Apache CXF -- Index Apache CXF Index Download | Documentation Apache CXF Home Download People Project Status Mailing Lists Issue Reporting Special Thanks License Security Advisories Users User's Guide Support FAQ Resources and Articles Search Developers Architecture Guide Source Repository Building Automated Builds Testing-Debugging Coding Guidelines Getting Involved Release Management Subprojects Distributed OSGi XJC Utils Build Utils Fediz ASF How Apache Works Foundation Sponsor Apache Thanks Security Apache CXF: An Open-Source Services Framework Overview Apache CXF is an open source services framework. CXF helps you build and develop services using frontend programming APIs, like JAX-WS and JAX-RS. These services can speak a variety of protocols such as SOAP, XML/HTTP, RESTful HTTP, or CORBA and work over a variety of transports such as HTTP, JMS or JBI. News August 5, 2026 - Apache CXF 4.2.3, 4.1.8 and 3.6.12 released! The Apache CXF team is proud to announce the availability of our latest patch releases! Over 10 JIRA issues were fixed for 4.2.3, 6 JIRA issues were fixed for 4.1.8. and 4 JIRA issues were fixed for 3.6.12. Downloads are availablehere. These releases contain fixes for multiple CVE issues, please see Security Advisories. June 10, 2026 - Apache CXF 4.2.2 and 4.1.7 released! The Apache CXF team is proud to announce the availability of our latest patch releases! Over 5 JIRA issues were fixed for 4.2.2 and 4 JIRA issues were fixed for 4.1.7. Downloads are availablehere. These releases contain fixes for multiple CVE issues, please see Security Advisories. May 20, 2026 - Apache CXF 4.2.1, 4.1.6 and 3.6.11 released! The Apache CXF team is proud to announce the availability of our latest patch releases! Over 15 JIRA issues were fixed for 4.2.1, 10 JIRA issues were fixed for 4.1.6, and 8 JIRA issues were fixed for 3.6.11. Downloads are availablehere. These releases contain fixes for 3 CVE issues, please seeSecurity Advisories. Feb 16, 2026 - Apache CXF 4.2.0, 4.1.5, 4.0.11 and 3.6.10 released! The Apache CXF team is proud to announce the availability of our latest patch releases! 4.2.0 brings Jakarta EE 11 support, over 15 JIRA issues were fixed for 4.1.5, 14 JIRA issues were fixed for 4.0.11, 8 JIRA issues were fixed for 3.6.10. Downloads are availablehere. Nov 17, 2025 - Apache CXF 4.1.4, 4.0.10 and 3.6.9 released! The Apache CXF team is proud to announce the availability of our latest patch releases! Over 13 JIRA issues were fixed for 4.1.4, 11 JIRA issues were fixed for 4.0.10, 12 JIRA issues were fixed for 3.6.9. Downloads are availablehere. Aug 06, 2025 - Apache CXF 4.1.3, 4.0.9 and 3.6.8 released! The Apache CXF team is proud to announce the availability of our latest patch releases! Over 10 JIRA issues were fixed for 4.1.3 and 4.0.9, 6 JIRA issues were fixed for 3.6.8. These releases contain a fix for a new CVE: https://cxf.apache.org/security-advisories.data/CVE-2025-48913.txt Downloads are availablehere. May 23, 2025 - Apache CXF 4.1.2, 4.0.8 and 3.6.7 released! The Apache CXF team is proud to announce the availability of our latest patch releases! Over 16 JIRA issues were fixed for 4.1.2, 11 JIRA issues were fixed for 4.0.8, 10 JIRA issues were fixed for 3.6.7. Downloads are availablehere. Mar 6, 2025 - Apache CXF 4.1.1, 4.0.7, 3.6.6 and 3.5.11 released! The Apache CXF team is proud to announce the availability of our latest patch releases! Over 17 JIRA issues were fixed for 4.1.1, 14 JIRA issues were fixed for 4.0.7, 11 JIRA issues were fixed for 3.6.6 and 5 JIRA issues were fixed for 3.5.11. Please note that the CXF 3.5.11 is the last release of CXF 3.5.x series Downloads are availablehere. Dec 13, 2024 - Apache CXF 4.1.0 released! The Apache CXF team is proud to announce the availability of CXF 4.1.0! The 4.1.0 is our first release to feature Jakarta EE 10 support and JDK-17 baseline Over 54 JIRA issues were fixed for 4.1.0, Downloads are availablehere. Dec 9, 2024 - Apache CXF 3.5.10, 3.6.5 and 4.0.6 released! The Apache CXF team is proud to announce the availability of our latest patch releases! Over 29 JIRA issues were fixed for 4.0.6, 25 JIRA issues were fixed for 3.6.5 and 18 JIRA issues were fixed for 3.5.10. Downloads are availablehere. July 17, 2024 - Apache CXF 3.5.9, 3.6.4 and 4.0.5 released! The Apache CXF team is proud to announce the availability of our latest patch releases! Over 19 JIRA issues were fixed for 4.0.5. These releases contain fixes for 3 different CVEs: https://cxf.apache.org/security-advisories.data/CVE-2024-29736.txt