This isn’t one of those. Handing large amounts of unvalidated user input to these libraries is particularly dangerous.
8 karma · joined November 14, 2017
I also recommended a mitigation strategy for unsafe code. Complaining that security is too hard is the reason for the situation we find ourselves in as an industry.
You really have to run this kind of complex parsing in a disposable containerized environment to do it safely. Or do everything carefully and in a memory safe language.