can be confusing at first, but I really like it.
It's minimalistic, super fast and memory efficient. Furthermore it is available in many languages, not just in (see my sample code here).

#xmlreader #programming #php #xml #backend

Last updated 2 years ago

André E. Veltstra · @aeveltstra
455 followers · 8468 posts · Server mastodon.social

Today, a post got published to r/netsec, concerning a DOS and arbitrary code execution in when parsing it with 's . Though correct, maybe hyperbolic: the problem is not limited to Java, and it's possible nobody in the field uses that class. When I first learned about it, years ago, I switched from automated XML parsing to dedicated -based parsing. That's more cumbersome, for sure, but also more .

#reddit #vulnerability #xml #java #xmlreader #xpath #secure

Last updated 2 years ago