Junglewise Threat Intelligence

CVE-2025-31991: HCL DevOps Velocity improper rate limiting in login

CVE-2025-31991 · Severity: medium · CVSS 6.8 · Published 2026-04-13

Vendors: Hcltech, HCL Software.

Executive brief

HCL DevOps Velocity, a platform used for managing software delivery pipelines, contains a security flaw where login attempt limits are not strictly enforced. This allows an attacker to repeatedly guess user passwords without being locked out or slowed down. If successful, an attacker could gain unauthorized access to the platform, potentially disrupting software development workflows or modifying delivery pipelines.

Technical details

HCL DevOps Velocity fails to properly enforce rate limiting on its authentication endpoint (CWE-307). The vulnerability allows a remote attacker to perform brute-force attacks against user accounts because the system does not effectively restrict excessive unsuccessful login attempts. While the vendor-provided CVSS vector suggests high privileges might be required for certain impacts, the nature of a brute-force vulnerability typically involves an unauthenticated or low-privileged network-based attacker attempting to escalate access. The issue is resolved in HCL DevOps Velocity version 5.1.7.

Affected products

  • HCL Software DevOps Velocity versions prior to 5.1.7

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory
  • 2026-04-13: patched: Fixed in version 5.1.7

References