Hi Mark,

Thank you for the clarification, I really appreciate your help in clearing
this up and confirming that upgrading to the 9.0.122 Tomcat release is the
required mitigation.

Best regards,
Thiru


On Sat, 26 Sept, 2026, 11:33 pm Mark Thomas, <[email protected]> wrote:

> Yes. It is a copy/paste error. Removing the examples (while a good thing
> to do) doesn't mitigate nay of those.
>
> Mark
>
>
> On 26/09/2026 11:48, Thiru wrote:
> > Hi Sebastian,
> >
> > Thank you again for the clarification.
> >
> > One point I missed to mention in my earlier email is that, if this was
> > indeed a copy-and-paste error in the disclosure emails, that would
> explain
> > the apparent inconsistency between the mitigation guidance ("Remove the
> > examples web application") and the code changes associated with the
> fixes,
> > which appear to be in Tomcat core classes.
> >
> > Just to confirm my understanding: for users running production systems
> > where the examples web application is not deployed, upgrading to 9.0.122
> > (or the corresponding fixed release) is still required to remediate these
> > vulnerabilities, and removing the examples application alone should not
> be
> > considered a complete substitute for applying the fixes. Is that correct?
> >
> > Thank you for your time and clarification.
> >
> > Kind regards,
> > Thiru
> >
> > On Sat, 26 Sept, 2026, 4:02 pm Thiru, <[email protected]> wrote:
> >
> >> Hi Sebastian,
> >>
> >> Thank you for the clarification.
> >>
> >> I came across these mitigation details in the vendor advisories
> referenced
> >> by the CVE entries linked from the Tomcat Security 9 page.
> >>
> >> For each of the 12 vulnerabilities, the referenced Tomcat advisory
> >> includes the same mitigation guidance:
> >>
> >> Users of the affected versions should apply one of the following
> >> mitigations:
> >>
> >>     - *Remove the examples web application*
> >>     - Upgrade to Apache Tomcat 11.0.26
> >>     - Upgrade to Apache Tomcat 10.1.60
> >>     - Upgrade to Apache Tomcat 9.0.122
> >>
> >> The advisories referenced from CVE.org are:
> >>
> >>     - https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp
> >>     - https://lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc
> >>     - https://lists.apache.org/thread/tyqcqk99g7ghgk22641vf67vghcyswnw
> >>     - https://lists.apache.org/thread/mb1pjjooqytrl6hbvbt3rw1lqwlon4cz
> >>     - https://lists.apache.org/thread/nmkmjp9l53y8h3oc4n8fc0bkw9dv15sk
> >>     - https://lists.apache.org/thread/bzwps6ck4szf2hmksbbon3syyl9qnkv8
> >>     - https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do
> >>     - https://lists.apache.org/thread/ypvlkjqsq0480fnk9jm6h9qllddwlw4w
> >>     - https://lists.apache.org/thread/qkmsos3s8chn5053qr466rzwv6sk5gjg
> >>     - https://lists.apache.org/thread/y5r9fvjo7ol24mkoyoc0st8bqrfyqcyn
> >>     - https://lists.apache.org/thread/bl5b6rxqh3vb2k9bj2794vhor7o6xl3z
> >>     - https://lists.apache.org/thread/njjcdkkzqyzx4n3ffc4ffjmyh5mpl1gr
> >>
> >> To clarify, we do not deploy the examples application in our production
> >> environments. My question was primarily to understand whether the
> presence
> >> of the examples application is actually a prerequisite for exploiting
> these
> >> vulnerabilities.
> >>
> >> When reviewing some of the associated fixes, I noticed changes in Tomcat
> >> core classes rather than in the examples application itself. That is
> what
> >> led me to wonder whether "Remove the examples web application" is a
> valid
> >> mitigation for these CVEs, or whether upgrading to the fixed Tomcat
> release
> >> is ultimately the only effective mitigation.
> >>
> >> In other words, if the examples application is not deployed, should
> these
> >> vulnerabilities still be considered applicable to the Tomcat instance,
> >> thereby requiring an upgrade to 9.0.122?
> >>
> >> Thank you again for your time and clarification.
> >>
> >> Kind regards,
> >> Thiru
> >>
> >>
> >> On Sat, Sep 26, 2026 at 1:48 PM Sebastian Trost via users <
> >> [email protected]> wrote:
> >>
> >>> On 9/26/26 04:27, Thiru wrote:
> >>>> The security page lists 12 issues (4 Important, 3 Moderate, and 5 Low
> >>>> severity). For each of these CVEs, the mitigation appears to be:
> >>>>
> >>>> Remove the examples web application
> >>>>
> >>>> [...]
> >>>>
> >>>> Could you please clarify whether all 12 CVEs are only exploitable
> >>> through
> >>>> the *examples* web application, and whether removing the examples
> >>>> application alone is sufficient to mitigate these vulnerabilities
> >>> without
> >>>> upgrading Tomcat?
> >>>>
> >>>> Reference:
> >>>>
> >>>
> https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.122
> >>> Where do you see this? The only reference to removing the examples web
> >>> application I can find is in the CVE disclosure mails from Mark. The
> >>> "Remove the examples web application" started with his mail on July
> >>> 28th, CVE-2026-66299, and continues in every other CVE disclosure. My
> >>> guess is that he simply forgot to remove the "Remove the examples web
> >>> application" again and this is a copy&paste mistake.
> >>>
> >>> Why are people so hung up about this examples web application? It
> always
> >>> has been best practice to remove it and the other web applications in
> >>> production environments and to only deploy your own web app.
> >>>
> >>> Sebastian
> >>>
> >>>
> >>>
> >>> ---------------------------------------------------------------------
> >>> To unsubscribe, e-mail: [email protected]
> >>> For additional commands, e-mail: [email protected]
> >>>
> >>>
> >
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
>

Reply via email to