SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.
{ "binaries": [ { "binary_name": "libsimple-xml-java", "binary_version": "2.7.1-1" } ] }