CVE-2026-34752
EUVD-2026-1850902.04.2026, 19:21
Haraka is a Node.js mail server. Prior to version 3.1.4, sending an email with __proto__: as a header name crashes the Haraka worker process. This issue has been patched in version 3.1.4.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| haraka_project | haraka | 𝑥 < 3.1.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration