Quarkus CXF 3.33.14 LTS release notes

Important dependency upgrades

Bugfixes

#2320 Methods of org.apache.cxf.ws.addressing.ContextUtils not found: $jacocoInit(…​)

Before Quarkus CXF 3.40.2 and 3.33.14, running @QuarkusTest tests with JaCoCo instrumentation could fail during class transformation with the named error. The transformer expected the synthetic $jacocoInit(…​) method added to QuarkusCxfContextUtils to have a counterpart in CXF’s ContextUtils. Since Quarkus CXF 3.40.2 and 3.33.14, the transformer ignores synthetic methods, allowing these tests to start.

Special thanks to @eekhoorn01 for reporting the issue.

Deprecations

WSS4J BouncyCastleUtils deprecated

WSS4J 4.0.2 deprecates org.apache.wss4j.common.crypto.BouncyCastleUtils for removal. Use org.apache.wss4j.common.crypto.X509KeyIdentifierUtil instead. The old class delegates to the new one for compatibility. See the WSS4J migration guide.

Breaking changes

Stricter XPath validation in streaming WS-SecurityPolicy

Before Quarkus CXF 3.40.2 and 3.33.14, unsupported XPath expressions in streaming WS-SecurityPolicy assertions could silently fail to enforce the intended protection. Since Quarkus CXF 3.40.2 and 3.33.14, WSS4J rejects descendant steps (//), wildcards, predicates and functions in these expressions. Use simple element paths, for example /soap:Envelope/soap:Header/wsse:Security/saml2:Assertion with the corresponding namespace declarations, instead of //saml2:Assertion. See CVE-2026-87830 for background.

WSS4J DOMX509SKI constructor declares a checked exception

Before Quarkus CXF 3.40.2 and 3.33.14, org.apache.wss4j.common.token.DOMX509SKI(Document, X509Certificate) did not declare a checked exception. Since Quarkus CXF 3.40.2 and 3.33.14, this constructor declares WSSecurityException for malformed SubjectKeyIdentifier extensions. Applications calling this constructor directly must catch or declare that exception when recompiling. See the WSS4J migration guide.