The server.c is exploitable and containes a buffer overflow. Please don't run the program on any public facing machine. I should not have to say this, but you never know what some people might do!! I ...
Low severity but cleanly fixable. Add NONET default documentation: Clearly document in the API reference that XML_PARSE_NONET should be used when parsing untrusted content, even though the built-in ...