Skip to main content

Askar Labs

ProductAskar Labs vulnerability database
Records still shown as active1
First contacted2026-08-08
Channels tried[email protected]
StatusAwaiting response

Records

CVE-2025-15603

Authoritative stateREJECTED at cve.org and NVD since 2026-06-18
Withdrawn byVulDB, the issuing CNA, as a false positive
CNA rating before withdrawalLow (CVSS 2.6, 3.7 and 2.9)
What Askar Labs displaysAn active vulnerability in open-webui, weak WEBUI_SECRET_KEY randomness, carrying Medium severity and no rejection marker
Our assessmentCVE-2025-15603

Two problems in one entry. The record is withdrawn and still shown as live, and the severity displayed is Medium, above the Low the issuing CNA assigned before withdrawing it. A rejected identifier cannot carry a severity at all, because there is no longer a finding to rate.


Contact log

DateChannelOutcome
2026-08-08[email protected]Awaiting response

See also

This content is for informational purposes only and does not constitute a warranty, guarantee, or contractual commitment. Open WebUI is provided "as is." See your license for applicable terms.