CVE-2025-31990

Rate limiting for certain API calls is not being enforced, making HCL Velocity vulnerable to Denial of Service (DoS) attacks. An attacker could flood the system with a large number of requests, overwhelming its resources and causing it to become unresponsive to legitimate users. This vulnerability is fixed in 5.1.7.
Configurations

No configuration.

History

07 Feb 2026, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-07 04:15

Updated : 2026-02-09 16:08


NVD link : CVE-2025-31990

Mitre link : CVE-2025-31990

CVE.ORG link : CVE-2025-31990


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling