Possible missing CVE commits in 9.0.120, 10.1.57 and 11.0.24 release builds

Thomas Williams <[email protected]> Thu, 16 Jul 2026 12:00:21 -0700
Newsgroups gmane.comp.jakarta.tomcat.user
Message-ID <CABWd67Em_z22zNsba7mwGR3pQMG_AE3TCPJhAvobXN8Xee-OTw@mail.gmail.com>
--000000000000ee77120656bf0dc0
Content-Type: text/plain; charset="UTF-8"

Hi Tomcat Team,

I noticed a discrepancy between the recent release documentation and the
actual release artifacts for Tomcat 9.0.120, 10.1.57 and 11.0.24.

The release notes state that CVE-2026-59084 was fixed via commits 617d7275
for 9.0.120, 79466463 for 10.1.57 and 57e80e9b 11.0.24. However, checking
the source tree for the 9.0.120, 10.1.57 and 11.0.24 tags, these commits do
not appear to be merged into the release builds.

Could someone please verify if these fixes were accidentally omitted from
the artifacts, or if the release notes are pointing to the wrong commit
references?

Thanks,
Tommy Williams

--000000000000ee77120656bf0dc0--