Skip to content

Commit 614e6f2

Browse files
committed
Add Rapid7 and Askar Labs to the databases still serving a rejected record
Both were contacted about CVE-2025-15603 alongside the others but had no page yet, so the section understated how widely the withdrawn record is still circulating. Rapid7 carries it as an active entry labelled "Undefined Security Weakness", an entry that names no weakness class at all and is still presented as a live finding against the project. Askar Labs shows it as active at Medium severity, above the Low its issuing CNA assigned before withdrawing it entirely. The sidebar is renumbered so the pages group by the date each database was first contacted, matching the order of the summary table.
1 parent c50db55 commit 614e6f2

7 files changed

Lines changed: 101 additions & 4 deletions

File tree

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
---
2+
sidebar_position: 10
3+
title: "Askar Labs"
4+
---
5+
6+
# Askar Labs
7+
8+
| | |
9+
| :--- | :--- |
10+
| **Product** | Askar Labs vulnerability database |
11+
| **Records still shown as active** | 1 |
12+
| **First contacted** | 2026-08-08 |
13+
| **Channels tried** | `hello@askarlabs.com` |
14+
| **Status** | Awaiting response |
15+
16+
---
17+
18+
## Records
19+
20+
### CVE-2025-15603
21+
22+
| | |
23+
| :--- | :--- |
24+
| **Authoritative state** | **REJECTED** at [cve.org](https://www.cve.org/CVERecord?id=CVE-2025-15603) and [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-15603) since 2026-06-18 |
25+
| **Withdrawn by** | VulDB, the issuing CNA, as a false positive |
26+
| **CNA rating before withdrawal** | Low (CVSS 2.6, 3.7 and 2.9) |
27+
| **What Askar Labs displays** | An active vulnerability in open-webui, weak `WEBUI_SECRET_KEY` randomness, carrying **Medium** severity and no rejection marker |
28+
| **Our assessment** | [CVE-2025-15603](/security/vendor-dispositions/cve-2025-15603) |
29+
30+
Two problems in one entry. The record is withdrawn and still shown as live, and the severity displayed is Medium, above the Low the issuing CNA assigned before withdrawing it. A rejected identifier cannot carry a severity at all, because there is no longer a finding to rate.
31+
32+
---
33+
34+
## Contact log
35+
36+
| Date | Channel | Outcome |
37+
| :--- | :--- | :--- |
38+
| 2026-08-08 | `hello@askarlabs.com` | Awaiting response |
39+
40+
---
41+
42+
## See also
43+
44+
- [Rejected CVEs in Vulnerability Databases](./) — the overview and how to verify any record yourself.
45+
- [CVE-2025-15603 vendor disposition](/security/vendor-dispositions/cve-2025-15603)

docs/security/supply-chain-security/vulnerability-databases/axxemble.mdx

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
sidebar_position: 7
2+
sidebar_position: 8
33
title: "Axxemble"
44
---
55

docs/security/supply-chain-security/vulnerability-databases/incibe.mdx

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
sidebar_position: 8
2+
sidebar_position: 9
33
title: "INCIBE-CERT"
44
---
55

docs/security/supply-chain-security/vulnerability-databases/index.mdx

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,10 +27,12 @@ A withdrawn CVE appearing in a commercial vulnerability database is a data-fresh
2727
| [CVEdetails](./cvedetails) | CVE-2025-15603 | 2026-07-23 | No response |
2828
| [Vulmon](./vulmon) | CVE-2025-15603 | 2026-07-23 | No response |
2929
| [Vulners](./vulners) | CVE-2025-15603 | 2026-07-23 | Acknowledged, fix in progress |
30+
| [Rapid7](./rapid7) | CVE-2025-15603 | 2026-07-23 | No response |
3031
| [Positive Technologies](./positive-technologies) | CVE-2025-15603 | 2026-08-08 | Awaiting response |
3132
| [Tenable](./tenable) | CVE-2025-15603 | 2026-08-08 | Auto-reply redirected to a product-vulnerability form |
3233
| [Axxemble](./axxemble) | CVE-2025-15603 | 2026-08-08 | Awaiting response |
3334
| [INCIBE-CERT](./incibe) | CVE-2025-15603 | 2026-08-08 | Awaiting response |
35+
| [Askar Labs](./askar-labs) | CVE-2025-15603 | 2026-08-08 | Awaiting response |
3436

3537
## What this means for your evaluation
3638

docs/security/supply-chain-security/vulnerability-databases/positive-technologies.mdx

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
sidebar_position: 5
2+
sidebar_position: 6
33
title: "Positive Technologies (dbugs)"
44
---
55

Lines changed: 50 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,50 @@
1+
---
2+
sidebar_position: 5
3+
title: "Rapid7"
4+
---
5+
6+
# Rapid7
7+
8+
| | |
9+
| :--- | :--- |
10+
| **Product** | Rapid7 Vulnerability & Exploit Database |
11+
| **Records still shown as active** | 1 |
12+
| **First contacted** | 2026-07-23 |
13+
| **Channels tried** | `info@rapid7.com` |
14+
| **Status** | No response |
15+
16+
---
17+
18+
## Records
19+
20+
### CVE-2025-15603
21+
22+
| | |
23+
| :--- | :--- |
24+
| **Authoritative state** | **REJECTED** at [cve.org](https://www.cve.org/CVERecord?id=CVE-2025-15603) and [NVD](https://nvd.nist.gov/vuln/detail/CVE-2025-15603) since 2026-06-18 |
25+
| **Withdrawn by** | VulDB, the issuing CNA, as a false positive |
26+
| **What Rapid7 displays** | An active entry against open-webui, labelled "Undefined Security Weakness" at CVSS 2.9 (Low) |
27+
| **Our assessment** | [CVE-2025-15603](/security/vendor-dispositions/cve-2025-15603) |
28+
29+
The score matches the CNA, so this is purely a status problem: the entry has not been re-synced since the withdrawal.
30+
31+
The label is worth noting separately. "Undefined Security Weakness" means the entry identifies no weakness class at all, and it is nonetheless carried as a live finding against a named product. An entry that cannot say what the weakness is has nothing left to tell a reader except that something is wrong, which in this case is not true.
32+
33+
---
34+
35+
## Contact log
36+
37+
| Date | Channel | Outcome |
38+
| :--- | :--- | :--- |
39+
| 2026-07-23 | `info@rapid7.com` | No response |
40+
| 2026-08-03 | `info@rapid7.com` | No response |
41+
| 2026-08-08 | `info@rapid7.com` | No response |
42+
43+
As of 2026-08-08 the entry is unchanged.
44+
45+
---
46+
47+
## See also
48+
49+
- [Rejected CVEs in Vulnerability Databases](./) — the overview and how to verify any record yourself.
50+
- [CVE-2025-15603 vendor disposition](/security/vendor-dispositions/cve-2025-15603)

docs/security/supply-chain-security/vulnerability-databases/tenable.mdx

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
sidebar_position: 6
2+
sidebar_position: 7
33
title: "Tenable"
44
---
55

0 commit comments

Comments
 (0)