CVE-2026-34752High· 7.5▾ TwilightHaraka is a Node.js mail server. Prior to version 3.1.4, sending an email with __proto__: as a header name crashes the Haraka worker process. This issue has been patched in version 3.1.4.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Haraka is a Node.js mail server. Prior to version 3.1.4, sending an email with proto: as a header name crashes the Haraka worker process. This issue has been patched in version 3.1.4.
haraka < 3.1.4Upgrade past the affected range:
haraka 3.1.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44001High· 8.6vm2 is an open source vm/sandbox for Node.js
CVE-2026-31812Medium· 5.3Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol
CVE-2026-96399NoneA repository's external issue tracker regular expression containing alternating capture groups could produce invalid slice indexes when Gitea rendered issue references, causing a runtime panic that terminated the Gitea process
CVE-2026-102413Medium· 6.2Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name
CVE-2026-106122Medium· 6.0The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes
GHSA-mgj2-jqjq-q8ggCritical· 8.6Duplicate Advisory: vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process