CVE-2017-0907: Recurly Client .net
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect use of "Uri.EscapeUriString" that could result in compromise of API keys or other critical resources.
Affected products
- Recurly Recurly Client .net: version 1.0.0 only; version 1.0.0.1 only; version 1.0.0.2 only; version 1.0.0.3 only; version 1.0.0.4 only; version 1.1.0 only; …
Published 2017-11-13. Last modified 2026-06-17.