As shown in the following dependencies tree, grid-exporter-addon:3.1.0 is transitively dependent upon org.docx4j:docx4j-core:11.5.0 which in turn, has been recently tied to CVE-2026-53752...
+--- org.vaadin.addons.flowingcode:grid-exporter-addon:3.1.0
| +--- org.apache.poi:poi:5.2.3
| | +--- commons-codec:commons-codec:1.15 -> 1.22.0
| | +--- org.apache.commons:commons-collections4:4.4 -> 4.5.0
| | +--- org.apache.commons:commons-math3:3.6.1
| | +--- commons-io:commons-io:2.11.0 -> 2.22.0
| | +--- com.zaxxer:SparseBitSet:1.2
| | \--- org.apache.logging.log4j:log4j-api:2.18.0 -> 2.25.5
| +--- com.opencsv:opencsv:5.6 -> 5.12.0 (*)
| +--- org.docx4j:docx4j-JAXB-ReferenceImpl:11.5.0
| | +--- org.docx4j:docx4j-core:11.5.0
With that said, I am hoping that there are plans to remediate the vulnerability (presumably with a docx4j-core upgrade).
Expected behavior
No response
Minimal reproducible example
No response
Add-on Version
3.1.0
Vaadin Version
25.2.3
Additional information
No response
As shown in the following dependencies tree, grid-exporter-addon:3.1.0 is transitively dependent upon org.docx4j:docx4j-core:11.5.0 which in turn, has been recently tied to CVE-2026-53752...
With that said, I am hoping that there are plans to remediate the vulnerability (presumably with a docx4j-core upgrade).
Expected behavior
No response
Minimal reproducible example
No response
Add-on Version
3.1.0
Vaadin Version
25.2.3
Additional information
No response