Denial of Service Vulnerability in SAPUI5 and OpenUI5 Packages
CVE-2025-42873
5.9MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-42873?
SAPUI5 and OpenUI5 packages incorporate outdated third-party libraries that contain known vulnerabilities. Specifically, the markdown-it library mishandles specially crafted malformed input, resulting in an infinite loop. This condition leads to Denial of Service as the system experiences excessive CPU usage and becomes unresponsive due to blocked processing threads. While this vulnerability does not compromise the confidentiality or integrity of the system, it significantly impacts its availability.
Affected Version(s)
SAPUI5 framework (Markdown-it component) SAP_UI 755
SAPUI5 framework (Markdown-it component) 756
SAPUI5 framework (Markdown-it component) 757