I'm not a static typing person (I like Python, bash, and C), but I have resolved to write all future parsers in OCaml or a similar language.
For other types of code, if you don't have a code path explosion, you can do OK in C. For example, numerical simulation code.
Unfortunately async code in C like Nginx tends to also produce this code path explosion. And kernel code is also littered with state machines.
Another interesting thing is that SQLite's parser is generated with Lemon. It's not even a hand-written parser in C (like Lua), which would be much worse. I guess all the crashes were in the semantic actions of the parser?