CVE-2022-48253: Nazgul Nostromo

Critical severity, CVSS 9.8. EPSS: 3.4% chance of exploitation in the next 30 days.

nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote server. The vulnerability occurs when the homedirs option is used.

Affected products

  • Nazgul Nostromo: before 2.1 (fixed in 2.1)

Published 2023-01-11. Last modified 2026-06-17.