Skip to content

[GHSA-rpf9-hrjr-88fv] Uncontrolled Resource Consumption vulnerability in Apache... - #9019

Open
adriansubu wants to merge 1 commit into
adriansubu/advisory-improvement-9019from
adriansubu-GHSA-rpf9-hrjr-88fv
Open

[GHSA-rpf9-hrjr-88fv] Uncontrolled Resource Consumption vulnerability in Apache...#9019
adriansubu wants to merge 1 commit into
adriansubu/advisory-improvement-9019from
adriansubu-GHSA-rpf9-hrjr-88fv

Conversation

@adriansubu

Copy link
Copy Markdown

Updates

  • Affected products
  • Description
  • References
  • Source code location
  • Summary

Comments
The current advisory does not sufficiently distinguish between the presence of an affected Tomcat version and deployment of the vulnerable functionality.

CVE-2026-66299 is limited to Tomcat's optional WebSocket chat example application. Apache rates the vulnerability Low and explicitly states that installations without the examples web application are not affected. Typical embedded Tomcat applications do not package or deploy this example application.

Please clarify this applicability condition and review the current High severity against Apache's authoritative Low vendor assessment. The existing 7.5 vector assumes that the vulnerable example application is installed, remotely reachable, and capable of causing complete availability loss.

No independently calculated replacement CVSS vector is proposed. The request is to reflect the vendor severity and restricted applicability.

Vendor advisory:
https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.25

Fix commit:
apache/tomcat@4e8e3f8

@github-actions
github-actions Bot changed the base branch from main to adriansubu/advisory-improvement-9019 August 7, 2026 07:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant