Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) attacks. An attacker could flood the system with a large number of requests, overwhelming its resources and causing it to become unresponsive to legitimate users. This vulnerability is fixed in 5.1.7.
Metrics
Affected Vendors & Products
References
History
Sat, 07 Feb 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) attacks. An attacker could flood the system with a large number of requests, overwhelming its resources and causing it to become unresponsive to legitimate users. This vulnerability is fixed in 5.1.7. | |
| Title | HCL DevOps Velocity is susceptible to a Denial of Service vulnerability | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-02-07T03:26:40.396Z
Reserved: 2025-04-01T18:46:33.656Z
Link: CVE-2025-31990
No data.
Status : Received
Published: 2026-02-07T04:15:52.470
Modified: 2026-02-07T04:15:52.470
Link: CVE-2025-31990
No data.
OpenCVE Enrichment
No data.