Re: Update for new versions

Mark Thomas <[email protected]>
Newsgroups gmane.comp.jakarta.tomcat.user
Message-ID <[email protected]>
On 20/08/2026 06:52, Venkumahanti Praveen wrote:
> Good morning Tomcat team,
> 
> I have installed the latest version of Tomcat, currently 9.0.120.0 and
> 10.1.57.0.
> 
> However, our security scan is still reporting a vulnerability associated
> with " CVE-2026-66299 ".
> Could you please advise if there is any recommended mitigation or
> workaround available to address this vulnerability?

You mean other than the mitigation described in the announcement [1], 
the published vulnerability information [2] and discussed on this list [3]?

> Alternatively, please let us know when a Tomcat release containing a fix
> for the vulnerability is expected to be available.

Why are you waiting for a new release? Although if you'd looked on the 
Tomcat website [4] or the past day's messages on this list [5] you would 
have seen that 9.0.121 is already available.

Mark

[1] https://lists.apache.org/[email protected]
[2] 
https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.25
[3] https://lists.apache.org/thread/84ydmgv8txmd8gqc174x15cv3s2hdh2j
[4] https://tomcat.apache.org/
[5] https://lists.apache.org/thread/sk8qd4xrbf18ct76jxgwqzf8ohzd8869
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.