Denial of Service Vulnerability in SAPUI5 and OpenUI5 Packages
CVE-2025-42873
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-42873?
SAPUI5 and OpenUI5 packages incorporate outdated third-party libraries that contain known vulnerabilities. Specifically, the markdown-it library mishandles specially crafted malformed input, resulting in an infinite loop. This condition leads to Denial of Service as the system experiences excessive CPU usage and becomes unresponsive due to blocked processing threads. While this vulnerability does not compromise the confidentiality or integrity of the system, it significantly impacts its availability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAPUI5 framework (Markdown-it component) SAP_UI 755
SAPUI5 framework (Markdown-it component) 756
SAPUI5 framework (Markdown-it component) 757
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved