CodeQL complains about use of XML parsing without disabling external document reading in:
kmip-client/src/main/java/ch/ntb/inf/kmip/config/ContextProperties.java
public void decode() {
SAXReader xmlReader = new SAXReader();
xmlReader.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true); -- add this line
}