I agree. +1

Am Sa., 22. Aug. 2026 um 07:07 Uhr schrieb Jacques Le Roux via dev <
[email protected]>:

> Hi Daniel,
>
> Sounds like a good idea to me
>
> Jacques
>
> Le 22/08/2026 à 00:33, Daniel Dekany a écrit :
> > In freemarker.ext.dom.NodeModel (main DOM-to-data-model wrapper) we have
> > these legacy static helpers in subject, and these all use a
> > DocumentBuilderFactory where external entity resolution is (probably) on,
> > and so they open the gate for XXE (XML External Entity) attacks, of
> someone
> > processes XML document from untrusted source. While this is documented
> > there, it's really easy to miss, and even just accidentally use
> > NodeModel.getDocumentBuilderFactory().
> >
> > I would like to  @Deprecate all of these, urgently, so if someone calls
> > them the IDE will warn them.
>

Reply via email to