Skip to main content

Askar Labs

ProductAskar Labs CVE Database
Records still shown as active9, every withdrawn identifier against Open WebUI
First contacted2026-08-08
Channels tried[email protected]
StatusAwaiting response

Records

Every CVE withdrawn against Open WebUI still has a live entry, carrying the original description, the original severity and no rejection marker. Each identifier below is in the REJECTED state at cve.org and at NVD:

IdentifierWithdrawn byRejected sinceStill live on Askar LabsOur assessment
CVE-2024-7033huntr / Protect AI2026-07-16askarlabs.comDisposition
CVE-2024-7034huntr / Protect AI2026-07-16askarlabs.comDisposition
CVE-2024-7038huntr / Protect AI2026-07-16askarlabs.comDisposition
CVE-2024-7039huntr / Protect AI2026-07-16askarlabs.comDisposition
CVE-2024-7040huntr / Protect AI2026-07-16askarlabs.comDisposition
CVE-2024-7959huntr / Protect AI2026-07-16askarlabs.comDisposition
CVE-2025-15603VulDB2026-06-18askarlabs.comDisposition
CVE-2025-29446MITRE2026-06-29askarlabs.comDisposition
CVE-2025-63391MITRE2026-06-29askarlabs.comDisposition

The entries say the current release is affected

This goes past a stale severity. It is an affirmative claim about which versions of Open WebUI carry the defect, published on records that no longer exist:

IdentifierAffected versions, as publishedReality
CVE-2024-7033"≥ unspecified and ≤ latest"Withdrawn. No version is affected.
CVE-2024-7040"≥ unspecified and ≤ latest"Withdrawn. No version is affected.
CVE-2025-29446"All versions"Withdrawn. No version is affected.
CVE-2025-63391"All versions"Withdrawn. No version is affected.

An upper bound of "latest" is not a bound at all. It tells a reader that whatever release of Open WebUI they are running right now, including one shipped today, is vulnerable. The descriptions on these same entries name specific old versions. The CVE-2024-7033 entry describes version 0.3.8, and the CVE-2025-29446 entry describes v0.5.16. Neither description claims anything about later releases, and both identifiers have since been withdrawn entirely, so the version range and the text beside it disagree on the same page.

An operator checking whether their deployment is exposed gets the worst possible answer here: yes, always, on a finding that does not exist.

Two of them do not even name the product

On CVE-2025-29446 and CVE-2025-63391 the Vendor field reads "N/A" and the Product field reads "n/a", while the Affected field reads "All versions" and the description names Open WebUI in prose.

An entry that cannot say which product it applies to is nonetheless asserting that every version of it is affected.

Records last updated before the withdrawal

IdentifierLast updated, as shownWithdrawn
CVE-2024-70332025-03-20, the day it was published2026-07-16
CVE-2024-70402025-10-152026-07-16
CVE-2025-294462025-05-122026-06-29
CVE-2025-633912026-01-222026-06-29

CVE-2024-7033 has not been touched since the day it was published, nearly seventeen months ago. It still carries the full original description, ending with the claim that the issue can be escalated to remote code execution and "a full system compromise", and a CVSS of 6.5 Medium.


Contact log

DateChannelOutcome
2026-08-08[email protected]Awaiting response

See also

This content is for informational purposes only and does not constitute a warranty, guarantee, or contractual commitment. Open WebUI is provided "as is." See your license for applicable terms.