Security Advisory – 18 Apr 2026

Security fixes and advisories that landed overnight. This daily security advisory summary covers one NIST notice in the current update. It focuses on the published issue and the details given in the advisory excerpt. Updated 18 Apr 2026 00:16 GMT.

Top items

NIST

CVE-2026-40324

Hot Chocolate’s recursive descent parser has no recursion depth limit before the fixed versions. A crafted GraphQL document can trigger a StackOverflowException and terminate the worker process.

  • Published: 18 Apr 2026 00:16 GMT
  • CVEs: CVE-2026-40324
  • Notes: crafted GraphQL document with deeply nested selection sets

Related posts

rclone | v1.73.5

rclone v1 73 5 released 2026 04 19: patch with fixes and backend updates, see changelog, test in staging, backup configs, pin versions, verify downloads

rclone | v1.73.5

rclone v1 73 5: maintenance release with fixes, backend updates and stability, assets and changelog on GitHub and rclone site, back up configs before upgrade

Security Advisory – 18 Apr 2026

Daily security advisory summary for 18 Apr 2026