PT-2026-6873 · Hcl · Hcl Velocity

Published

2026-02-07

·

Updated

2026-02-07

·

CVE-2025-31990

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HCL Velocity versions prior to 5.1.7
Description Rate limiting is not enforced for certain API calls, which makes the software vulnerable to Denial of Service (DoS) attacks. An attacker could send a large number of requests to overwhelm the system’s resources, causing it to become unresponsive to legitimate users.
Recommendations Update to version 5.1.7 or later.

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2025-31990

Affected Products

Hcl Velocity