Security fixes and advisories that landed overnight. This daily security advisory summary covers one NIST notice in the current update. It focuses on the published issue and the details given in the advisory excerpt. Updated 18 Apr 2026 00:16 GMT.
Top items
NIST
CVE-2026-40324
Hot Chocolate’s recursive descent parser has no recursion depth limit before the fixed versions. A crafted GraphQL document can trigger a StackOverflowException and terminate the worker process.
- Published: 18 Apr 2026 00:16 GMT
- CVEs: CVE-2026-40324
- Notes: crafted GraphQL document with deeply nested selection sets

