Junglewise Threat Intelligence

CVE-2019-16278: Nostromo nhttpd Directory Traversal Vulnerability

CVE-2019-16278 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-11-07

Executive brief

A directory traversal vulnerability exists in the http_verify() function of Nostromo nhttpd through version 1.9.6. An attacker can exploit this via a crafted HTTP request to bypass directory restrictions and achieve remote code execution on non-chrooted servers.

Affected products

  • Nazgul nhttpd up to 1.9.6

Timeline

  • 2019-10-31: disclosed: Initial CVE modification date recorded by MITRE
  • 2024-11-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-11-07: advisory: NVD publication date