CVE-2023-31485: gitlab::api::v4 Project gitlab::api::v4

Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.

GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks.

Affected products

Published 2023-04-29. Last modified 2026-06-17.