VDB

CVE-2016-9014

CVE-2016-9014 PUBLISHED

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

EPSS 3.67% · 88.1th percentile

Risk Scores

EPSS Score
3.67%
88.1th percentile

Affected Products

VendorProductVersions
Cloudflaredns
Ubuntu:16.04:LTSpython-django1.8.7-1ubuntu5.2, 0, 1.7.9-1ubuntu5
Ubuntu:14.04:LTSpython-django1.6.1-2ubuntu0.12, 1.6.1-2ubuntu0.13, 1.6.1-2ubuntu0.14

Timeline

  • Nov 1, 2016 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 17, 2025 EPSS Score
  • Mar 29, 2025 EPSS Score
  • Mar 30, 2025 EPSS Score
  • May 4, 2025 EPSS Score
  • Jun 1, 2025 EPSS Score
  • Jun 4, 2025 EPSS Score
  • Jun 19, 2025 EPSS Score
  • Jul 1, 2025 EPSS Score
  • Jul 4, 2025 EPSS Score
  • Jul 13, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›