WhisperX tag archive

#CVE-2026-24400

This page collects WhisperX intelligence signals tagged #CVE-2026-24400. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-14 02:22:23 · GitHub Issues

1. AssertJ Core 3.24.2 曝高危 XXE 漏洞,解析不可信 XML 时存在安全风险

Java 测试库 AssertJ Core 的一个关键组件被发现存在高危安全漏洞。该漏洞位于 `org.assertj.core.util.xml.XmlStringPrettyFormatter` 类中,其 `toXmlDocument(String)` 方法在初始化 `DocumentBuilderFactory` 时使用了默认配置,未能禁用 DTD 或外部实体解析。这使得当应用程序使用 `isXmlEqualTo(CharSequence)` 断言来处理不可信的 XML 输入时,可能遭受 XML 外部实体攻击。 具体而言,该漏洞(标识为 GHSA-rqfh-9r24-8c9r,别名 CVE-2026-24400)被归类为 C...

The Lab · 2026-04-21 19:23:06 · GitHub Issues

2. AssertJ Core 3.27.7 Patches Critical XXE Vulnerability in XML Comparison Feature

A critical security vulnerability in the popular Java testing library AssertJ has been patched, forcing a mandatory update for millions of projects. The flaw, tracked as CVE-2026-24400, is an XML External Entity (XXE) vulnerability that resides within the library's `isXmlEqualTo` assertion. This function, used to compa...