On 28/07/2026 15:26, Mark Thomas wrote:
CVE-2026-66299 Apache Tomcat - DoS via WebSocket chat example
<snip/>
The majority of the subscribers here aren't part of the Tomcat security
team so we wanted to make everyone aware of some of the discussions the
security team had about this issue.
Given that this issue shouldn't affect anyone (everyone has followed the
advice to remove the examples web application for production - right?),
we wanted to use this as an experiment to see how the community reacted
to us publishing a CVE that they should not be impacted by when they
can't currently obtain a release with a fix for the CVE.
One of the ideas floated in various OSS projects to help manage the
flood of AI generated vulnerability reports - particularly where it is
highly unlikely any users will be affected - is to fix and publish
without a release. The purpose of this experiment is to see what that
might look like for the Tomcat community.
Mark
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]