Don't send duplicate messages to the mailing list. Read the replies that have already been written and then, if you have nay follow-up questions, reply to those replies,

Mark


On 06/08/2026 10:40, Roshan Patil wrote:
Hii Mark,

         I hope you are doing well.

        We are currently performing security remediation based on a Vulnerability Assessment (VA) report.

        The report indicates that our Apache Tomcat installation is affected by *CVE-2026-66299*and recommends upgrading to *Apache Tomcat 10.1.58 or later*. The advisory states that the issue affects Apache Tomcat versions *10.1.24 through 10.1.57*and is fixed in *10.1.58*.

        However, we are unable to find Apache Tomcat *10.1.58*on the official Apache Tomcat download page or archives.

         The relevant portion of the VA report is as follows:

      o *CVE:*CVE-2026-66299
      o *Affected versions:*Apache Tomcat 10.1.24 through 10.1.57
     o *Recommended remediation:*Upgrade to Apache Tomcat 10.1.58 or later.
      o *Additional note:*Nessus relies on the application's
        self-reported version number.

Could you please help us with the following:

1. Has Apache Tomcat *10.1.58*been officially released?
2. If not, when is it expected to be available?
3. Is there an alternative fixed version that we should upgrade to in
    order to remediate CVE-2026-66299?
4. If the vulnerability only affects the *examples*web application
    (specifically the WebSocket chat example), would removing the
    *examples*web application be considered sufficient mitigation until
    the fixed version becomes available?

We appreciate your guidance, as we need to complete our organization's security remediation and close the VA findings.

*/NOTE:/* /There is not any examples folder in apache-tomcat/webapps/ directory./


Regards,
Roshan Patil

------------------------------------------------------------------------------------------------------------
[ C-DAC is on Social-Media too. Kindly follow us at:
Facebook: https://www.facebook.com/CDACINDIA & Twitter: @cdacindia ]

This e-mail is for the sole use of the intended recipient(s) and may
contain confidential and privileged information. If you are not the
intended recipient, please contact the sender by reply e-mail and destroy
all copies and the original message. Any unauthorized review, use,
disclosure, dissemination, forwarding, printing or copying of this email
is strictly prohibited and appropriate legal action will be taken.
------------------------------------------------------------------------------------------------------------




---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to