Security Advisory – 18 Apr 2026

Security fixes and advisories that landed overnight. This daily security advisory summary covers one NIST notice in the current update. It focuses on the published issue and the details given in the advisory excerpt. Updated 18 Apr 2026 00:16 GMT.

Top items

NIST

CVE-2026-40324

Hot Chocolate’s recursive descent parser has no recursion depth limit before the fixed versions. A crafted GraphQL document can trigger a StackOverflowException and terminate the worker process.

  • Published: 18 Apr 2026 00:16 GMT
  • CVEs: CVE-2026-40324
  • Notes: crafted GraphQL document with deeply nested selection sets

Related posts

Privacy boundaries when AI touches government records

AI governance gets awkward fast when government records are involved, because the model is rarely the problem. The problem is the sloppy boundary around it, the sort I have seen quietly turn a...

Metadata schema choices for content libraries

Structured metadata only works when it matches how people actually retrieve content. I have seen neat schemas fail as soon as the library meets real records, and tarot makes the problem obvious. If...

Federation trade-offs in self-hosted social feeds

Federation looks tidy until you let it touch the edges, and then the odd cases arrive fast. I prefer self-hosted social feeds that stay explicit about what is local, what is remote, and what should...