On 20/08/2026 06:52, Venkumahanti Praveen wrote:
Good morning Tomcat team,
I have installed the latest version of Tomcat, currently 9.0.120.0 and
10.1.57.0.
However, our security scan is still reporting a vulnerability associated
with " CVE-2026-66299 ".
Could you please advise if there is any recommended mitigation or
workaround available to address this vulnerability?
You mean other than the mitigation described in the announcement [1],
the published vulnerability information [2] and discussed on this list [3]?
Alternatively, please let us know when a Tomcat release containing a fix
for the vulnerability is expected to be available.
Why are you waiting for a new release? Although if you'd looked on the
Tomcat website [4] or the past day's messages on this list [5] you would
have seen that 9.0.121 is already available.
Mark
[1] https://lists.apache.org/[email protected]
[2]
https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.25
[3] https://lists.apache.org/thread/84ydmgv8txmd8gqc174x15cv3s2hdh2j
[4] https://tomcat.apache.org/
[5] https://lists.apache.org/thread/sk8qd4xrbf18ct76jxgwqzf8ohzd8869
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]