mirror of
https://github.com/open-webui/docs.git
synced 2026-08-24 14:32:58 -04:00
Record the CVE Program escalation over the unchanged huntr report status
All fifteen records carry the REJECTED state on cve.org while the corresponding reports remain published as valid and awaiting a fix, so the matter has been raised with the CVE Program and each timeline now says so, citing the CNA rule that requires published information not to contradict the record. The six records withdrawn in July say the CNA was unresponsive to the direct request of 2026-08-08. The nine withdrawn in August do not, since they were not yet withdrawn when that request was sent and no direct request about their status has gone out.
This commit is contained in:
@@ -50,6 +50,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
|
||||
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
|
||||
| 2026-08-13 | <span className="badge badge--success cve-rejected">Officially rejected</span> The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -38,6 +38,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
|
||||
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
|
||||
| 2026-08-13 | <span className="badge badge--success cve-rejected">Officially rejected</span> The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -36,6 +36,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm
|
||||
| 2026-07-16 | <span className="badge badge--success cve-rejected">Officially rejected</span> huntr / Protect AI accepts the dispute and withdraws the record. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-08 | Open WebUI asks huntr / Protect AI to bring the report validity and fix status in line with the withdrawal, and to make those fields follow CVE state transitions so it does not recur. Awaiting response. |
|
||||
| 2026-08-14 | With huntr / Protect AI unresponsive on that request, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -36,6 +36,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm
|
||||
| 2026-07-16 | <span className="badge badge--success cve-rejected">Officially rejected</span> huntr / Protect AI accepts the dispute and withdraws the record. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-08 | Open WebUI asks huntr / Protect AI to bring the report validity and fix status in line with the withdrawal, and to make those fields follow CVE state transitions so it does not recur. Awaiting response. |
|
||||
| 2026-08-14 | With huntr / Protect AI unresponsive on that request, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -38,6 +38,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
|
||||
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
|
||||
| 2026-08-13 | <span className="badge badge--success cve-rejected">Officially rejected</span> The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -51,6 +51,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
|
||||
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
|
||||
| 2026-08-13 | <span className="badge badge--success cve-rejected">Officially rejected</span> The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -36,6 +36,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm
|
||||
| 2026-07-16 | <span className="badge badge--success cve-rejected">Officially rejected</span> huntr / Protect AI accepts the dispute and withdraws the record. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-08 | Open WebUI asks huntr / Protect AI to bring the report validity and fix status in line with the withdrawal, and to make those fields follow CVE state transitions so it does not recur. Awaiting response. |
|
||||
| 2026-08-14 | With huntr / Protect AI unresponsive on that request, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -36,6 +36,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm
|
||||
| 2026-07-16 | <span className="badge badge--success cve-rejected">Officially rejected</span> huntr / Protect AI accepts the dispute and withdraws the record. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-08 | Open WebUI asks huntr / Protect AI to bring the report validity and fix status in line with the withdrawal, and to make those fields follow CVE state transitions so it does not recur. Awaiting response. |
|
||||
| 2026-08-14 | With huntr / Protect AI unresponsive on that request, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -43,6 +43,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm
|
||||
| 2026-07-16 | The CVE Program's Root confirms the record is rejected and closes the dispute. |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-08 | Open WebUI asks huntr / Protect AI to bring the report validity and fix status in line with the withdrawal, and to make those fields follow CVE state transitions so it does not recur. Awaiting response. |
|
||||
| 2026-08-14 | With huntr / Protect AI unresponsive on that request, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -38,6 +38,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
|
||||
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
|
||||
| 2026-08-13 | <span className="badge badge--success cve-rejected">Officially rejected</span> The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -51,6 +51,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
|
||||
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
|
||||
| 2026-08-13 | <span className="badge badge--success cve-rejected">Officially rejected</span> The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -55,6 +55,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
|
||||
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
|
||||
| 2026-08-13 | <span className="badge badge--success cve-rejected">Officially rejected</span> The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -36,6 +36,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm
|
||||
| 2026-07-16 | <span className="badge badge--success cve-rejected">Officially rejected</span> huntr / Protect AI accepts the dispute and withdraws the record. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-08 | Open WebUI asks huntr / Protect AI to bring the report validity and fix status in line with the withdrawal, and to make those fields follow CVE state transitions so it does not recur. Awaiting response. |
|
||||
| 2026-08-14 | With huntr / Protect AI unresponsive on that request, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -38,6 +38,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
|
||||
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
|
||||
| 2026-08-13 | <span className="badge badge--success cve-rejected">Officially rejected</span> The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
@@ -50,6 +50,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
|
||||
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
|
||||
| 2026-08-13 | <span className="badge badge--success cve-rejected">Officially rejected</span> The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
|
||||
| <span className="badge badge--warning">Still open</span> | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
|
||||
| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
|
||||
|
||||
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user