THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gc95-3vw8-vg43 (high) — docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service

[GHSA] GHSA-gc95-3vw8-vg43 (high) — docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service

medgithub_advisoriesPublished 2026-08-17

GHSA-gc95-3vw8-vg43 Severity: high CVE: CVE-2026-53752

docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service

### Summary docx4j's `PropertyResolver` and several adjacent helpers recursively walk the OpenXML style inheritance chain (`w:basedOn`) without cycle detection.

A WordprocessingML document containing a cyclic style chain (for example, Style A based on B an

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gc95-3vw8-vg43