<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 18:49:34 +0000</lastBuildDate>
    <item>
      <title>cnvd-2016-10590</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2016-10590</link>
      <description>cnvd-2016-10590</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2016-10590</guid>
    </item>
    <item>
      <title>EUVD-2026-87524</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-87524</link>
      <description>EUVD-2026-87524</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-87524</guid>
    </item>
    <item>
      <title>fkie_cve-2016-9014</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2016-9014</link>
      <description>&lt;p&gt;Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2016-9014</guid>
    </item>
    <item>
      <title>GHSA-3f2c-jm6v-cr35 — Django DNS Rebinding Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3f2c-jm6v-cr35</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Django&lt;/p&gt;
&lt;p&gt;Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Django&lt;/p&gt;
&lt;p&gt;Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3f2c-jm6v-cr35</guid>
    </item>
    <item>
      <title>gsd-2016-9014</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2016-9014</link>
      <description>gsd-2016-9014</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2016-9014</guid>
    </item>
    <item>
      <title>PYSEC-2016-18</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2016-18</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django&lt;/p&gt;
&lt;p&gt;Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: django&lt;/p&gt;
&lt;p&gt;Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2016-18</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:0973-1 — Security update for python-Django</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:0973-1</link>
      <description>&lt;p&gt;Security update for python-Django&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Django&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:0973-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2016-9014</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-9014</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: python-django, Ubuntu:16.04:LTS: python-django&lt;/p&gt;
&lt;p&gt;Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: python-django, Ubuntu:16.04:LTS: python-django&lt;/p&gt;
&lt;p&gt;Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2016-9014</guid>
    </item>
  </channel>
</rss>
