Skip to main content

INCIBE-CERT

ProductINCIBE-CERT early-warning vulnerability listing
Records still shown as active1
First contacted2026-08-08
Channels triedempresas@
StatusAwaiting response

Records

CVE-2025-15603

Authoritative stateREJECTED at cve.org and NVD since 2026-06-18
Withdrawn byVulDB, the issuing CNA, as a false positive
Their entryincibe.es early-warning listing for CVE-2025-15603
What it displaysAn active vulnerability in open-webui, weak WEBUI_SECRET_KEY randomness, with no rejection marker
Our assessmentCVE-2025-15603

This one carries additional weight because INCIBE-CERT is a national CERT. Its early-warning listings are read by organisations as authoritative guidance about what to act on, so a withdrawn identifier presented without a rejection marker propagates further than it would from a commercial aggregator.


Contact log

DateChannelOutcome
2026-08-08empresas@Awaiting response

See also

This content is for informational purposes only and does not constitute a warranty, guarantee, or contractual commitment. Open WebUI is provided "as is." See your license for applicable terms.