Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-42873 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate properly, resulting in an infinite loop. This Denial of Service via infinite loop causes high CPU usage and system unresponsiveness due to a blocked processing thread. This vulnerability has no impact on confidentiality or integrity but has a high impact on system availability.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-405Asymmetric Resource Consumption (Amplification)[email protected]

Affected Products

ProductVersions
SAPUI5
All versions

CPE

  • cpe:2.3:a:sap:ui5:*:*:*:*:*:*:*:*
  • cpe:2.3:a:sap:sapui5_library:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
OpenUI5
All versions

CPE

  • cpe:2.3:a:sap:openui5:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-42873
NVD Published Date:
Dec 9, 2025
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2025-42873 Details - Not Deferred