CVE-2026-0767
UnknownEPSS 0.25%
Last modified
This CVE is reserved or rejected; no details have been published by NVD.
Description
Rejected reason: Open WebU's investigation showed that this describes the behavior of plain HTTP rather than a defect in the product. TLS termination is the operator's deployment decision, as it is for any backend that speaks HTTP, and not a security issue. https://docs.openwebui.com/security/vendor-dispositions/cve-2026-0767
Metrics
Timeline
- Published
- Last Modified
- Status
- Rejected
Related CVEs from 2026
- CVE-2026-0761Foundation Agents MetaGPT actionoutput_str_to_mapping Code I…9.8
- CVE-2026-0762GPT Academic stream_daas Deserialization of Untrusted Data R…8.1
- CVE-2026-0763GPT Academic run_in_subprocess_wrapper_func Deserialization …9.8
- CVE-2026-0764GPT Academic upload Deserialization of Untrusted Data Remote…9.8
- CVE-2026-0765Rejected reason: Open WebU's investigation further investiga…
- CVE-2026-0766Rejected reason: Open WebU's investigation further investiga…
- CVE-2026-0768Langflow code Code Injection Remote Code Execution Vulnerabi…9.8
- CVE-2026-0769Langflow eval_custom_component_code Eval Injection Remote Co…9.8
- CVE-2026-0770Langflow exec_globals Inclusion of Functionality from Untrus…9.8
- CVE-2026-0771Langflow PythonFunction Code Injection Remote Code Execution…7.1
- CVE-2026-0772Langflow Disk Cache Deserialization of Untrusted Data Remote…7.5
- CVE-2026-0773Upsonic Cloudpickle Deserialization of Untrusted Data Remote…9.8
Are you affected by CVE-2026-0767?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
