Skip to content

CVE-2026-53752 org.docx4j:docx4j-core #206

Description

@tmuldoon

As shown in the following dependencies tree, grid-exporter-addon:3.1.0 is transitively dependent upon org.docx4j:docx4j-core:11.5.0 which in turn, has been recently tied to CVE-2026-53752...

+--- org.vaadin.addons.flowingcode:grid-exporter-addon:3.1.0
|    +--- org.apache.poi:poi:5.2.3
|    |    +--- commons-codec:commons-codec:1.15 -> 1.22.0
|    |    +--- org.apache.commons:commons-collections4:4.4 -> 4.5.0
|    |    +--- org.apache.commons:commons-math3:3.6.1
|    |    +--- commons-io:commons-io:2.11.0 -> 2.22.0
|    |    +--- com.zaxxer:SparseBitSet:1.2
|    |    \--- org.apache.logging.log4j:log4j-api:2.18.0 -> 2.25.5
|    +--- com.opencsv:opencsv:5.6 -> 5.12.0 (*)
|    +--- org.docx4j:docx4j-JAXB-ReferenceImpl:11.5.0
|    |    +--- org.docx4j:docx4j-core:11.5.0

With that said, I am hoping that there are plans to remediate the vulnerability (presumably with a docx4j-core upgrade).

Expected behavior

No response

Minimal reproducible example

No response

Add-on Version

3.1.0

Vaadin Version

25.2.3

Additional information

No response

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions