diff --git a/docs/security/vendor-dispositions/cve-2024-12534.mdx b/docs/security/vendor-dispositions/cve-2024-12534.mdx
index 053def7f..387530c8 100644
--- a/docs/security/vendor-dispositions/cve-2024-12534.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-12534.mdx
@@ -50,6 +50,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
| 2026-08-13 | Officially rejected The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
+| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-12537.mdx b/docs/security/vendor-dispositions/cve-2024-12537.mdx
index 7cc52c3a..fee977a7 100644
--- a/docs/security/vendor-dispositions/cve-2024-12537.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-12537.mdx
@@ -38,6 +38,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
| 2026-08-13 | Officially rejected The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
+| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-7033.mdx b/docs/security/vendor-dispositions/cve-2024-7033.mdx
index cc7fe0a8..5b2bc67b 100644
--- a/docs/security/vendor-dispositions/cve-2024-7033.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-7033.mdx
@@ -36,6 +36,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm
| 2026-07-16 | Officially rejected huntr / Protect AI accepts the dispute and withdraws the record. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
| 2026-08-08 | Open WebUI asks huntr / Protect AI to bring the report validity and fix status in line with the withdrawal, and to make those fields follow CVE state transitions so it does not recur. Awaiting response. |
+| 2026-08-14 | With huntr / Protect AI unresponsive on that request, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-7034.mdx b/docs/security/vendor-dispositions/cve-2024-7034.mdx
index d5d16c0d..c813b07b 100644
--- a/docs/security/vendor-dispositions/cve-2024-7034.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-7034.mdx
@@ -36,6 +36,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm
| 2026-07-16 | Officially rejected huntr / Protect AI accepts the dispute and withdraws the record. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
| 2026-08-08 | Open WebUI asks huntr / Protect AI to bring the report validity and fix status in line with the withdrawal, and to make those fields follow CVE state transitions so it does not recur. Awaiting response. |
+| 2026-08-14 | With huntr / Protect AI unresponsive on that request, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-7036.mdx b/docs/security/vendor-dispositions/cve-2024-7036.mdx
index 53348c4c..571adce7 100644
--- a/docs/security/vendor-dispositions/cve-2024-7036.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-7036.mdx
@@ -38,6 +38,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
| 2026-08-13 | Officially rejected The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
+| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-7037.mdx b/docs/security/vendor-dispositions/cve-2024-7037.mdx
index 152c209d..3f9e239c 100644
--- a/docs/security/vendor-dispositions/cve-2024-7037.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-7037.mdx
@@ -51,6 +51,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
| 2026-08-13 | Officially rejected The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
+| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-7038.mdx b/docs/security/vendor-dispositions/cve-2024-7038.mdx
index a63f37f3..849f8e10 100644
--- a/docs/security/vendor-dispositions/cve-2024-7038.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-7038.mdx
@@ -36,6 +36,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm
| 2026-07-16 | Officially rejected huntr / Protect AI accepts the dispute and withdraws the record. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
| 2026-08-08 | Open WebUI asks huntr / Protect AI to bring the report validity and fix status in line with the withdrawal, and to make those fields follow CVE state transitions so it does not recur. Awaiting response. |
+| 2026-08-14 | With huntr / Protect AI unresponsive on that request, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-7039.mdx b/docs/security/vendor-dispositions/cve-2024-7039.mdx
index b39bd59b..4aece9a8 100644
--- a/docs/security/vendor-dispositions/cve-2024-7039.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-7039.mdx
@@ -36,6 +36,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm
| 2026-07-16 | Officially rejected huntr / Protect AI accepts the dispute and withdraws the record. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
| 2026-08-08 | Open WebUI asks huntr / Protect AI to bring the report validity and fix status in line with the withdrawal, and to make those fields follow CVE state transitions so it does not recur. Awaiting response. |
