CVE-2017-0906: Recurly Client Python

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources.

Affected products

  • Recurly Recurly Client Python: from 2.0.0, up to and including 2.0.4; from 2.1.0, up to and including 2.1.15; from 2.2.0, up to and including 2.2.21; version 2.3.0 only; from 2.4.0, up to and including 2.4.4; version 2.5.0 only; …

Published 2017-11-13. Last modified 2026-06-17.