CVE-2026-40324Disclosure

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Utf8GraphQLParser` has no recursion depth limit. A crafted GraphQL document with deeply nested selection sets, object values, list values, or list types can trigger a `StackOverflowException` on payloads as small as 40 KB. Because `StackOverflowException` is uncatchable in .NET (since .NET 2.0), the entire worker process is terminated immediately. All in-flight HTTP requests, background `IHostedService` tasks, and open WebSocket subscriptions on that worker are dropped. The orchestrator (Kubernetes, IIS, etc.) must restart the process. This occurs before any validation rules run — `MaxExecutionDepth`, complexity analyzers, persisted query allow-lists, and custom `IDocumentValidatorRule` implementations cannot intercept the crash because `Utf8GraphQLParser.Parse` is invoked before validation. The `MaxAllowedFields=2048` limit does not help because the crashing payloads contain very few fields. The fix in versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14 adds a `MaxAllowedRecursionDepth` option to `ParserOptions` with a safe default, and enforces it across all recursive parser methods (`ParseSelectionSet`, `ParseValueLiteral`, `ParseObject`, `ParseList`, `ParseTypeReference`, etc.). When the limit is exceeded, a catchable `SyntaxException` is thrown instead of overflowing the stack. There is no application-level workaround. `StackOverflowException` cannot be caught in .NET. The only mitigation is to upgrade to a patched version. Operators can reduce (but not eliminate) risk by limiting HTTP request body size at the reverse proxy or load balancer layer, though the smallest crashing payload (40 KB) is well below most default body size limits and is highly compressible (~few hundred bytes via gzip).

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-18); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-17: 1Mentions · 2026-04-18: 2Mentions · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-17: 1Patch / Workaround · 2026-04-18: 2Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-18: 2Technical Details · 2026-04-19: 104-1704-1804-19
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-171
Disclosure1
2026-04-182
Disclosure2
2026-04-191
Disclosure1
Full discourse4 posts
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 Critical CVEs Today: Image codecs and library pipelines (CVSS 9.1-9.8) Affected: SAIL; NovumOS; Hot Chocolate Internet-facing exposure dominates, led by image codecs and runtime libraries; fixes and mitigations below. • CVE-2026-40492 (CVSS 9.8) In SAIL, the XWD codec can read/write beyond the allocated buffer when pixmap_depth is 8 and bits_per_pixel is 32, prior to patch 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02; patched in commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02. • CVE-2026-40493 (CVSS 9.8) In SAIL, the PSD codec computes bytes-per-pixel from channels and depth but allocates the buffer differently, causing a heap overflow in LAB mode (channels=3, depth=16); patched in commit c930284445ea3ff94451ccd7a57c999eca3bc979. • CVE-2026-40494 (CVSS 9.8) In SAIL, the TGA codec's raw-packet path lacks an equivalent bounds check, allowing writes past the end of a heap buffer; patched in commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302. • CVE-2026-40317 (CVSS 9.3) NovumOS allows JumpToUser to transfer control to kernel addresses from user space in versions prior to 0.24; fixed in 0.24. • CVE-2026-40324 (CVSS 9.1) Hot Chocolate Utf8GraphQLParser has no recursion depth limit, enabling deeply nested payloads to trigger stack overflow; MaxAllowedRecursionDepth added and enforced across recursive parser methods, with fixes in 12.22.7, 13.9.16, 14.3.1, and 15.1.14. 🛠️ Action • Patch/upgrade to the fixed versions called out (or vendor advisory latest) • Prioritize internet-facing instances and edge appliances first • If "no fix yet", apply the stated mitigations and reduce exposure (disable feature/module, restrict access) • Add detections for the exploitation patterns implied by the CVEs (memory corruption paths, file-write paths, auth anomalies) • Hunt for indicators around the affected services during the disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post discloses newly identified high‑CVSS CVEs across image codecs and kernel components, provides detailed technical information and patch references, but offers no evidence of active exploitation or PoC.

    0000072
    99 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40324 Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Utf8GraphQLParser` … https://www.cve.org/CVERecord?id=CVE-2026-40324

    Post summary

    CVE-2026-40324 identifies a flaw in Hot Chocolate's Utf8GraphQLParser prior to specific releases; updating to 12.22.7, 13.9.16, 14.3.1, or 15.1.14 (or newer) should mitigate the issue.

    00000120
    57.2K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical stack overflow (CVE-2026-40324) impacts `ChilliCream GraphQL Platform`'s `Utf8GraphQLParser` via deep queries, risking DoS. Assess exposure; apply depth limits. #GraphQL #AppSec #DoS https://www.pulsepatch.io/posts/cve-2026-40324-chillicream-graphql-platform-stack-overflow

    Post summary

    The text announces a critical stack overflow vulnerability (CVE-2026-40324) in ChilliCream GraphQL Platform’s Utf8GraphQLParser that can lead to denial of service via deep queries, and recommends applying depth limits as a mitigation.

    0000063
    12 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40324: Hot C... 40KB payload = instant process kill via uncatchable StackOverflowException, bypassing all GraphQL validation layers. #GraphQL #DoS #StackOverflow. https://zerodaysignal.com/vulnerability/CVE-2026-40324 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet alerts on CVE‑2026‑40324, a GraphQL vulnerability that can be exploited with a 40 KB payload to trigger a stack overflow and kill processes; no exploit code or patch is mentioned.

    0000078
    218 followersView on X

Explore more