A curious search reveals that vulnerabilities that do exist are of 2 flavors.
1. Standard C memory vulnerabilities
2. Unsafe file traversal while unzipping
The entire second class is avoided in a fixed file format. The first class of vulnerabilities plague everything. A quick look at libxml2 CVEs shows that.
https://nvd.nist.gov/vuln/detail/CVE-2025-11001