<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Denial-of-Service on pok3 // security notes</title><link>https://pok3.xyz/tags/denial-of-service/</link><description>Recent content in Denial-of-Service on pok3 // security notes</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 27 Sep 2026 15:13:38 -0400</lastBuildDate><atom:link href="https://pok3.xyz/tags/denial-of-service/index.xml" rel="self" type="application/rss+xml"/><item><title>Parsing YAML is a minefield</title><link>https://pok3.xyz/posts/parsing-yaml-is-a-minefield/</link><pubDate>Sun, 27 Sep 2026 15:13:38 -0400</pubDate><guid>https://pok3.xyz/posts/parsing-yaml-is-a-minefield/</guid><description>&lt;p&gt;Not long ago I was researching the behavior of YAML parsing libraries as part of my master&amp;rsquo;s thesis. Since there is a &#10;&lt;a href="https://yaml.org/spec/1.2.2/" class="ext" target="_blank" rel="noopener noreferrer"&gt;YAML specification&lt;/a&gt;&#10;, I wanted to assess whether the parsing libraries listed on the official &#10;&lt;a href="https://yaml.org/libraries/" class="ext" target="_blank" rel="noopener noreferrer"&gt;yaml.org&lt;/a&gt;&#10; website comply with the current specification. My idea is hugely inspired by Nicolas Seriot&amp;rsquo;s &#10;&lt;a href="https://seriot.ch/security/parsing_json.html" class="ext" target="_blank" rel="noopener noreferrer"&gt;Parsing JSON is a minefield&lt;/a&gt;&#10;^[&#10;&lt;a href="https://seriot.ch/security/parsing_json.html" class="ext" target="_blank" rel="noopener noreferrer"&gt;https://seriot.ch/security/parsing_json.html&lt;/a&gt;&#10;], which I definitely recommend reading.&lt;/p&gt;</description></item></channel></rss>