Re: Update for new versions
Mark Thomas <[email protected]>
| Newsgroups | gmane.comp.jakarta.tomcat.user |
|---|---|
| Message-ID | <[email protected]> |
On 20/08/2026 06:52, Venkumahanti Praveen wrote: > Good morning Tomcat team, > > I have installed the latest version of Tomcat, currently 9.0.120.0 and > 10.1.57.0. > > However, our security scan is still reporting a vulnerability associated > with " CVE-2026-66299 ". > Could you please advise if there is any recommended mitigation or > workaround available to address this vulnerability? You mean other than the mitigation described in the announcement [1], the published vulnerability information [2] and discussed on this list [3]? > Alternatively, please let us know when a Tomcat release containing a fix > for the vulnerability is expected to be available. Why are you waiting for a new release? Although if you'd looked on the Tomcat website [4] or the past day's messages on this list [5] you would have seen that 9.0.121 is already available. Mark [1] https://lists.apache.org/[email protected] [2] https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.25 [3] https://lists.apache.org/thread/84ydmgv8txmd8gqc174x15cv3s2hdh2j [4] https://tomcat.apache.org/ [5] https://lists.apache.org/thread/sk8qd4xrbf18ct76jxgwqzf8ohzd8869