It parses untrusted input, the library is basically unmaintained, it’s not often audited but anytime someone looks they find a CVE.