See tracker for details, though there don't seem to be any yet..
Vulnerability is in bcel according to https://www.openwall.com/lists/oss-security/2022/10/18/2, which we're depending on in the ebuild. Fix will have to be there, so nothing for xalan to do.