Skip to main content

Rapid7

ProductRapid7 Vulnerability & Exploit Database
Records still shown as active1
First contacted2026-07-23
Channels tried[email protected]
StatusNo response

Records

CVE-2025-15603

Authoritative stateREJECTED at cve.org and NVD since 2026-06-18
Withdrawn byVulDB, the issuing CNA, as a false positive
What Rapid7 displaysAn active entry against open-webui, labelled "Undefined Security Weakness" at CVSS 2.9 (Low)
Our assessmentCVE-2025-15603

The score matches the CNA, so this is purely a status problem: the entry has not been re-synced since the withdrawal.

The label is worth noting separately. "Undefined Security Weakness" means the entry identifies no weakness class at all, and it is nonetheless carried as a live finding against a named product. An entry that cannot say what the weakness is has nothing left to tell a reader except that something is wrong, which in this case is not true.


Contact log

DateChannelOutcome
2026-07-23[email protected]No response
2026-08-03[email protected]No response
2026-08-08[email protected]No response

As of 2026-08-08 the entry is unchanged.


See also

This content is for informational purposes only and does not constitute a warranty, guarantee, or contractual commitment. Open WebUI is provided "as is." See your license for applicable terms.