Security fixes and advisories that landed overnight. Updated 18 Apr 2026 00:16 GMT.
Top items
NIST
CVE-2026-40324
Hot Chocolate’s recursive descent parser has no recursion depth limit in affected versions. A crafted GraphQL document can trigger a StackOverflowException and terminate the worker process immediately.
- Published: 18 Apr 2026 00:16 GMT
- CVEs: CVE-2026-40324
- Notes: Fixes add a MaxAllowedRecursionDepth option


