Re: Regarding apache-tomcat 10.1.58 version
Mark Thomas <[email protected]>
| Newsgroups | gmane.comp.jakarta.tomcat.user |
|---|---|
| Message-ID | <[email protected]> |
Don't send duplicate messages to the mailing list. Read the replies that have already been written and then, if you have nay follow-up questions, reply to those replies, Mark On 06/08/2026 10:40, Roshan Patil wrote: > Hii Mark, > > I hope you are doing well. > > We are currently performing security remediation based on a > Vulnerability Assessment (VA) report. > > The report indicates that our Apache Tomcat installation is > affected by *CVE-2026-66299*and recommends upgrading to *Apache Tomcat > 10.1.58 or later*. The advisory states that the issue affects Apache > Tomcat versions *10.1.24 through 10.1.57*and is fixed in *10.1.58*. > > However, we are unable to find Apache Tomcat *10.1.58*on the > official Apache Tomcat download page or archives. > > The relevant portion of the VA report is as follows: > > o *CVE:*CVE-2026-66299 > o *Affected versions:*Apache Tomcat 10.1.24 through 10.1.57 > o *Recommended remediation:*Upgrade to Apache Tomcat 10.1.58 or > later. > o *Additional note:*Nessus relies on the application's > self-reported version number. > > Could you please help us with the following: > > 1. Has Apache Tomcat *10.1.58*been officially released? > 2. If not, when is it expected to be available? > 3. Is there an alternative fixed version that we should upgrade to in > order to remediate CVE-2026-66299? > 4. If the vulnerability only affects the *examples*web application > (specifically the WebSocket chat example), would removing the > *examples*web application be considered sufficient mitigation until > the fixed version becomes available? > > We appreciate your guidance, as we need to complete our organization's > security remediation and close the VA findings. > > */NOTE:/* /There is not any examples folder in apache-tomcat/webapps/ > directory./ > > > Regards, > Roshan Patil > > ------------------------------------------------------------------------------------------------------------ > [ C-DAC is on Social-Media too. Kindly follow us at: > Facebook: https://www.facebook.com/CDACINDIA & Twitter: @cdacindia ] > > This e-mail is for the sole use of the intended recipient(s) and may > contain confidential and privileged information. If you are not the > intended recipient, please contact the sender by reply e-mail and destroy > all copies and the original message. Any unauthorized review, use, > disclosure, dissemination, forwarding, printing or copying of this email > is strictly prohibited and appropriate legal action will be taken. > ------------------------------------------------------------------------------------------------------------ > >