Skip to main content

Vulners

ProductVulners
Records still shown as active1
First contacted2026-07-23
Channels triedsupport@
StatusAcknowledged the same day, cause identified, fix in progress
This one answered

Vulners is the only database in this section where a person replied, identified the cause and opened work on it, on the day we wrote. The record below is kept for completeness rather than as a complaint.


Records

CVE-2025-15603

Authoritative stateREJECTED at cve.org and NVD since 2026-06-18
Withdrawn byVulDB, the issuing CNA, as a false positive
CNA rating before withdrawalLow (CVSS 2.6, 3.7 and 2.9)
What Vulners displaysAn active vulnerability in open-webui, with a machine-generated Vulners AI Score of 5.3 (Medium)
Our assessmentCVE-2025-15603

The underlying data is correct: Vulners confirmed the record carries vulnStatus: "Rejected" in the API. The web interface does not surface that field, so the entry reads as live to anyone browsing it.

The separate point is the score. The AI Score of 5.3 (Medium) sits above the CNA's own rating of Low, for a record the CNA has withdrawn. A machine-generated score that exceeds the issuing CNA's assessment should be presented as the database's own opinion, not as the record.


Contact log

DateChannelOutcome
2026-07-23support@Replied the same day. Confirmed the API carries vulnStatus: "Rejected", acknowledged the web interface does not reflect it, and opened an internal task to surface the status correctly.
2026-08-08support@Follow-up asking for an update. The entry still does not show the rejected state or the updated record text.

As of 2026-08-08 the fix has not shipped.


See also

This content is for informational purposes only and does not constitute a warranty, guarantee, or contractual commitment. Open WebUI is provided "as is." See your license for applicable terms.