The following CVEs are popping up against apache commons compress: CVE-2024-25710, CVE-2024-26308 The suggested remedy is to bump to version 1.26.0. I'll follow up with a PR.