On 28/07/2026 15:26, Mark Thomas wrote:
CVE-2026-66299 Apache Tomcat - DoS via WebSocket chat example

<snip/>

The majority of the subscribers here aren't part of the Tomcat security team so we wanted to make everyone aware of some of the discussions the security team had about this issue.

Given that this issue shouldn't affect anyone (everyone has followed the advice to remove the examples web application for production - right?), we wanted to use this as an experiment to see how the community reacted to us publishing a CVE that they should not be impacted by when they can't currently obtain a release with a fix for the CVE.

One of the ideas floated in various OSS projects to help manage the flood of AI generated vulnerability reports - particularly where it is highly unlikely any users will be affected - is to fix and publish without a release. The purpose of this experiment is to see what that might look like for the Tomcat community.

Mark


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to