What can I do to make an application using Expat resilient to malicious XML? Explosion of neither time nor space are acceptable in my case. Has anyone built a working solution before? I'd be happy to hear about your experience. Thanks in advance, Sebastian