{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-0767","assignerOrgId":"99f1926a-a320-47d8-bbb5-42feb611262e","state":"REJECTED","assignerShortName":"zdi","dateReserved":"2026-01-08T22:50:10.918Z","datePublished":"2026-01-23T03:28:39.523Z","dateUpdated":"2026-09-02T17:34:15.123Z","dateRejected":"2026-09-02T17:27:29.647Z"},"containers":{"cna":{"providerMetadata":{"orgId":"99f1926a-a320-47d8-bbb5-42feb611262e","shortName":"zdi","dateUpdated":"2026-09-02T17:34:15.123Z"},"rejectedReasons":[{"lang":"en","value":"Open WebU's investigation showed that this describes the behavior of plain HTTP rather than a defect in the product. TLS termination is the operator's deployment decision, as it is for any backend that speaks HTTP, and not a security issue. https://docs.openwebui.com/security/vendor-dispositions/cve-2026-0767","supportingMedia":[{"type":"text/html","base64":false,"value":"Open WebU's investigation showed that this describes the behavior of plain HTTP rather than a defect in the product. TLS termination is the operator's deployment decision, as it is for any backend that speaks HTTP, and not a security issue. https://docs.openwebui.com/security/vendor-dispositions/cve-2026-0767"}]}],"x_generator":{"engine":"Vulnogram 1.0.5"}}}}