You would use this for parsing data you know is safe.
Using a "tiny library" for parsing untrusted data is where the mistake is. Not in OP code.