CVE Explorer
CVE-2026-40324
Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Utf8GraphQLParser` has no recursion depth limit. A crafted GraphQL document with deeply nested selection sets, object values, list values, or list types can trigger a `StackOverflowException` on payloads as small as 40 KB. Because `StackOverflowException` is uncatchable in .NET (since .NET 2.0), the entire worker process is terminated immediately. All
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"graphql-platform","vendor":"ChilliCream","versions":[{"status":"affected","version":"< 12.22.7"},{"status":"affected","version":">= 13.0.0, < 13.9.16"},{"status":"affected","version":">= 14.0.0, < 14.3.1"},{"status":"affected","version":">= 15.0.0, < 15.1.14"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-674","description":"CWE-674: Uncontrolled Recursion","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/problemTypes/0/descriptions/0
Source references
12 source assertions{"name":"https://github.com/ChilliCream/graphql-platform/commit/08c0caa42ca33c121bbed49d2db892e5bf6fb541","tags":["x_refsource_MISC"],"url":"https://github.com/ChilliCream/graphql-platform/commit/08c0caa42ca33c121bbed49d2db892e5bf6fb541"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/references/4
{"name":"https://github.com/ChilliCream/graphql-platform/commit/4cbaf67d366f800fc1e484bc5c06dfcf27b45023","tags":["x_refsource_MISC"],"url":"https://github.com/ChilliCream/graphql-platform/commit/4cbaf67d366f800fc1e484bc5c06dfcf27b45023"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/references/5
{"name":"https://github.com/ChilliCream/graphql-platform/commit/b185eb276c9ee227bd44616ff113be7f01a66c69","tags":["x_refsource_MISC"],"url":"https://github.com/ChilliCream/graphql-platform/commit/b185eb276c9ee227bd44616ff113be7f01a66c69"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/references/6
{"name":"https://github.com/ChilliCream/graphql-platform/commit/b9271e6a500484c002fd528dcd34d1a9b445480f","tags":["x_refsource_MISC"],"url":"https://github.com/ChilliCream/graphql-platform/commit/b9271e6a500484c002fd528dcd34d1a9b445480f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/references/7
{"name":"https://github.com/ChilliCream/graphql-platform/pull/9528","tags":["x_refsource_MISC"],"url":"https://github.com/ChilliCream/graphql-platform/pull/9528"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/references/1
{"name":"https://github.com/ChilliCream/graphql-platform/pull/9530","tags":["x_refsource_MISC"],"url":"https://github.com/ChilliCream/graphql-platform/pull/9530"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/references/2
{"name":"https://github.com/ChilliCream/graphql-platform/pull/9531","tags":["x_refsource_MISC"],"url":"https://github.com/ChilliCream/graphql-platform/pull/9531"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/references/3
{"name":"https://github.com/ChilliCream/graphql-platform/releases/tag/12.22.7","tags":["x_refsource_MISC"],"url":"https://github.com/ChilliCream/graphql-platform/releases/tag/12.22.7"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/references/8
{"name":"https://github.com/ChilliCream/graphql-platform/releases/tag/13.9.16","tags":["x_refsource_MISC"],"url":"https://github.com/ChilliCream/graphql-platform/releases/tag/13.9.16"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/references/9
{"name":"https://github.com/ChilliCream/graphql-platform/releases/tag/14.3.1","tags":["x_refsource_MISC"],"url":"https://github.com/ChilliCream/graphql-platform/releases/tag/14.3.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/references/10
{"name":"https://github.com/ChilliCream/graphql-platform/releases/tag/15.1.14","tags":["x_refsource_MISC"],"url":"https://github.com/ChilliCream/graphql-platform/releases/tag/15.1.14"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/references/11
{"name":"https://github.com/ChilliCream/graphql-platform/security/advisories/GHSA-qr3m-xw4c-jqw3","tags":["x_refsource_CONFIRM"],"url":"https://github.com/ChilliCream/graphql-platform/security/advisories/GHSA-qr3m-xw4c-jqw3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4147231bb994765c2d55bd7f13e1eda389adf346a1750d143416042b77d4cc44 · sha256:bc0e2182e8fd7366… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.