All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-2019-9658.
https://snyk.io/vuln/SNYK-JAVA-COMPUPPYCRAWLTOOLS-543266
https://lists.debian.org/debian-lts-announce/2020/02/msg00008.html