gitlab.gnome.org/GNOME/libxml...
gitlab.gnome.org/GNOME/libxml...
gitlab.gnome.org/GNOME/libxml...
gitlab.gnome.org/GNOME/libxml...
It's not *just* been Project Zero sending vulnerability disclosures to the maintainer.
gitlab.gnome.org/GNOME/libxml...
It's not *just* been Project Zero sending vulnerability disclosures to the maintainer.
gitlab.gnome.org/GNOME/libxml...
https://github.com/bovine3dom/departures/blob/master/make_station_list/db/wrangler.jl
(iirc DB […]
https://github.com/bovine3dom/departures/blob/master/make_station_list/db/wrangler.jl
(iirc DB […]
• chrome inherited libxml/libxslt dependency from safari
• one of google's security guys fuzzed libxslt and found a shitton of memory bugs
• libxslt maintainer wouldn't fix; quit over it
• chrome team wants it out (i don't blame them for that)
• buuuut…
• chrome inherited libxml/libxslt dependency from safari
• one of google's security guys fuzzed libxslt and found a shitton of memory bugs
• libxslt maintainer wouldn't fix; quit over it
• chrome team wants it out (i don't blame them for that)
• buuuut…
gitlab.gnome.org/GNOME/libxml...
gitlab.gnome.org/GNOME/libxml...
> All the "best practices" like OpenSSF Scorecards are just an attempt by big tech companies to guilt trip OSS maintainers and make them work for free.
gitlab.gnome.org/GNOME/libxml...
> All the "best practices" like OpenSSF Scorecards are just an attempt by big tech companies to guilt trip OSS maintainers and make them work for free.
gitlab.gnome.org/GNOME/libxml...
Recently, the author of libxml2 refused to approach vulnerabilities professionally, because he isn’t paid for it.
gitlab.gnome.org/GNOME/libxml...
Recently, the author of libxml2 refused to approach vulnerabilities professionally, because he isn’t paid for it.
gitlab.gnome.org/GNOME/libxml...
"These companies make billions of profits and refuse to pay back their technical debt, either by switching to better solutions, developing their own or by trying to improve libxml2. Their behavior is irresponsible."
gitlab.gnome.org/GNOME/libxml...
"These companies make billions of profits and refuse to pay back their technical debt, either by switching to better solutions, developing their own or by trying to improve libxml2. Their behavior is irresponsible."
gitlab.gnome.org/GNOME/libxml...
URL: access.redhat.com/security/cve...
Classification: Critical, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
CVEs: CVE-2025-49794, CVE-2025-49795, CVE-2025-49796
URL: access.redhat.com/security/cve...
Classification: Critical, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
CVEs: CVE-2025-49794, CVE-2025-49795, CVE-2025-49796