Quarkus CXF 3.33.14 LTS release notes
Important dependency upgrades
-
Apache WSS4J 4.0.1 → 4.0.2 - release notes, changelog, fixed CVEs (see the Apache WSS4J security advisories for details):
-
CVE-2026-85532 Inadequate bounds on derived-key lengths and offsets
-
CVE-2026-87830 Streaming policy validation can fail to enforce element signatures and encryption
-
CVE-2026-88920 Forged SAML sender-vouches assertions can bypass authentication
-
CVE-2026-89238 Incorrect selection of a decrypted header can bypass protection requirements
-
CVE-2026-92121 Streaming signature policy checks can be bypassed after processing an STR-Transform reference
-
CVE-2026-92899 Alternate nonce encodings can bypass UsernameToken replay detection
-
CVE-2026-95616 Malformed X.509 certificate extensions can trigger excessive memory allocation
-
Bugfixes
#2320 Methods of org.apache.cxf.ws.addressing.ContextUtils not found: $jacocoInit(…)
Before Quarkus CXF 3.40.2 and 3.33.14, running @QuarkusTest tests with JaCoCo instrumentation could fail during class transformation with the named error.
The transformer expected the synthetic $jacocoInit(…) method added to QuarkusCxfContextUtils to have a counterpart in CXF’s ContextUtils.
Since Quarkus CXF 3.40.2 and 3.33.14, the transformer ignores synthetic methods, allowing these tests to start.
Special thanks to @eekhoorn01 for reporting the issue.
Deprecations
WSS4J BouncyCastleUtils deprecated
WSS4J 4.0.2 deprecates org.apache.wss4j.common.crypto.BouncyCastleUtils for removal.
Use org.apache.wss4j.common.crypto.X509KeyIdentifierUtil instead.
The old class delegates to the new one for compatibility.
See the WSS4J migration guide.
Breaking changes
Stricter XPath validation in streaming WS-SecurityPolicy
Before Quarkus CXF 3.40.2 and 3.33.14, unsupported XPath expressions in streaming WS-SecurityPolicy assertions could silently fail to enforce the intended protection.
Since Quarkus CXF 3.40.2 and 3.33.14, WSS4J rejects descendant steps (//), wildcards, predicates and functions in these expressions.
Use simple element paths, for example /soap:Envelope/soap:Header/wsse:Security/saml2:Assertion with the corresponding namespace declarations, instead of //saml2:Assertion.
See CVE-2026-87830 for background.
WSS4J DOMX509SKI constructor declares a checked exception
Before Quarkus CXF 3.40.2 and 3.33.14, org.apache.wss4j.common.token.DOMX509SKI(Document, X509Certificate) did not declare a checked exception.
Since Quarkus CXF 3.40.2 and 3.33.14, this constructor declares WSSecurityException for malformed SubjectKeyIdentifier extensions.
Applications calling this constructor directly must catch or declare that exception when recompiling.
See the WSS4J migration guide.