6.8
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Description
Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) attacks. An attacker could flood the system with a large number of requests, overwhelming its resources and causing it to become unresponsive to legitimate users. This vulnerability is fixed in 5.1.7.
Basic Information
ID
CVE-2025-31990
Source
HCL
Published
Feb 7, 2026 at 03:26
Affected Product
Vendor
HCLSoftware
Product
HCL DevOps Velocity
Version
<5.1.7
Affected Versions
HCLSoftware HCL DevOps Velocity <5.1.7