| |
|---|
| Product | CVEdetails |
| Records still shown as active | 1 |
| First contacted | 2026-07-23 |
| Channels tried | admin@ |
| Status | No response |
Records
CVE-2025-15603
| |
|---|
| Authoritative state | REJECTED at cve.org and NVD since 2026-06-18 |
| Withdrawn by | VulDB, the issuing CNA, as a false positive |
| What CVEdetails displays | An active vulnerability in open-webui, annotated "the exploit has been disclosed publicly and may be used". Page stamped "Updated 2026-04-29". |
| Our assessment | CVE-2025-15603 |
The scoring matches the CNA, so this is purely a status problem: the page was last refreshed roughly seven weeks before the withdrawal and has not re-synced since. The added note that a public exploit exists and may be used compounds it, because that framing pushes a reader toward treating the entry as actionable.
| Date | Channel | Outcome |
|---|
| 2026-07-23 | admin@ | No response |
| 2026-08-03 | admin@ | No response |
| 2026-08-08 | admin@ | No response |
As of 2026-08-08 the entry is unchanged.
See also
This content is for informational purposes only and does not constitute a warranty, guarantee, or contractual commitment. Open WebUI is provided "as is." See your
license for applicable terms.