Rejected CVEs in Vulnerability Databases
When a CVE identifier is withdrawn, the authoritative record at cve.org moves to the REJECTED state and NVD mirrors it. Downstream vulnerability databases, scanners and endpoint-security products ingest that data, but several of them do not reprocess reject and withdrawal transitions. A record snapshotted before withdrawal is never re-synced, so it keeps displaying as an active finding against Open WebUI indefinitely, to the security teams and enterprise customers who pay for those products.
This section is the public record of some of those cases, the ones we have chased far enough to document. There is one page per database, each listing the specific identifiers that database still presents as active, what it displays for each, and a dated log of every contact attempt and its outcome. It is not an exhaustive survey of every database carrying a stale record against Open WebUI.
A withdrawn CVE appearing in a commercial vulnerability database is a data-freshness defect in that database, not a live issue in Open WebUI. The state at cve.org is the authority, it is public, and it takes seconds to check.
Check any CVE against Open WebUI yourself
- Open the record at cve.org (
https://www.cve.org/CVERecord?id=CVE-YYYY-NNNNN) and read the state.REJECTEDmeans the issuing CNA withdrew the identifier. No downstream presentation overrides that. - Cross-check NVD (
https://nvd.nist.gov/vuln/detail/CVE-YYYY-NNNNN), which carries the same state. - Read our assessment in Vendor Dispositions, where every externally filed CVE against Open WebUI has a page setting out what the record claims and where it is wrong.
Databases we have contacted
| Database | Records still shown as active | First contacted | Status |
|---|---|---|---|
| SentinelOne | CVE-2025-15603 | 2026-07-23 | No response on four channels. Published security contact does not accept mail. |
| CVEdetails | CVE-2025-15603 | 2026-07-23 | No response |
| Vulmon | CVE-2025-15603 | 2026-07-23 | No response |
| Vulners | CVE-2025-15603 | 2026-07-23 | Acknowledged, fix in progress |
| Rapid7 | CVE-2025-15603 | 2026-07-23 | No response |
| Positive Technologies | CVE-2025-15603 | 2026-08-08 | Awaiting response |
| Tenable | CVE-2025-15603 | 2026-08-08 | Auto-reply redirected to a product-vulnerability form |
| Axxemble | CVE-2025-15603 | 2026-08-08 | Awaiting response |
| INCIBE-CERT | CVE-2025-15603 | 2026-08-08 | Awaiting response |
| Askar Labs | CVE-2025-15603 | 2026-08-08 | Awaiting response |
What this means for your evaluation
If Open WebUI appears in a scan report or a vendor vulnerability database, the presence of an identifier is not by itself evidence that the record is live, correctly classified, or correctly scored. Check the state at cve.org first.
Where a record is genuinely live, we say so. Our published advisories, with affected and fixed versions for each, are at Open WebUI Security Advisories, and every externally filed CVE we contest has a reasoned page under Vendor Dispositions. We do not ask anyone to take our word for any of it.
What we ask of database operators
- Reprocess reject and withdrawal transitions from the CVE and NVD feeds. A one-time snapshot at ingestion means every record later withdrawn stays wrong permanently.
- Do not present a record above its CNA's own classification or score. Where a machine-generated score exceeds the CNA's, label it as your own assessment rather than as the record.
- Keep the address published in your
security.txtable to receive mail. A contact that bounces is worse than no contact, because it consumes the reporter's time before failing.
If you operate a database listed here and have corrected an entry, write to [email protected] and we will update the page to reflect it. Once every inaccurate record we have raised with you is corrected, we will take the page down entirely. We are glad to do that, and we would much rather have no pages here at all. Until then the page stays up, because it describes something that is still true.
See also
- Supply Chain and Security Scanners: our position on automated capability flags and scanner risk scores.
- Vendor Dispositions: per-CVE assessments, including disputes still open with issuing CNAs.
- Security Policy: the reporting process and threat model.