Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks:
{
"cwe_ids": [
"CWE-835"
],
"github_reviewed": true,
"github_reviewed_at": "2020-11-06T18:56:32Z",
"nvd_published_at": "2018-01-29T17:29:00Z",
"severity": "HIGH"
}