NSClient++

MySolutions NORDIC·MySolutionsNORDIC.NSClient++

A fully fledged monitoring agent which can be used with many monitoring tools.

NSClient++ (nscp) aims to be a simple yet powerful and secure monitoring daemon. It was built for Nagios/Icinga, but nothing in the daemon is Nagios/Icinga specific and it can be used in many other scenarios where you want to receive/distribute check metrics. The daemon has 3 main functions: - Allow a remote machine (monitoring server) to request commands to be run on this machine (the monitored machine) which return the status of the machine. - Submit the same results to a remote (monitoring server). - Take action and perform tasks.

winget install --id MySolutionsNORDIC.NSClient++ --exact --source winget

Latest 0.16.4·August 21, 2026

Release Notes

Security release: request-smuggling fixes in the bundled web server This release upgrades the Cesanta Mongoose web server bundled in the Windows builds to 7.23, closing two critical HTTP request-smuggling vulnerabilities in its HTTP parser. If NSClient++'s web server is reachable through a reverse proxy or WAF, upgrade promptly. Highlights

  • Bundled Mongoose upgraded from 7.20 to 7.23. Fixes two critical (CVSS 9.1) HTTP request-smuggling vulnerabilities, CVE-2026-73256 and CVE-2026-73257, fixed upstream in Mongoose 7.22.
  • Windows builds only. The Windows WEBServer module (REST API and web UI) uses the Mongoose backend; the Linux DEB/RPM packages build on Boost.Beast and never contained the vulnerable code.
  • Exploitable behind an intermediary. Both flaws let an unauthenticated attacker smuggle requests past a reverse proxy, WAF or load balancer in front of NSClient++ — bypassing proxy-level ACLs or injecting into other clients' reused connections. Direct client → NSClient++ deployments have no front end to desynchronize, and NSClient++'s own authentication is still enforced per request either way. Detailed changes WEBServer — bundled Mongoose upgraded to 7.23 (security) Mongoose versions before 7.22 mis-parse HTTP message framing in two ways: ───────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── CVE │Flaw ───────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── CVE-2026-73256 │Broken HTTP/1.0 detection in http_cb() — a request combining Transfer-Encoding: chunked with conflicting HTTP/1.0 framing is parsed with different message boundaries than an HTTP/1.0 reverse proxy │sees.

───────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── CVE-2026-73257 │Requests carrying both Content-Length and Transfer-Encoding: chunked are accepted instead of rejected, enabling CL.TE desynchronization against a Content-Length-preferring front end. ───────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── All build pipelines now pin Mongoose 7.23 (the latest release, which also carries further upstream TLS and TCP/IP hardening): the Windows CI workflows, the Linux docker scenario images that fall back to the Mongoose backend (minimal, no-openssl), and the developer build instructions. The full advisory record is on the security notices page. Upgrade notes

  • Upgrade Windows installs, promptly if behind a reverse proxy/WAF: the request-smuggling CVEs only matter when an intermediary in front of NSClient++ frames the HTTP stream differently than the built-in web server. No configuration change is needed — this is a drop-in upgrade.
  • Linux packages are unaffected (Boost.Beast web backend, no Mongoose), as are installs with the WEBServer module disabled. Full Changelog: 0.16.3...0.16.4

Installer type: wix

x862D04D5866E942C7A5C64E39188B7D11E8868DD262AE9ADC915DF1846B4D5967A
x64F798238F170E8D51372C0FE578161605A9764FB1E1F106C64A3C7FAF016C1896

Details

Homepage
https://nsclient.org/
License
GPL-2.0
Publisher
MySolutions NORDIC
Support
https://github.com/mickem/nscp/issues
Copyright
Copyright (C) 2026 - Michael Medin
Moniker
nscp

Tags

icinganaemonnagios

Older versions (2)

0.14.0.0
x86A0E4CA4B77D6A0C8AC84FDABA74DCF5779DC162450632C276CA978CC7006DF7F
x6497BEF7D36B7F57B21F2102881694D75222F0D4B673083997054AA07DDFB7594F
0.12.6.0
x8676C6CD5DBB630E0237F110A42F416F54710EA1A9E6AA6C31A98B80D16219963E
x643B91EE23E1E18D757667485A7CAA93D05F93606C8620BCE6EE0BAE2D14D204C1