Haraka is a Node.js-based mail server and SMTP proxy widely used in email infrastructure, presenting a focused but strategically important attack surface given its role in message processing and routing. Its vulnerability profile centers on the core Haraka product and recurs through weakness classes including command injection and uncaught exception handling, reflecting the input-validation and error-handling demands of a protocol-facing mail system. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Haraka Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-1000282CRITICAL Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection. | Feb 5, 2019 | 9.8 | 49 | NO | YES |
CVE-2026-34752HIGH Haraka is a Node.js mail server. Prior to version 3.1.4, sending an email with __proto__: as a header name crashes the Haraka worker process. This issue has been patched in version | Apr 2, 2026 | 7.5 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Haraka Project.
Media articles that mention a CVE ID that affects a product developed by Haraka Project — matched by CVE ID, not by vendor name.