Parsing of Extensible Metadata Platform (XMP) within a PDF.
The XML parser is not securely configured.
This is a replay of CVE-2016-2175.
This vulnerability is buried fairly deeply in the codebase. The vulnerability should be easy to fix, but finding it in the full codebase and generating a proof of vulnerability are both good challenges.