Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-9014

22
FAUCET Score

CVE-2016-9014 is a DNS rebinding vulnerability affecting Django versions before 1.8.16, 1.9.11, and 1.10.3 when DEBUG mode is enabled. It allows remote attackers to bypass HTTP Host header validation, impacting various Django installations across Canonical, Fedora, and DjangoProject distributions. This vulnerability carries a high CVSS score of 8.1, indicating a significant risk with network-based attacks and high potential for confidentiality, integrity, and availability compromise, though with high attack complexity. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
24CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:24:*:*:*:*:*:*:*
25CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:25:*:*:*:*:*:*:*
12.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.1HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
6.07%
Probability of exploitation in next 30 days
EPSS Percentile
92.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0607 is in the 66th percentile among its peer group of 8,915 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

pippatch availablevia ghsa
Product: DjangoFixed in: 1.8.16
pippatch availablevia ghsa
Product: DjangoFixed in: 1.9.11
pippatch availablevia ghsa
Product: DjangoFixed in: 1.10.3
redhatend of lifevia redhat_api
Product: Red Hat Ceph Storage 1.3Fixed in: calamari-server
redhatend of lifevia redhat_api
Product: Red Hat Ceph Storage 2Fixed in: python-django
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)Fixed in: python-django
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 6 (Juno)Fixed in: python-django
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)Fixed in: python-django
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) Operational ToolsFixed in: python-django
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 10 (Newton)Fixed in: python-django
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 10 (Newton) Operational ToolsFixed in: python-django
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 8 (Liberty)Fixed in: python-django
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 8 (Liberty) Operational ToolsFixed in: python-django
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 9 (Mitaka)Fixed in: python-django
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 9 (Mitaka) Operational ToolsFixed in: python-django
redhatend of lifevia redhat_api
Product: Red Hat Storage Console 2Fixed in: Django
redhatend of lifevia redhat_api
Product: Red Hat Storage Console 2Fixed in: python-django
redhatend of lifevia redhat_api
Product: Red Hat Subscription Asset ManagerFixed in: Django

Vendor Advisories (2)

pipGHSA-3f2c-jm6v-cr35critical

Django DNS Rebinding Vulnerability

May 17, 2022
redhatCVE-2016-9014Low

python-django: DNS rebinding vulnerability when 'DEBUG=True'

Nov 1, 2016

References

lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/OG5ROMUPS6C7BXELD3TAUUH7OBYV56WQ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QXDKJYHN74BWY3P7AR2UZDVJREQMRE6S
djangoproject.com / weblog/2016/nov/01/security-releases
Release NotesVendor Advisory
debian.org / security/2017/dsa-3835
securityfocus.com / bid/94068
Third Party AdvisoryVDB Entry
securitytracker.com / id/1037159
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-3115-1
Third Party Advisory