When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
https://www.tenable.com/blog/oracle-april-2022-critical-patch-update-addresses-221-cves
https://www.tenable.com/blog/oracle-october-2021-critical-patch-update-addresses-231-cves
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpujan2022.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://security.netapp.com/advisory/ntap-20211022-0001/
https://commons.apache.org/proper/commons-compress/security-reports.html