Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) attacks. An attacker could flood the system with a large number of requests, overwhelming its resources and causing it to become unresponsive to legitimate users. This vulnerability is fixed in 5.1.7.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hclsoftware
Hclsoftware hcl Devops Velocity |
|
| Vendors & Products |
Hclsoftware
Hclsoftware hcl Devops Velocity |
Sat, 07 Feb 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) attacks. An attacker could flood the system with a large number of requests, overwhelming its resources and causing it to become unresponsive to legitimate users. This vulnerability is fixed in 5.1.7. | |
| Title | HCL DevOps Velocity is susceptible to a Denial of Service vulnerability | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-02-09T16:51:29.503Z
Reserved: 2025-04-01T18:46:33.656Z
Link: CVE-2025-31990
Updated: 2026-02-09T16:51:22.322Z
Status : Awaiting Analysis
Published: 2026-02-07T04:15:52.470
Modified: 2026-02-09T16:08:55.263
Link: CVE-2025-31990
No data.