Re: [SECURITY] CVE-2026-66299 Apache Tomcat - DoS via WebSocket chat example

Mark Thomas <[email protected]> Tue, 28 Jul 2026 15:44:07 +0100
Newsgroups gmane.comp.jakarta.tomcat.devel
Message-ID <[email protected]>
On 28/07/2026 15:26, Mark Thomas wrote:
> CVE-2026-66299 Apache Tomcat - DoS via WebSocket chat example

<snip/>

The majority of the subscribers here aren't part of the Tomcat security 
team so we wanted to make everyone aware of some of the discussions the 
security team had about this issue.

Given that this issue shouldn't affect anyone (everyone has followed the 
advice to remove the examples web application for production - right?), 
we wanted to use this as an experiment to see how the community reacted 
to us publishing a CVE that they should not be impacted by when they 
can't currently obtain a release with a fix for the CVE.

One of the ideas floated in various OSS projects to help manage the 
flood of AI generated vulnerability reports - particularly where it is 
highly unlikely any users will be affected - is to fix and publish 
without a release. The purpose of this experiment is to see what that 
might look like for the Tomcat community.

Mark