HIGH
Haraka affected by DoS via `__proto__` email header
Published Apr 2, 2026
8.7
HIGHCVSS 4.0
EPSS 0.52%
Description
Haraka is a Node.js mail server. Prior to version 3.1.4, sending an email with __proto__: as a header name crashes the Haraka worker process. This issue has been patched in version 3.1.4.
Affected products
-
- Version < 3.1.4StatusaffectedConstraints-
- Version
- < 3.1.4
No data.
No Red Hat product state for this CVE.
Haraka
npm
Introduced 0 Fixed 3.1.4
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | Haraka | 0 | 3.1.4 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://github.com/advisories/GHSA-xph3-r2jf-4vp3 Advisory
- https://github.com/haraka/Haraka/releases/tag/v3.1.4 x_refsource_MISCRelease Notes
- https://github.com/haraka/Haraka/security/advisories/GHSA-xph3-r2jf-4vp3 x_refsource_CONFIRMExploitVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-34752
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-xph3-r2jf-4vp3 | Advisory | |
| https://github.com/haraka/Haraka/releases/tag/v3.1.4 | x_refsource_MISCRelease Notes | |
| https://github.com/haraka/Haraka/security/advisories/GHSA-xph3-r2jf-4vp3 | x_refsource_CONFIRMExploitVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-34752 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 2, 2026
Updated Apr 3, 2026
Reserved Mar 30, 2026
Link CVE-2026-34752
CISA Vulnrichment
GHSA-XPH3-R2JF-4VP3 Updated Apr 3, 2026