CVE-2019-16278

Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.

  • Published Oct 14, 2019
  • CVSS 9.8 critical
  • 99.0% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • A Metasploit module exploits it

Affected software

CVE-2019-16278 at the National Vulnerability Database