Quarkus CXF 3.33.12 LTS release notes
Important dependency upgrades
-
Apache Neethi 3.2.2 → 3.2.4 - release announcement, changelog, fixed CVEs (see the Apache Neethi security advisories for details):
-
CVE-2026-66142 Uncontrolled recursion during policy processing
-
CVE-2026-66143 Bypass of limits on normalized policy alternatives
-
CVE-2026-66144 Unbounded data read when fetching remote policy references
-
CVE-2026-91863 Stack exhaustion through policies that bypass the nesting-depth limit
-
CVE-2026-91864 Heap exhaustion through assertions that bypass element and attribute limits
-
CVE-2026-91865 Excessive expansion of repeated policy references during normalization
-
CVE-2026-91866 Unbounded computation during policy intersection
-
CVE-2026-91867 Missing total timeout when fetching remote policies
-