diff --git a/docs/security/vendor-dispositions/cve-2024-7040.mdx b/docs/security/vendor-dispositions/cve-2024-7040.mdx index 94f545fe..f5d6c40b 100644 --- a/docs/security/vendor-dispositions/cve-2024-7040.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7040.mdx @@ -32,6 +32,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm | 2026-07-06 | The Root routes the dispute to the issuing CNA under CVE Program Rule 4.1 (Vulnerability Determination), requesting its response. | | 2026-07-08 | huntr / Protect AI reviews the dispute and agrees with Open WebUI's assessment. | | 2026-07-16 | huntr / Protect AI withdraws the record. | +| 2026-07-16 | The CVE Program's Root confirms the record is rejected and closes the dispute. | The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.