{
  "slug": "parser",
  "name": "Parsers, archives, and fail-open",
  "category": "Application",
  "summary": "Review file and document processing as a chain of bounded parsing, typed validation, storage, and authorized action.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "Parser and upload design",
    "Accepted file and archive policy",
    "Owned sample artifacts and unit tests"
  ],
  "review": [
    {
      "title": "Define accepted meaning",
      "body": "Specify supported formats, size and complexity budgets, encoding rules, and the safe typed result each parser may produce."
    },
    {
      "title": "Keep parsing contained",
      "body": "Run processing with minimal privileges and isolate it from sensitive filesystem, network, and interpreter authority."
    },
    {
      "title": "Validate after parsing",
      "body": "Treat parsed metadata and paths as untrusted until they satisfy an application-specific authorization and storage policy."
    },
    {
      "title": "Review failure behavior",
      "body": "Ensure malformed or unsupported input produces a bounded rejection without partial state or public diagnostics."
    }
  ],
  "outputs": [
    "Format acceptance contract",
    "Processing isolation notes",
    "Failure-handling tests"
  ],
  "pitfalls": [
    "Trusting declared content type",
    "Letting parsed paths select storage targets",
    "Converting parser errors into permissive behavior"
  ],
  "references": {
    "resources": [
      {
        "id": "chromium-rule-of-two-input-isolation",
        "title": "Chromium Rule of Two: input trust, memory safety and privilege",
        "url": "https://vulns.co/research/resources/chromium-rule-of-two-input-isolation/"
      },
      {
        "id": "pypdf-2026-attachment-processing-cost-boundary",
        "title": "pypdf: bound repeated work when reading embedded attachments",
        "url": "https://vulns.co/research/resources/pypdf-2026-attachment-processing-cost-boundary/"
      },
      {
        "id": "owasp-error-response-data-minimization",
        "title": "Error Handling Cheat Sheet",
        "url": "https://vulns.co/research/resources/owasp-error-response-data-minimization/"
      }
    ],
    "diagrams": [
      {
        "id": "parsing-safety-action-authority",
        "title": "Parsing safety and action authority",
        "url": "https://vulns.co/research/diagrams/parsing-safety-action-authority/"
      },
      {
        "id": "error-diagnostic-disclosure-boundary",
        "title": "Failures need separate public and diagnostic contracts",
        "url": "https://vulns.co/research/diagrams/error-diagnostic-disclosure-boundary/"
      }
    ],
    "reports": [
      {
        "id": "google-chrome-v8-type-consistency-2025",
        "title": "V8 optimized object handling retained invalid type assumptions",
        "url": "https://vulns.co/research/reports/google-chrome-v8-type-consistency-2025/"
      },
      {
        "id": "redis-lua-object-lifetime-isolation-2025",
        "title": "Redis Lua object lifetime failure crossed the scripting boundary",
        "url": "https://vulns.co/research/reports/redis-lua-object-lifetime-isolation-2025/"
      },
      {
        "id": "facebook-error-response-data-isolation-2019",
        "title": "Facebook error responses exposed unintended application data",
        "url": "https://vulns.co/research/reports/facebook-error-response-data-isolation-2019/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/parser/",
  "markdown_url": "https://vulns.co/skills/parser/SKILL.md"
}
