Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Reading XML ain't secure against malicious data either.


I don't know why you're downvoted, because this is exactly correct.

https://www.vsecurity.com//download/publications/XMLDTDEntit...

Granted, most modern parsers disable the features that can trigger this by default. But there's still a lot of code out there compiled against libraries that did not, and some of that code is still updated and extended today.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: