Security Advisory – 18 Apr 2026

Security fixes and advisories that landed overnight. Updated 18 Apr 2026 00:16 GMT.

Top items

NIST

CVE-2026-40324

Hot Chocolate’s recursive descent parser has no recursion depth limit in affected versions. A crafted GraphQL document can trigger a StackOverflowException and terminate the worker process immediately.

  • Published: 18 Apr 2026 00:16 GMT
  • CVEs: CVE-2026-40324
  • Notes: Fixes add a MaxAllowedRecursionDepth option

Related posts

rclone | v1.73.5

rclone v1 73 5: maintenance release with fixes, backend updates and stability, assets and changelog on GitHub and rclone site, back up configs before upgrade

Security Advisory – 18 Apr 2026

Daily security advisory summary for 18 Apr 2026

Sport bike power draw: battery backup planning for garages

A fast bike review can turn into a useful smart home power and noise checklist if you stop guessing and measure the garage properly. I prefer that to discovering, too late, that a tidy little charger,...