CVE-2019-16278: Nostromo nhttpd Directory Traversal Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-11-07. EPSS: 99% chance of exploitation in the next 30 days.

Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.

Affected products

  • Nazgul Nostromo Nhttpd: before 1.9.7 (fixed in 1.9.7)

Published 2019-10-14. Last modified 2026-06-17.