CVE-2020-10956: GitLab
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.
Affected products
- GitLab GitLab: from 8.10.0, before 12.9.1 (fixed in 12.9.1)
Published 2020-03-27. Last modified 2026-06-17.