Hi Sebastian,
Thank you again for the clarification.
One point I missed to mention in my earlier email is that, if this was
indeed a copy-and-paste error in the disclosure emails, that would explain
the apparent inconsistency between the mitigation guidance ("Remove the
examples web application") and the code changes associated with the fixes,
which appear to be in Tomcat core classes.
Just to confirm my understanding: for users running production systems
where the examples web application is not deployed, upgrading to 9.0.122
(or the corresponding fixed release) is still required to remediate these
vulnerabilities, and removing the examples application alone should not be
considered a complete substitute for applying the fixes. Is that correct?
Thank you for your time and clarification.
Kind regards,
Thiru
On Sat, 26 Sept, 2026, 4:02 pm Thiru, <[email protected]> wrote:
> Hi Sebastian,
>
> Thank you for the clarification.
>
> I came across these mitigation details in the vendor advisories referenced
> by the CVE entries linked from the Tomcat Security 9 page.
>
> For each of the 12 vulnerabilities, the referenced Tomcat advisory
> includes the same mitigation guidance:
>
> Users of the affected versions should apply one of the following
> mitigations:
>
> - *Remove the examples web application*
> - Upgrade to Apache Tomcat 11.0.26
> - Upgrade to Apache Tomcat 10.1.60
> - Upgrade to Apache Tomcat 9.0.122
>
> The advisories referenced from CVE.org are:
>
> - https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp
> - https://lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc
> - https://lists.apache.org/thread/tyqcqk99g7ghgk22641vf67vghcyswnw
> - https://lists.apache.org/thread/mb1pjjooqytrl6hbvbt3rw1lqwlon4cz
> - https://lists.apache.org/thread/nmkmjp9l53y8h3oc4n8fc0bkw9dv15sk
> - https://lists.apache.org/thread/bzwps6ck4szf2hmksbbon3syyl9qnkv8
> - https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do
> - https://lists.apache.org/thread/ypvlkjqsq0480fnk9jm6h9qllddwlw4w
> - https://lists.apache.org/thread/qkmsos3s8chn5053qr466rzwv6sk5gjg
> - https://lists.apache.org/thread/y5r9fvjo7ol24mkoyoc0st8bqrfyqcyn
> - https://lists.apache.org/thread/bl5b6rxqh3vb2k9bj2794vhor7o6xl3z
> - https://lists.apache.org/thread/njjcdkkzqyzx4n3ffc4ffjmyh5mpl1gr
>
> To clarify, we do not deploy the examples application in our production
> environments. My question was primarily to understand whether the presence
> of the examples application is actually a prerequisite for exploiting these
> vulnerabilities.
>
> When reviewing some of the associated fixes, I noticed changes in Tomcat
> core classes rather than in the examples application itself. That is what
> led me to wonder whether "Remove the examples web application" is a valid
> mitigation for these CVEs, or whether upgrading to the fixed Tomcat release
> is ultimately the only effective mitigation.
>
> In other words, if the examples application is not deployed, should these
> vulnerabilities still be considered applicable to the Tomcat instance,
> thereby requiring an upgrade to 9.0.122?
>
> Thank you again for your time and clarification.
>
> Kind regards,
> Thiru
>
>
> On Sat, Sep 26, 2026 at 1:48 PM Sebastian Trost via users <
> [email protected]> wrote:
>
>> On 9/26/26 04:27, Thiru wrote:
>> > The security page lists 12 issues (4 Important, 3 Moderate, and 5 Low
>> > severity). For each of these CVEs, the mitigation appears to be:
>> >
>> > Remove the examples web application
>> >
>> > [...]
>> >
>> > Could you please clarify whether all 12 CVEs are only exploitable
>> through
>> > the *examples* web application, and whether removing the examples
>> > application alone is sufficient to mitigate these vulnerabilities
>> without
>> > upgrading Tomcat?
>> >
>> > Reference:
>> >
>> https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.122
>> Where do you see this? The only reference to removing the examples web
>> application I can find is in the CVE disclosure mails from Mark. The
>> "Remove the examples web application" started with his mail on July
>> 28th, CVE-2026-66299, and continues in every other CVE disclosure. My
>> guess is that he simply forgot to remove the "Remove the examples web
>> application" again and this is a copy&paste mistake.
>>
>> Why are people so hung up about this examples web application? It always
>> has been best practice to remove it and the other web applications in
>> production environments and to only deploy your own web app.
>>
>> Sebastian
>>
>>
>>
>> ---------------------------------------------------------------------
>> To unsubscribe, e-mail: [email protected]
>> For additional commands, e-mail: [email protected]
>>
>>