Vulners
| Product | Vulners |
| Records still shown as active | 1 |
| First contacted | 2026-07-23 |
| Channels tried | support@ |
| Status | Acknowledged the same day, cause identified, fix in progress |
This one answered
Vulners is the only database in this section where a person replied, identified the cause and opened work on it, on the day we wrote. The record below is kept for completeness rather than as a complaint.
Records
CVE-2025-15603
| Authoritative state | REJECTED at cve.org and NVD since 2026-06-18 |
| Withdrawn by | VulDB, the issuing CNA, as a false positive |
| CNA rating before withdrawal | Low (CVSS 2.6, 3.7 and 2.9) |
| What Vulners displays | An active vulnerability in open-webui, with a machine-generated Vulners AI Score of 5.3 (Medium) |
| Our assessment | CVE-2025-15603 |
The underlying data is correct: Vulners confirmed the record carries vulnStatus: "Rejected" in the API. The web interface does not surface that field, so the entry reads as live to anyone browsing it.
The separate point is the score. The AI Score of 5.3 (Medium) sits above the CNA's own rating of Low, for a record the CNA has withdrawn. A machine-generated score that exceeds the issuing CNA's assessment should be presented as the database's own opinion, not as the record.
Contact log
| Date | Channel | Outcome |
|---|---|---|
| 2026-07-23 | support@ | Replied the same day. Confirmed the API carries vulnStatus: "Rejected", acknowledged the web interface does not reflect it, and opened an internal task to surface the status correctly. |
| 2026-08-08 | support@ | Follow-up asking for an update. The entry still does not show the rejected state or the updated record text. |
As of 2026-08-08 the fix has not shipped.
See also
- Rejected CVEs in Vulnerability Databases — the overview and how to verify any record yourself.
- CVE-2025-15603 vendor disposition