Vulnerabilities
Vulnerable Software
Haraka Project:  >> Haraka  >> 0.2  Security Vulnerabilities
Haraka is a Node.js mail server. Prior to version 3.1.4, sending an email with __proto__: as a header name crashes the Haraka worker process. This issue has been patched in version 3.1.4.
CVSS Score
7.5
EPSS Score
0.0
Published
2026-04-02
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.
CVSS Score
9.8
EPSS Score
0.683
Published
2019-02-05


Contact Us

Shodan ® - All rights reserved