Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.
https://github.com/advisories/GHSA-92j7-34x9-f3jw
http://www.securityfocus.com/bid/15765