Denial of Service Vulnerability in SAPUI5 and OpenUI5 Packages
CVE-2025-42873

5.9MEDIUM

Key Information:

Vendor

SAP

Vendor
CVE Published:
9 December 2025

What is CVE-2025-42873?

SAPUI5 and OpenUI5 packages incorporate outdated third-party libraries that contain known vulnerabilities. Specifically, the markdown-it library mishandles specially crafted malformed input, resulting in an infinite loop. This condition leads to Denial of Service as the system experiences excessive CPU usage and becomes unresponsive due to blocked processing threads. While this vulnerability does not compromise the confidentiality or integrity of the system, it significantly impacts its availability.

Affected Version(s)

SAPUI5 framework (Markdown-it component) SAP_UI 755

SAPUI5 framework (Markdown-it component) 756

SAPUI5 framework (Markdown-it component) 757

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.