An ingestion job parses documents written by someone else, so its parser is attack surface. XML's risks come from features feeds rarely need (entity declarations, external references) and from queries built from strings. The defences are configuration, shown here on this machine's own parsers with two more tools:
sudo apt-get install -y -qq xmlsec1 > /dev/null && xmlsec1 --version
~/de-venv/bin/pip install --quiet defusedxml==0.7.1Output
xmlsec1 1.3.9 (openssl)