Recurly is a billing and subscription-management platform whose vulnerability footprint centers on its client libraries across multiple programming languages—notably .NET, Python, and Ruby implementations. The durable signal reflects server-side request forgery (SSRF) risks in these SDK components, a weakness class inherent to HTTP-client functionality that handles external callbacks and webhook interactions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Recurly over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-0906CRITICAL The Recurly Client Python Library before 2.0.5, 2.1.16, 2.2.22, 2.3.1, 2.4.5, 2.5.1, 2.6.2 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource.get" method | Nov 13, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-0905CRITICAL The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side Request Forgery vulne | Nov 13, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-0907CRITICAL The Recurly Client .NET Library before 1.0.1, 1.1.10, 1.2.8, 1.3.2, 1.4.14, 1.5.3, 1.6.2, 1.7.1, 1.8.1 is vulnerable to a Server-Side Request Forgery vulnerability due to incorrect | Nov 13, 2017 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Recurly.
Media articles that mention a CVE ID that affects a product developed by Recurly — matched by CVE ID, not by vendor name.