New severity for security reports
Mark Thomas <[email protected]> Wed, 15 Jul 2026 10:03:20 +0100
| Newsgroups | gmane.comp.jakarta.tomcat.devel |
|---|---|
| Message-ID | <[email protected]> |
All, We have had quite a few security reports recently that are technically valid vulnerabilities but have pre-requisites that are such that it is almost certain no users are impacted by them. Currently we assign these a severity of LOW. Do we want to handle them differently? Possible options: - Don't issue CVEs for these - New severity for "Lower than low" name TBD - Something else? Mark