EXPOSURES › CVE-2019-16278
CVE-2019-16278
HIGH ⌖ ON CISA KEV · EXPLOITEDNostromo's nhttpd shipped with a remote code execution vulnerability in http_verify() that allows attackers to traverse directories and execute arbitrary code.
This unpatched directory traversal flaw in nhttpd enables remote code execution, posing a severe risk to DIB systems relying on Nostromo's web server components. The vulnerability is actively exploited in the wild and allows attackers to bypass security controls, potentially compromising sensitive data or enabling lateral movement within a network. DIB organizations must immediately audit their deployments of nhttpd and apply vendor patches or replace the component to prevent exploitation.
Shame score — A critical RCE vulnerability in a web server component that is actively exploited in the wild indicates a severe failure in vendor security practices and patch management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.