+| 2026-08-14 | With huntr / Protect AI unresponsive on that request, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-7040.mdx b/docs/security/vendor-dispositions/cve-2024-7040.mdx
index 02e25a6b..bbfbb588 100644
--- a/docs/security/vendor-dispositions/cve-2024-7040.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-7040.mdx
@@ -43,6 +43,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm
| 2026-07-16 | The CVE Program's Root confirms the record is rejected and closes the dispute. |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
| 2026-08-08 | Open WebUI asks huntr / Protect AI to bring the report validity and fix status in line with the withdrawal, and to make those fields follow CVE state transitions so it does not recur. Awaiting response. |
+| 2026-08-14 | With huntr / Protect AI unresponsive on that request, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-7045.mdx b/docs/security/vendor-dispositions/cve-2024-7045.mdx
index a042a916..460e0b19 100644
--- a/docs/security/vendor-dispositions/cve-2024-7045.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-7045.mdx
@@ -38,6 +38,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
| 2026-08-13 | Officially rejected The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
+| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-7046.mdx b/docs/security/vendor-dispositions/cve-2024-7046.mdx
index 53e5cf72..24e621dd 100644
--- a/docs/security/vendor-dispositions/cve-2024-7046.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-7046.mdx
@@ -51,6 +51,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
| 2026-08-13 | Officially rejected The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
+| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-7053.mdx b/docs/security/vendor-dispositions/cve-2024-7053.mdx
index 3e2120cf..423b008e 100644
--- a/docs/security/vendor-dispositions/cve-2024-7053.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-7053.mdx
@@ -55,6 +55,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
| 2026-08-13 | Officially rejected The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
+| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-7959.mdx b/docs/security/vendor-dispositions/cve-2024-7959.mdx
index 149c4acf..f4f68c05 100644
--- a/docs/security/vendor-dispositions/cve-2024-7959.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-7959.mdx
@@ -36,6 +36,7 @@ This CVE was **withdrawn by its issuing CNA** after review. Open WebUI's assessm
| 2026-07-16 | Officially rejected huntr / Protect AI accepts the dispute and withdraws the record. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
| 2026-08-08 | Open WebUI asks huntr / Protect AI to bring the report validity and fix status in line with the withdrawal, and to make those fields follow CVE state transitions so it does not recur. Awaiting response. |
+| 2026-08-14 | With huntr / Protect AI unresponsive on that request, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-7990.mdx b/docs/security/vendor-dispositions/cve-2024-7990.mdx
index eb41c2ec..9b8a20f7 100644
--- a/docs/security/vendor-dispositions/cve-2024-7990.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-7990.mdx
@@ -38,6 +38,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
| 2026-08-13 | Officially rejected The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
+| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.
diff --git a/docs/security/vendor-dispositions/cve-2024-8060.mdx b/docs/security/vendor-dispositions/cve-2024-8060.mdx
index 5d3f2af1..da383bd1 100644
--- a/docs/security/vendor-dispositions/cve-2024-8060.mdx
+++ b/docs/security/vendor-dispositions/cve-2024-8060.mdx
@@ -50,6 +50,7 @@ This CVE was **withdrawn by its issuing CNA** after the dispute was escalated to
| 2026-08-12 | huntr / Protect AI replies to the CVE Program and agrees to withdraw the record. |
| 2026-08-13 | Officially rejected The record is updated on cve.org. **The CVE record is now officially REJECTED.** |
| Still open | **The huntr report page has not followed the withdrawal.** The report is still shown as Valid with a green check and its status as "Awaiting fix", while the CVE field on the same page reads Rejected. |
+| 2026-08-14 | With the report status unchanged, Open WebUI raises the matter with the CVE Program, asking that records withdrawn by the CNA no longer be presented as valid and awaiting a fix. [CNA Rule 4.5.2.3](https://www.cve.org/ResourcesSupport/AllResources/CNARules) states that a CNA's published vulnerability information "MUST generally support and MUST NOT contradict information published by the CNA in corresponding CVE Records". |
The record is now in the **REJECTED** state on cve.org, and that state propagates to NVD and downstream feeds. No action is required from users, and the CVE should not be treated as an Open WebUI vulnerability.