Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
https://github.com/advisories/GHSA-78vv-qj73-h9m5
https://www.oracle.com/security-alerts/cpuoct2020.html