216.73.217.22

CVE-2026-34752

· Published 02/04/2026 19:21 · Modified 03/04/2026 19:50

Labels: CVE-2026-34752 2026-04-02CVE-2026-34752CWE-248[email protected]

Essential information

Published
02/04/2026 19:21
Modified
03/04/2026 19:50
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Haraka is a Node.js mail server. Prior to version 3.1.4, sending an email with __proto__: as a header name crashes the Haraka worker process. This issue has been patched in version 3.1.4.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
haraka project / haraka cpe:2.3:a:haraka_project:haraka:*:*:*:*:*:node.js:*:*

References