Rapid7
| Product | Rapid7 Vulnerability & Exploit Database |
| Records still shown as active | 1 |
| First contacted | 2026-07-23 |
| Channels tried | [email protected] |
| Status | No response |
Records
CVE-2025-15603
| Authoritative state | REJECTED at cve.org and NVD since 2026-06-18 |
| Withdrawn by | VulDB, the issuing CNA, as a false positive |
| What Rapid7 displays | An active entry against open-webui, labelled "Undefined Security Weakness" at CVSS 2.9 (Low) |
| Our assessment | CVE-2025-15603 |
The score matches the CNA, so this is purely a status problem: the entry has not been re-synced since the withdrawal.
The label is worth noting separately. "Undefined Security Weakness" means the entry identifies no weakness class at all, and it is nonetheless carried as a live finding against a named product. An entry that cannot say what the weakness is has nothing left to tell a reader except that something is wrong, which in this case is not true.
Contact log
| Date | Channel | Outcome |
|---|---|---|
| 2026-07-23 | [email protected] | No response |
| 2026-08-03 | [email protected] | No response |
| 2026-08-08 | [email protected] | No response |
As of 2026-08-08 the entry is unchanged.
See also
- Rejected CVEs in Vulnerability Databases — the overview and how to verify any record yourself.
- CVE-2025-15603 vendor disposition