From bb2f97829eac5d269bd15d5bd0338cfacf43a899 Mon Sep 17 00:00:00 2001 From: Classic298 <27028174+Classic298@users.noreply.github.com> Date: Thu, 16 Jul 2026 20:14:30 +0200 Subject: [PATCH] Record the Root closing the CVE-2024-7040 dispute The CVE Program's Root confirmed the record is rejected and closed the dispute it had routed to the CNA, completing the escalation the page documents. --- docs/security/vendor-dispositions/cve-2024-7040.mdx | 1 + 1 file changed, 1 insertion(+) diff --git a/docs/security/vendor-dispositions/cve-2024-7040.mdx b/docs/security/vendor-dispositions/cve-2024-7040.mdx index 94f545fe..f5d6c40b 100644 --- a/docs/security/vendor-dispositions/cve-2024-7040.mdx +++ b/docs/security/vendor-dispositions/cve-2024-7040.mdx @@ -32,6 +32,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm | 2026-07-06 | The Root routes the dispute to the issuing CNA under CVE Program Rule 4.1 (Vulnerability Determination), requesting its response. | | 2026-07-08 | huntr / Protect AI reviews the dispute and agrees with Open WebUI's assessment. | | 2026-07-16 | huntr / Protect AI withdraws the record. | +| 2026-07-16 | The CVE Program's Root confirms the record is rejected and closes the dispute. | The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.