Xz package contains a vulnerability

And do you understand why they are recommending that?