Your vulnerability scanner flagged your DLP installation with CVE-2025-23184 - Apache CXF DOS and you need to know if DLP is actually vulnerable.
DLP does not use enable CachedOutputStream temp file spooling, nor does it use streams large enough to cause automatic temp file spooling, hence it is not impacted by the vulnerability in CVE-2025-23184