SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate properly, resulting in an infinite loop. This Denial of Service via infinite loop causes high CPU usage and system unresponsiveness due to a blocked processing thread. This vulnerability has no impact on confidentiality or integrity but has a high impact on system availability.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap sapui5 Sap Se Sap Se sapui5 |
|
| Vendors & Products |
Sap
Sap sapui5 Sap Se Sap Se sapui5 |
Tue, 09 Dec 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate properly, resulting in an infinite loop. This Denial of Service via infinite loop causes high CPU usage and system unresponsiveness due to a blocked processing thread. This vulnerability has no impact on confidentiality or integrity but has a high impact on system availability. | |
| Title | Denial of Service (DoS) in SAPUI5 framework (Markdown-it component) | |
| Weaknesses | CWE-405 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-12-09T02:14:07.094Z
Updated: 2025-12-09T16:40:18.368Z
Reserved: 2025-04-16T13:25:17.023Z
Link: CVE-2025-42873
Updated: 2025-12-09T16:40:15.548Z
Status : Awaiting Analysis
Published: 2025-12-09T16:17:51.320
Modified: 2025-12-09T18:36:53.557
Link: CVE-2025-42873
No data.