INCIBE-CERT
| Product | INCIBE-CERT early-warning vulnerability listing |
| Records still shown as active | 1 |
| First contacted | 2026-08-08 |
| Channels tried | empresas@ |
| Status | Awaiting response |
Records
CVE-2025-15603
| Authoritative state | REJECTED at cve.org and NVD since 2026-06-18 |
| Withdrawn by | VulDB, the issuing CNA, as a false positive |
| Their entry | incibe.es early-warning listing for CVE-2025-15603 |
| What it displays | An active vulnerability in open-webui, weak WEBUI_SECRET_KEY randomness, with no rejection marker |
| Our assessment | CVE-2025-15603 |
This one carries additional weight because INCIBE-CERT is a national CERT. Its early-warning listings are read by organisations as authoritative guidance about what to act on, so a withdrawn identifier presented without a rejection marker propagates further than it would from a commercial aggregator.
Contact log
| Date | Channel | Outcome |
|---|---|---|
| 2026-08-08 | empresas@ | Awaiting response |
See also
- Rejected CVEs in Vulnerability Databases — the overview and how to verify any record yourself.
- CVE-2025-15603 vendor disposition