Nhdta-793 Link
The vendor has issued a patch (v3.5.0) that removes the vulnerable code path and introduces strict input validation. Until all deployments are updated, organizations should (network isolation, WAF rules, removal of the vulnerable library) and monitor for exploitation attempts using the detection signatures provided above.