New severity for security reports

Mark Thomas <[email protected]> Wed, 15 Jul 2026 10:03:20 +0100
Newsgroups gmane.comp.jakarta.tomcat.devel
Message-ID <[email protected]>
All,

We have had quite a few security reports recently that are technically 
valid vulnerabilities but have pre-requisites that are such that it is 
almost certain no users are impacted by them.

Currently we assign these a severity of LOW. Do we want to handle them 
differently?

Possible options:
- Don't issue CVEs for these
- New severity for "Lower than low" name TBD
- Something else?

Mark