVE-2026-24400Moderate

assertj: AssertJ: Information disclosure and denial of service via XML External Entity (XXE)

Jan 26, 2026
mavenGHSA-rqfh-9r24-8c9rhigh

AssertJ has XML External Entity (XXE) vulnerability when parsing untrusted XML via isXmlEqualTo assertion

Jan 26, 2026

References

cheatsheetseries.owasp.org / cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html
Technical Description
github.com / assertj/assertj/commit/85ca7eb6609bb179c043b85ae7d290523b1ba79a
Patch
github.com / assertj/assertj/releases/tag/assertj-build-3.27.7
ProductRelease Notes
github.com / assertj/assertj/security/advisories/GHSA-rqfh-9r24-8c9r
MitigationVendor Advisory