| Summary: CVE-2026-66299 is an Apache Tomcat uncontrolled resource consumption issue in the WebSocket chat example application. The Tomcat 9.0.120 patch does not include the upstream fix for this CVE. Engineering assessment determined that standard DocuShare deployments are not affected because the Tomcat examples web application is not used by DocuShare. |
Overview
CVE-2026-66299 affects Apache Tomcat versions 9.0.89 through 9.0.120 when the vulnerable WebSocket chat example application is available. The issue is not caused by normal DocuShare document, search, or administration activity.
Xerox engineering reviewed this CVE against the Tomcat configuration used by DocuShare and determined that standard DocuShare deployments are not vulnerable because they do not use the affected examples application.
Affected DocuShare Releases
This assessment applies to standard DocuShare 7.5, 7.6, 7.7, and 8.0 deployments using the Xerox-supplied Tomcat configuration.
| Important: The conclusion above assumes that the standard DocuShare Tomcat configuration has not been changed to deploy or expose the Tomcat examples web application. Custom Tomcat content or configuration must be reviewed separately. |
Recommended Action
- Apply the Tomcat 9.0.120 patch that matches your installed DocuShare release, as recommended for the other Tomcat findings covered by that patch.
- If the Tomcat examples web application is present in your environment, remove it according to your organization’s change-control procedures.
- Do not deploy the Tomcat WebSocket chat example application on a DocuShare server.
- Plan to apply the first DocuShare Tomcat patch that includes the upstream Tomcat 9.0.121 fix, when Xerox makes that patch available for your release.
How to Check Your Environment
- Review the DocuShare Tomcat web applications and confirm that the examples application is not deployed.
- If the examples application is present, remove it or contact DocuShare Support before making the change.
- Restart the DocuShare services according to your normal maintenance procedure.
- Verify that DocuShare login, document access, search, and administration functions operate normally.