Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.
https://github.com/andknownmaly/CVE-2019-16278
https://github.com/cancela24/CVE-2019-16278-Nostromo-1.9.6-RCE
https://github.com/FredBrave/CVE-2019-16278-Nostromo-1.9.6-RCE
https://github.com/keshiba/cve-2019-16278
https://github.com/NHPT/CVE-2019-16278
https://github.com/darkerego/Nostromo_Python3
https://github.com/ianxtianxt/CVE-2019-16278
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-16278
https://git.sp0re.sh/sp0re/Nhttpd-exploits
http://www.nazgul.ch/dev/nostromo_cl.txt
http://packetstormsecurity.com/files/155802/nostromo-1.9.6-Remote-Code-Execution.html