SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate properly, resulting in an infinite loop. This Denial of Service via infinite loop causes high CPU usage and system unresponsiveness due to a blocked processing thread. This vulnerability has no impact on confidentiality or integrity but has a high impact on system availability.
History

Tue, 09 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap sapui5
Sap Se
Sap Se sapui5
Vendors & Products Sap
Sap sapui5
Sap Se
Sap Se sapui5

Tue, 09 Dec 2025 02:30:00 +0000

Type Values Removed Values Added
Description SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate properly, resulting in an infinite loop. This Denial of Service via infinite loop causes high CPU usage and system unresponsiveness due to a blocked processing thread. This vulnerability has no impact on confidentiality or integrity but has a high impact on system availability.
Title Denial of Service (DoS) in SAPUI5 framework (Markdown-it component)
Weaknesses CWE-405
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-12-09T02:14:07.094Z

Updated: 2025-12-09T16:40:18.368Z

Reserved: 2025-04-16T13:25:17.023Z

Link: CVE-2025-42873

cve-icon Vulnrichment

Updated: 2025-12-09T16:40:15.548Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-09T16:17:51.320

Modified: 2025-12-09T18:36:53.557

Link: CVE-2025-42873

cve-icon Redhat

No data.