---
id: CVE-2025-42873
title: >-
  SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known
  security vulnerabilities
summary: >-
  SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known
  security vulnerabilities. When markdown-it encounters special malformed input,
  it fails to terminate properly, resulting in an infinite loop. This Denial of
  Servic…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-405
published: '2025-12-09'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-42873'
references:
  - url: 'https://me.sap.com/notes/3676970'
    label: cna@sap.com
  - url: 'https://url.sap/sapsecuritypatchday'
    label: cna@sap.com
tags:
  - nvd
epss: 0.00381
epssPercentile: 0.29836
ingestedAt: '2026-10-07T20:46:46.793Z'
---

## Overview

SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate properly, resulting in an infinite loop. This Denial of Service via infinite loop causes high CPU usage and system unresponsiveness due to a blocked processing thread. This vulnerability has no impact on confidentiality or integrity but has a high impact on system availability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
