#xslt
⚠️ Ao abrir um sitemap XML no Google Chrome, é possível que tenha visto uma mensagem a informar que o suporte a XSLT será removido.

Saiba se esta alteração afeta o SEO do seu website, o que é o XSLT, e o que fazer.

www.mindseo.com/atualizacoes...
Aviso de remoção do XSLT no Chrome e impacto no SEO - MindSEO
Viu a mensagem do Chrome sobre a remoção do XSLT no sitemap XML? Saiba o que significa e porque é que o SEO do seu site não está em risco
www.mindseo.com
October 6, 2026 at 5:12 PM
📌 CVE-2026-100779 - Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firef... https://www.cyberhub.blog/cves/CVE-2026-100779
CVE-2026-100779
Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
www.cyberhub.blog
October 6, 2026 at 2:07 PM
oh yeah so this week's job is gonna be figure out wtf to do about the memoryholing of xslt

• replace sense atlas ui with some provisional thing
• some solution for all my other web properties
• i dunno should i take a swipe at implementing github.com/doriantaylor...?
GitHub - doriantaylor/swet: Standard Web Templates (a proposal)
Standard Web Templates (a proposal). Contribute to doriantaylor/swet development by creating an account on GitHub.
github.com
October 5, 2026 at 9:15 PM
I dislike the developers of the major web browsers. Their decisions have played part in the web being in the significantly worse state that it is today.

XSLT has low usage because they kept it at version 1.0 from 1999 instead of updating it. What is the logical choice? Remove it and tell people […]
Original post on procial.tchncs.de
procial.tchncs.de
October 5, 2026 at 2:22 PM
Thread about XSLT removal
eliminating xslt is a huge middle finger to the open web

this is something that has worked reliably for 25 literal years

i know because i have been using it for 25 literal years

the rationale is "it's old", "less than 1% use it", and that there are vulns in the implementation
i would like to wish a very hearty go suck yourself to the engineers at Google who can’t maintain one measly XSLT parser with all their infinite agentic budget
October 2, 2026 at 6:24 PM
so just as a footnote, the draft spec for xslt 4.0 was released the same week as that github issue: qt4cg.org/specificatio...

like xslt has been kept up and gets plenty of use, just in the publishing industry, not on the web
XSL Transformations (XSLT) Version 4.0
qt4cg.org
October 2, 2026 at 3:03 PM
and yeah my understanding is it the mozilla team was actually *more* aggressive about wanting to nuke xslt despite having their own implementation
October 2, 2026 at 3:01 PM
there are (at least) two rust implementations of xslt 3.0, just give one of them a hundred grand and some tokens
October 2, 2026 at 2:52 PM
Still, I wouldn’t be surprised if an urgent use case pops up that has been overlooked… that happens too. I’d imagine the remedy would be extending the timeline and working with the implementor(s) to migrate them on to another path rather than keep XSLT on the client side. :-(
October 2, 2026 at 2:49 PM
See also: meyerweb.com/eric/thought... which goes into more of the process wonkery stuff. I’ll add that removing client-side XSLT support was a common discussion topic even in the 2010s.
No, Google Did Not Unilaterally Decide to Kill XSLT
The Web Discourse has been spicy of late, and XSLT is to blame. Well, sort of. It’s complicated.
meyerweb.com
October 2, 2026 at 2:49 PM
When I worked on HTML5 Google and Microsoft staff were both keenly aware of how and where any given bit of the web platform is used, including intranets.

(This is not a defense of removing XSLT from client side browser support just a note from the trenches…)
October 2, 2026 at 2:49 PM
let's take those arguments in order:

it's old

yup it is. xslt 1.0 was designed in 1999 and the first in-browser implementation was MSIE 5.5 in 2001. i know because i remember where i was when i first used it

the browsers didn't keep up but it's up to version 4.0: qt4cg.org/specificatio...
XSL Transformations (XSLT) Version 4.0
qt4cg.org
October 2, 2026 at 1:51 PM
eliminating xslt is a huge middle finger to the open web

this is something that has worked reliably for 25 literal years

i know because i have been using it for 25 literal years

the rationale is "it's old", "less than 1% use it", and that there are vulns in the implementation
i would like to wish a very hearty go suck yourself to the engineers at Google who can’t maintain one measly XSLT parser with all their infinite agentic budget
October 2, 2026 at 1:46 PM
at least they can't mess up a simple xslt parser
October 2, 2026 at 5:20 AM
i would like to wish a very hearty go suck yourself to the engineers at Google who can’t maintain one measly XSLT parser with all their infinite agentic budget
October 1, 2026 at 8:54 PM
🚨 EUVD-2026-90762
📊 8.6/10
🏢 Apache Software Foundation

📝 Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quark...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-90762

#cybersecurity #infosec #cve #euvd
October 1, 2026 at 12:02 PM
CVE-2026-63219 - Unauthenticated file upload via missing Authorization on formatter Upload Endpoint
CVE-2026-55864 - Unauthenticated Server-Side Request Forgery in SLD Tool
CVE-2026-57582 - Reflected XSS via unsanitized Javascript Sink
CVE-2026-58400 - Remote Code Execution via unsafe Saxon XSLT
October 1, 2026 at 10:02 AM
Esta semana tengo un follón de mucho cuidado con la eliminación de XSLT en los navegadores web. Si digo lo que pienso de las tecnologías "revolucionarias" que nos iban a salvar y que acaban en la basura, me meten en la cárcel.
October 1, 2026 at 7:08 AM
Styling Your RSS Feed for Browsers: XSLT, CSS and Alternatives

https://postrss.com/style-rss-feed-xslt-browser/
Styling Your RSS Feed for Browsers: XSLT, CSS and Alternatives
postrss.com
October 1, 2026 at 6:22 AM
📌 CVE-2026-63498 - Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allo... https://www.cyberhub.blog/cves/CVE-2026-63498
CVE-2026-63498
Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments and request them with the inline=true parameter. The app/Http/
www.cyberhub.blog
September 30, 2026 at 6:37 AM
🚨 EUVD-2026-88931
📊 n/a

📝 Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88931

#cybersecurity #infosec #cve #euvd
September 29, 2026 at 2:06 PM
🚨 EUVD-2026-88942
📊 n/a

📝 Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88942

#cybersecurity #infosec #cve #euvd
September 29, 2026 at 2:05 PM
Back when the AI boom began I thought people would regret the failure of the semantic web.

I'm at a data event in Barcelona, and baby, it's back. Big time. Time to brush up on your XSLT. I mean, I've been able to mention UNVTD formats and people have understood what I am talking about.
September 29, 2026 at 1:55 PM
The notification goes to this page: chromestatus.com/feature/4709...

And it also links to this Chrome extension:
chromewebstore.google.com/search/XSLT%...
September 29, 2026 at 11:29 AM