Generally BioJava produces bugfix releases, security or others, only for the latest major version series. Currently it is 5.4.x, but soon it will be 6.0.x.
Please report security issues by contacting the BioJava lead maintainer jose.duarte at rcsb.org . The lead maintainer will respond and acknowledge in no more than 1 week since receiving the message.