| |
|---|
| Product | Askar Labs vulnerability database |
| Records still shown as active | 1 |
| First contacted | 2026-08-08 |
| Channels tried | [email protected] |
| Status | Awaiting response |
Records
CVE-2025-15603
| |
|---|
| Authoritative state | REJECTED at cve.org and NVD since 2026-06-18 |
| Withdrawn by | VulDB, the issuing CNA, as a false positive |
| CNA rating before withdrawal | Low (CVSS 2.6, 3.7 and 2.9) |
| What Askar Labs displays | An active vulnerability in open-webui, weak WEBUI_SECRET_KEY randomness, carrying Medium severity and no rejection marker |
| Our assessment | CVE-2025-15603 |
Two problems in one entry. The record is withdrawn and still shown as live, and the severity displayed is Medium, above the Low the issuing CNA assigned before withdrawing it. A rejected identifier cannot carry a severity at all, because there is no longer a finding to rate.
See also
This content is for informational purposes only and does not constitute a warranty, guarantee, or contractual commitment. Open WebUI is provided "as is." See your
license for applicable terms.