CVE-2016-9014: Canonical Ubuntu Linux

High severity, CVSS 8.1. EPSS: 6.1% chance of exploitation in the next 30 days.

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 16.10 only
  • Djangoproject Django: version 1.8 only; version 1.8.1 only; version 1.8.2 only; version 1.8.3 only; version 1.8.4 only; version 1.8.5 only; …
  • Fedoraproject Fedora: version 24 only; version 25 only

Published 2016-12-09. Last modified 2026-06-17.