<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T18:49:35.018544+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2016-10590</id>
    <title>cnvd-2016-10590</title>
    <updated>2026-10-05T18:49:35.024012+00:00</updated>
    <content>cnvd-2016-10590</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2016-10590"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-87524</id>
    <title>EUVD-2026-87524</title>
    <updated>2026-10-05T18:49:35.024046+00:00</updated>
    <content>EUVD-2026-87524</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-87524"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2016-9014</id>
    <title>fkie_cve-2016-9014</title>
    <updated>2026-10-05T18:49:35.024060+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2016-9014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3f2c-jm6v-cr35</id>
    <title>GHSA-3f2c-jm6v-cr35 — Django DNS Rebinding Vulnerability</title>
    <updated>2026-10-05T18:49:35.024089+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Django</p>
<p>Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3f2c-jm6v-cr35"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2016-9014</id>
    <title>gsd-2016-9014</title>
    <updated>2026-10-05T18:49:35.024113+00:00</updated>
    <content>gsd-2016-9014</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2016-9014"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2016-18</id>
    <title>PYSEC-2016-18</title>
    <updated>2026-10-05T18:49:35.024124+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: django</p>
<p>Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2016-18"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2018:0973-1</id>
    <title>SUSE-SU-2018:0973-1 — Security update for python-Django</title>
    <updated>2026-10-05T18:49:35.024141+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Django</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2018:0973-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-9014</id>
    <title>UBUNTU-CVE-2016-9014</title>
    <updated>2026-10-05T18:49:35.024159+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: python-django, Ubuntu:16.04:LTS: python-django</p>
<p>Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-9014"/>
  </entry>
</feed>
