Yes. It is a copy/paste error. Removing the examples (while a good thing to do) doesn't mitigate nay of those.

Mark


On 26/09/2026 11:48, Thiru wrote:
Hi Sebastian,

Thank you again for the clarification.

One point I missed to mention in my earlier email is that, if this was
indeed a copy-and-paste error in the disclosure emails, that would explain
the apparent inconsistency between the mitigation guidance ("Remove the
examples web application") and the code changes associated with the fixes,
which appear to be in Tomcat core classes.

Just to confirm my understanding: for users running production systems
where the examples web application is not deployed, upgrading to 9.0.122
(or the corresponding fixed release) is still required to remediate these
vulnerabilities, and removing the examples application alone should not be
considered a complete substitute for applying the fixes. Is that correct?

Thank you for your time and clarification.

Kind regards,
Thiru

On Sat, 26 Sept, 2026, 4:02 pm Thiru, <[email protected]> wrote:

Hi Sebastian,

Thank you for the clarification.

I came across these mitigation details in the vendor advisories referenced
by the CVE entries linked from the Tomcat Security 9 page.

For each of the 12 vulnerabilities, the referenced Tomcat advisory
includes the same mitigation guidance:

Users of the affected versions should apply one of the following
mitigations:

    - *Remove the examples web application*
    - Upgrade to Apache Tomcat 11.0.26
    - Upgrade to Apache Tomcat 10.1.60
    - Upgrade to Apache Tomcat 9.0.122

The advisories referenced from CVE.org are:

    - https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp
    - https://lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc
    - https://lists.apache.org/thread/tyqcqk99g7ghgk22641vf67vghcyswnw
    - https://lists.apache.org/thread/mb1pjjooqytrl6hbvbt3rw1lqwlon4cz
    - https://lists.apache.org/thread/nmkmjp9l53y8h3oc4n8fc0bkw9dv15sk
    - https://lists.apache.org/thread/bzwps6ck4szf2hmksbbon3syyl9qnkv8
    - https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do
    - https://lists.apache.org/thread/ypvlkjqsq0480fnk9jm6h9qllddwlw4w
    - https://lists.apache.org/thread/qkmsos3s8chn5053qr466rzwv6sk5gjg
    - https://lists.apache.org/thread/y5r9fvjo7ol24mkoyoc0st8bqrfyqcyn
    - https://lists.apache.org/thread/bl5b6rxqh3vb2k9bj2794vhor7o6xl3z
    - https://lists.apache.org/thread/njjcdkkzqyzx4n3ffc4ffjmyh5mpl1gr

To clarify, we do not deploy the examples application in our production
environments. My question was primarily to understand whether the presence
of the examples application is actually a prerequisite for exploiting these
vulnerabilities.

When reviewing some of the associated fixes, I noticed changes in Tomcat
core classes rather than in the examples application itself. That is what
led me to wonder whether "Remove the examples web application" is a valid
mitigation for these CVEs, or whether upgrading to the fixed Tomcat release
is ultimately the only effective mitigation.

In other words, if the examples application is not deployed, should these
vulnerabilities still be considered applicable to the Tomcat instance,
thereby requiring an upgrade to 9.0.122?

Thank you again for your time and clarification.

Kind regards,
Thiru


On Sat, Sep 26, 2026 at 1:48 PM Sebastian Trost via users <
[email protected]> wrote:

On 9/26/26 04:27, Thiru wrote:
The security page lists 12 issues (4 Important, 3 Moderate, and 5 Low
severity). For each of these CVEs, the mitigation appears to be:

Remove the examples web application

[...]

Could you please clarify whether all 12 CVEs are only exploitable
through
the *examples* web application, and whether removing the examples
application alone is sufficient to mitigate these vulnerabilities
without
upgrading Tomcat?

Reference:

https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.122
Where do you see this? The only reference to removing the examples web
application I can find is in the CVE disclosure mails from Mark. The
"Remove the examples web application" started with his mail on July
28th, CVE-2026-66299, and continues in every other CVE disclosure. My
guess is that he simply forgot to remove the "Remove the examples web
application" again and this is a copy&paste mistake.

Why are people so hung up about this examples web application? It always
has been best practice to remove it and the other web applications in
production environments and to only deploy your own web app.

Sebastian



---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]





---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to