#libxml
oh i see, $GOOG leaned on the guy to fix their bugs for free, on a deadline, under embargo, and he told them to piss off, and now they're just threatening to nuke XSLT out of chrome:

gitlab.gnome.org/GNOME/libxml...
August 15, 2025 at 1:09 AM
Refuses to work with anything other than a hideously vulnerable version of libxml
April 11, 2026 at 1:44 AM
kudos to @callum90ish.bsky.social for spotting that the libxml issue had got updated since I finished my piece
September 4, 2025 at 9:09 PM
This is a banger of a response, and honestly while I'm still very happy to have projects like Google's Project Zero, it does make me wonder if every bug report shouldn't come with either a dedicated engineer to FIX the OSS project, or a $ for a maintainer to fix it.

gitlab.gnome.org/GNOME/libxml...
Triaging security issues reported by third parties (#913) · Issues · GNOME / libxml2 · GitLab
I have to spend several hours each week dealing with security issues reported by third parties. Most of these issues aren't critical but it's still a lot of...
gitlab.gnome.org
June 19, 2025 at 5:34 PM
CVE-2025-1219: Critical PHP (libxml) vulnerability. Incorrect redirect handling bypasses validation in versions < 8.1.32, 8.2.28, 8.3.18, & 8.4.5. Update immediately.#PHPlibxmlVulnerability
March 31, 2025 at 8:18 AM
While there is much more that industry can do, and NEEDS to do, we should recognize that in the past Google has directly sponsored libxml2 development.

It's not *just* been Project Zero sending vulnerability disclosures to the maintainer.
gitlab.gnome.org/GNOME/libxml...
June 21, 2025 at 11:08 PM
@moof `less` if it's indented and huge, vim if it's indented and merely big. if it isn't indented, i use some binding to libxml in Julia to prod at it. but really i don't get on well with XML at all

https://github.com/bovine3dom/departures/blob/master/make_station_list/db/wrangler.jl

(iirc DB […]
Original post on masto.ai
masto.ai
September 25, 2026 at 11:27 PM
i’m just impressed that we finally moved past infinite libxml buffer overflows just so we could invent new ways to mess up parsing xml
June 21, 2025 at 6:12 PM
Here was I thinking you meant libxml
June 22, 2025 at 10:44 PM
tl;dr:

• chrome inherited libxml/libxslt dependency from safari
• one of google's security guys fuzzed libxslt and found a shitton of memory bugs
• libxslt maintainer wouldn't fix; quit over it
• chrome team wants it out (i don't blame them for that)
• buuuut…
February 7, 2026 at 1:53 PM
the issues with XSLT continue: the maintainer of libxml2 has stepped down (and plans to continue working on an AGPL fork which I'm sure every Linux distro with this in the build chain will have thoughts about). the new maintainer of libxsltc plans to help out but...
gitlab.gnome.org/GNOME/libxml...
Making sure you're not a bot!
gitlab.gnome.org
September 30, 2025 at 7:23 PM
Like imagine if every tiny util had an author who was getting a few hundred bucks a month, that would be awesome. Especially folks maintaining critical libraries like libxml, various GNOME libraries, etc. Would be awesome for them to get money for their work.
August 27, 2026 at 3:48 AM
it wasn't even an actual xml library either, just better bindings to libxml
July 18, 2024 at 2:26 PM
More relevant than ever.

> All the "best practices" like OpenSSF Scorecards are just an attempt by big tech companies to guilt trip OSS maintainers and make them work for free.

gitlab.gnome.org/GNOME/libxml...
May 15, 2025 at 8:18 AM
OK you know I said XSLT is a continuing source of drama (it's truly a perpetual motion machine of drama); the libxml maintainer is stepping down so someone else (Bueller?) can keep the MIT licenced version going for GNOME and the new browser polyfill while new code in his fork will be AGPL 🔥
September 4, 2025 at 9:03 PM
Why does XML::LibXML::Document's toString() give me a SCALAR instead of an #XML string ? <a href="http://stackoverflow.com/q/14954242/91034" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link" target="_blank" rel="noopener" data-link="bsky">http://stackoverflow.com/q/14954242/91034 #Perl
Why does XML::LibXML::Document's toString() give me "SCAL...
Here is a code sample that reproduces the behaviour I won...
stackoverflow.com
November 18, 2024 at 10:00 AM
libxmlがないとかでUnityが起動しなくなったんですがこれは一体
May 5, 2025 at 8:56 AM
When a large corporation starts using your library, it doesn’t give you much except increase workload. They pay pennies.

Recently, the author of libxml2 refused to approach vulnerabilities professionally, because he isn’t paid for it.

gitlab.gnome.org/GNOME/libxml...
Triaging security issues reported by third parties (#913) · Issues · GNOME / libxml2 · GitLab
I have to spend several hours each week dealing with security issues reported by third parties. Most of these issues aren't critical but it's still a lot of...
gitlab.gnome.org
June 23, 2025 at 2:37 PM
Microsoft, Apple, Google abusing #opensource

"These companies make billions of profits and refuse to pay back their technical debt, either by switching to better solutions, developing their own or by trying to improve libxml2. Their behavior is irresponsible."

gitlab.gnome.org/GNOME/libxml...
Triaging security issues reported by third parties (#913) · Issues · GNOME / libxml2 · GitLab
I have to spend several hours each week dealing with security issues reported by third parties. Most of these issues aren't critical but it's still a lot of...
gitlab.gnome.org
June 22, 2025 at 10:40 AM
To my Linux running peeps: update your systems today to get the latest version of libxml2 - there’s a security issue you’ll want to patch and libxml is _everywhere_.
September 5, 2025 at 3:44 AM
Multiple vulnerabilities in Libxml
URL: access.redhat.com/security/cve...
Classification: Critical, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
CVEs: CVE-2025-49794, CVE-2025-49795, CVE-2025-49796
cve-details
access.redhat.com
June 17, 2025 at 8:08 AM