VYPR
Critical severity9.8OSV Advisory· Published Feb 5, 2019· Updated Jun 17, 2026

CVE-2016-1000282

CVE-2016-1000282

Description

Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Harakanpm
< 2.8.92.8.9

Affected products

3
  • Haraka/HarakaOSV2 versions
    v0.2, v0.3, v0.4, …+ 1 more
    • (no CPE)range: v0.2, v0.3, v0.4, …
    • cpe:2.3:a:haraka_project:haraka:*:*:*:*:*:*:*:*range: <=2.8.8
  • ghsa-coords
    Range: < 2.8.9

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.