Not to mention that libxmlsec1 has some insane insecure defaults that are effectively undocumented.
(I'd go into more details, but i literally just sent a security report yesterday to a saml library for using it wrong, so i guess i shouldn't post publicly about it until they fix)