Skip to main content

CVEdetails

ProductCVEdetails
Records still shown as active1
First contacted2026-07-23
Channels triedadmin@
StatusNo response

Records

CVE-2025-15603

Authoritative stateREJECTED at cve.org and NVD since 2026-06-18
Withdrawn byVulDB, the issuing CNA, as a false positive
What CVEdetails displaysAn active vulnerability in open-webui, annotated "the exploit has been disclosed publicly and may be used". Page stamped "Updated 2026-04-29".
Our assessmentCVE-2025-15603

The scoring matches the CNA, so this is purely a status problem: the page was last refreshed roughly seven weeks before the withdrawal and has not re-synced since. The added note that a public exploit exists and may be used compounds it, because that framing pushes a reader toward treating the entry as actionable.


Contact log

DateChannelOutcome
2026-07-23admin@No response
2026-08-03admin@No response
2026-08-08admin@No response

As of 2026-08-08 the entry is unchanged.


See also

This content is for informational purposes only and does not constitute a warranty, guarantee, or contractual commitment. Open WebUI is provided "as is." See your license for applicable terms.