Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-42873

Опубликовано: 09 дек. 2025
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate properly, resulting in an infinite loop. This Denial of Service via infinite loop causes high CPU usage and system unresponsiveness due to a blocked processing thread. This vulnerability has no impact on confidentiality or integrity but has a high impact on system availability.

EPSS

Процентиль: 18%
0.00057
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-405

Связанные уязвимости

CVSS3: 5.9
github
2 месяца назад

SAPUI5 (and OpenUI5) packages use outdated 3rd party libraries with known security vulnerabilities. When markdown-it encounters special malformed input, it fails to terminate properly, resulting in an infinite loop. This Denial of Service via infinite loop causes high CPU usage and system unresponsiveness due to a blocked processing thread. This vulnerability has no impact on confidentiality or integrity but has a high impact on system availability.

CVSS3: 5.9
fstec
2 месяца назад

Уязвимость компонента Markdown-it платформы для разработки пользовательского интерфейса SAPUI, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 18%
0.00057
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-405