Media servers using the Cling library have recently been spotted has having a security issue:
https://www.exploit-db.com/exploits/45146/
https://www.exploit-db.com/exploits/45133/
https://www.exploit-db.com/exploits/45145/
The XML parser don't disable the inline DTDs parsing by default or do not provide a mean to disable it AFAIK.