https://bz.apache.org/bugzilla/show_bug.cgi?id=69557
--- Comment #5 from PJ Fanning <fannin...@yahoo.com> --- POI is a 20 year old project and lots of users have successfully used it. Most users are willing to spend time on tweaking the code and configs. And I repeat - there are streaming APIs provided. I say this emphatically - do not accept xlsx files (or any MS format like it) from untrusted parties. There are numerous ways to hack the formats to cause read issues. You might want to read up on why we named the project as POI. We strongly recommend that POI is run in a sandbox environment so that problematic files and crashes that they can cause will not lead to issues with other jobs that you are running. There are other libraries too so you can use those if you are unhappy with POI. -- You are receiving this mail because: You are the assignee for the bug. --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@poi.apache.org For additional commands, e-mail: dev-h...@poi.apache.org