There is a moderate vulnerability in commons-lang3:3.13.0 (CVE-2025-48924) which is transitively included by opencsv and by commons-text
Updating opencsv from 5.9 to 5.12.0 and commons-text to 1.14.0 should address this as both libs update that dependency in there latest versions.