Quarkus CXF 3.33.13 LTS release notes
Important dependency upgrades
-
Apache XMLSchema 2.3.2 → 2.3.3 - release notes, changelog, fixed CVEs (see the Apache XMLSchema security advisories for details):
-
CVE-2026-102495 Stack exhaustion when resolving deeply nested schema imports and includes
-
CVE-2026-102496 Stack exhaustion when parsing deeply nested schema structures
-
CVE-2026-102497 Stack exhaustion when the schema walker processes cyclic definitions (
xmlschema-walker)
-