Someone tries to DDoS the server by HLS requests. Maybe there is a vulnerability in some media servers they try to exploit. But WCS is proof, so you can ignore those logs or disable HLS at all if you don't use it:
hls_server_enabled=false
About NPE in logs: we raised the ticket WCS-4014 to...