3 ms·
I’m wondering which security risks they mean. I don’t see any security risk in XML itself, maybe it’s related to some XPath or XQuery functions?
by richx 6y ago
I’m wondering which security risks they mean. I don’t see any security risk in XML itself, maybe it’s related to some XPath or XQuery functions?
- barefootliam 6y agoI think more about the fact libxml and libxslt are large pieces of code and have had CVEs raised against them (and fixed) in the past. They are still actively maintained.
- foota 6y agoI think the idea is the increased security risk of potentially poorly maintained large body of code with a wide surface area.