DisallowedHost (SuspiciousOperation) and Media Visibility
Host Header Validation and Media Exposure In Django environments where DEBUG = False , the ALLOWED_HOSTS setting acts as a primary defense against Host-header-based attacks. If a request arrives with a Host header that does not match any entry in this list, Django raises a DisallowedHost exception (a subclass of SuspiciousOperation ), resulting in an HTTP 40