Quarkus CXF 3.33.11 LTS release notes

Important dependency upgrades

Enhancements

New WS-Addressing decoupled endpoint configuration options

The following options configure the WS-Addressing changes introduced in Apache CXF PR #3279:

These options replace the plain CXF system properties org.apache.cxf.ws.addressing.decoupled.enabled and org.apache.cxf.ws.addressing.decoupled.allowedSchemes. Setting either system property directly causes the application to fail at startup. WS-Addressing log and error messages now refer to the corresponding Quarkus CXF configuration options.

Breaking changes

WS-Addressing decoupled destinations disabled by default

Before Quarkus CXF 3.39.0 and 3.33.11, WS-Addressing clients could request non-anonymous reply or fault destinations without explicitly enabling this on the server. Since Quarkus CXF 3.33.11, such requests are rejected with a DestinationUnreachable fault by default to prevent Server-Side Request Forgery (SSRF). Applications that require decoupled WS-Addressing callbacks must enable them using quarkus.cxf.endpoint.addressing.decoupled.enabled and configure the allowed URI scheme prefixes via quarkus.cxf.endpoint.addressing.decoupled.allowed-schemes if the defaults are insufficient.

Default attachment size limit

Before Quarkus CXF 3.39.0 and 3.33.11, CXF did not impose a default maximum attachment size. Since Quarkus CXF 3.33.11, the upgrade to CXF 4.1.8 introduces a default limit of 50 MB. Applications that process larger attachments must explicitly configure the CXF attachment-max-size contextual property. See Securing CXF Services for details.

Apache HttpComponents dependency management

The Quarkus CXF BOM no longer manages Apache HttpClient 5 and HttpCore 5 artifacts directly. Their versions are now managed by the Quarkus BOM. Applications relying solely on the Quarkus CXF BOM for these artifacts should use the Quarkus Platform BOMs or provide their own dependency management.