# Rapid7

Source: https://docs.openwebui.com/security/supply-chain-security/vulnerability-databases/rapid7

|  |  |
| --- | --- |
| Product | Rapid7 Vulnerability & Exploit Database |
| Problem | The withdrawal is shown, and the entry keeps its severity and CVSS score |
| First contacted | 2026-07-23 |
| Channels tried | info@rapid7.com |
| Status | No response, but the entry has since been corrected in part |

> **note**
>
> When we wrote on 2026-07-23 the entry carried the original claim with no rejection marker. As of 2026-08-08 it carries the CNA's withdrawal notice in full. We received no reply, so we cannot say whether our mail prompted the change.

---

## Records

Nine identifiers have been withdrawn against Open WebUI. [CVE-2025-15603](https://www.rapid7.com/db/vulnerabilities/cve-2025-15603/) is the only one we have found on Rapid7.

### The withdrawal is on the page

The entry reproduces the rejection, including the vendor explanation the CNA recorded alongside it: that the default value concerned was unreachable on every supported deployment path, and could only be reached by invoking uvicorn directly, which is unsupported.

### The severity did not follow

| Field | Value shown |
| --- | --- |
| Title | "Undefined Security Weakness" |
| Severity | LOW |
| CVSS v4 base score | 2.9 |
| CVSS v4 vector, as published | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P |

A withdrawn identifier has no severity, because there is no finding left to rate. This one is rated Low, with a full vector, on a record whose own description states that it was withdrawn as not a security issue. The vector carries an Exploit Maturity value of `E:P`, a Threat metric describing the maturity of exploit code, published against an identifier for which the CVE Program recognises no vulnerability.

The score matches what the CNA assigned before withdrawing. The rejection is carried as prose, and every structured field beside it still describes a finding.

The title compounds it slightly. "Undefined Security Weakness" names no weakness class, so a withdrawn record is headed by a label asserting that a weakness exists while declining to say which.

---

## Contact log

| Date | Channel | Outcome |
| --- | --- | --- |
| 2026-07-23 | info@rapid7.com | No response |
| 2026-08-03 | info@rapid7.com | No response |
| 2026-08-08 | info@rapid7.com | No response. The entry now carries the withdrawal notice, with the severity and score unchanged. |

---

## See also

- [Rejected CVEs in Vulnerability Databases](/security/supply-chain-security/vulnerability-databases/) — the overview and how to verify any record yourself.
- [CVE-2025-15603 vendor disposition](/security/vendor-dispositions/cve-2025-15603)
