THREAT OPS › Threat News › [GHSA] GHSA-gc95-3vw8-vg43 (high) — docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
[GHSA] GHSA-gc95-3vw8-vg43 (high) — docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
GHSA-gc95-3vw8-vg43 Severity: high CVE: CVE-2026-53752
docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service
### Summary docx4j's `PropertyResolver` and several adjacent helpers recursively walk the OpenXML style inheritance chain (`w:basedOn`) without cycle detection.
A WordprocessingML document containing a cyclic style chain (for example, Style A based on B an
MITRE ATT&CK techniques
- ServerlessT1583.007
- ServerlessT1584.007
- ServerlessAML.T0008.004
Indicators of compromise
- CVE-2026-53752cve
Original source: https://github.com/advisories/GHSA-gc95-3vw8-vg43