Back

CVE-2017-0906

CRITICAL

The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method that could result in compromise of API keys or other critical resources.

Published: Nov 13, 2017 Modified: Jun 17, 2026
CWE-918 CWE-918

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (8)

Vendor Product Version
recurly recurly_client_python * ≥ 2.0.0
recurly recurly_client_python * ≥ 2.1.0
recurly recurly_client_python * ≥ 2.2.0
recurly recurly_client_python 2.3.0
recurly recurly_client_python * ≥ 2.4.0
recurly recurly_client_python 2.5.0
recurly recurly_client_python 2.6.0
recurly recurly_client_python 2.6.1

GitHub Security Advisory GHSA-38rv-5jqc-m2cv

Recurly vulnerable to SSRF

pip recurly >= 2.6.0, < 2.6.2 Fixed: 2.6.2
pip recurly = 2.5.0 Fixed: 2.5.1
pip recurly >= 2.4.0, < 2.4.5 Fixed: 2.4.5
pip recurly = 2.3.0 Fixed: 2.3.1
pip recurly >= 2.2.0, < 2.2.22 Fixed: 2.2.22
pip recurly >= 2.1.0, < 2.1.16 Fixed: 2.1.16
pip recurly < 2.0.5 Fixed: 2.0.5

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 2.62%

Top 16% most likely to be exploited

Threat Score 40 / 100

Data Sources

NVD EPSS GitHub