https://cxf.apache.org/security-advisories.data/CVE-2024-32007.txt https://cxf.apache.org/security-advisories.data/CVE-2024-41172.txt Downloads are availablehere. March 12, 2024 - Apache CXF 3.5.8, 3.6.3 and 4.0.4 released! The Apache CXF team is proud to announce the availability of our latest patch releases! Over 28 JIRA issues were fixed for 4.0.4. These releases contain a fix for a new security issue: https://cxf.apache.org/security-advisories.data/CVE-2024-28752.txt Downloads are availablehere. Sept 18, 2023 - Apache CXF 3.5.7, 3.6.2 and 4.0.3 released! The Apache CXF team is proud to announce the availability of our latest patch releases! Over 15 JIRA issues were fixed for 4.01 and 3.5.6. Downloads are availablehere. June 12, 2023 - Apache CXF 3.6.1 and 4.0.2 released! The Apache CXF team is proud to announce the availability of our latest patch releases! Over 7 JIRA issues were fixed for 4.0.2 and 3.6.1. Downloads are availablehere. May 8, 2023 - Apache CXF 3.5.6, 3.6.0 and 4.0.1 released! The Apache CXF team is proud to announce the availability of our latest patch releases! Over 15 JIRA issues were fixed for 4.01 and 3.5.6. Downloads are availablehere. Features CXF includes a broad feature set, but it is primarily focused on the following areas: Web Services Standards Support: CXF supports a variety of web service standards including SOAP, the WS-I Basic Profile, WSDL, WS-Addressing, WS-Policy, WS-ReliableMessaging, WS-Security, WS-SecurityPolicy, WS-SecureConverstation, and WS-Trust (partial). Frontends: CXF supports a variety of "frontend" programming models. CXF implements the JAX-WS APIs. CXF JAX-WS support includes some extensions to the standard that make it significantly easier to use, compared to the reference implementation: It will automatically generate code for request and response bean classes, and does not require a WSDL for simple cases. It also includes a "simple frontend" which allows creation of clients and endpoints without annotations. CXF supports both contract first development with WSDL and code first development starting from Java. For REST, CXF also supports a JAX-RS frontend. Ease of use: CXF is designed to be intuitive and easy to use. There are simple APIs to quickly build code-first services, Maven plug-ins to make tooling integration easy, JAX-WS API support, Spring 2.x XML support to make configuration a snap, and much more. Binary and Legacy Protocol Support: CXF has been designed to provide a pluggable architecture that supports not only XML but also non-XML type bindings, such as JSON and CORBA, in combination with any type of transport. To get started using CXF, check out the downloads, the user's guide, or the mailing lists to get more information! Goals General High Performance Extensible Intuitive & Easy to Use Support for Standards JSR Support JAX-WS - Java API for XML-Based Web Services (JAX-WS) 2.0 - JSR-224 Web Services Metadata for the Java Platform - JSR-181 JAX-RS - The Java API for RESTful Web Services - JSR-311, JSR-370 SAAJ - SOAP with Attachments API for Java (SAAJ) - JSR-67 WS-* and related Specifications Support Basic support: WS-I Basic Profile 1.1 Quality of Service: WS-Reliable Messaging Metadata: WS-Policy, WSDL 1.1 - Web Service Definition Language Communication Security: WS-Security, WS-SecurityPolicy, WS-SecureConversation, WS-Trust (partial support) Messaging Support: WS-Addressing, SOAP 1.1, SOAP 1.2, Message Transmission Optimization Mechanism (MTOM) OpenAPI Specification (OAS) Support OAS 2.0 (classic Swagger specification) OAS 3.0.x (new revised specification) Multiple Transports, Protocol Bindings, Data Bindings, and Formats Transports: HTTP, Servlet, JMS, In-VM and many others via the Camel transport for CXF such as SMTP/POP3, TCP and Jabber Protocol Bindings: SOAP, REST/HTTP, pure XML Data bindings: JAXB 2.x, Aegis, Apache XMLBeans, Service Data Objects (SDO), JiBX Formats: XML Textual, JSON, FastInfoset Extensibility API allows additional bindings for CXF, enabling additional message format support such as CORBA/IIOP Flexible Deployment Lightweight containers: deploy services in Jetty, Tomcat or Spring-based containers JBI integration: deploy as a service engine in a JBI container such as ServiceMix, OpenESB or Petals Java EE integration: deploy services in Java EE application servers such as Apache Geronimo, JOnAS, Redhat JBoss, OC4J, Oracle WebLogic, and IBM WebSphere Standalone Java client/server Support for Multiple Programming Languages Full support for JAX-WS 2.x client/server programming model JAX-WS 2.x synchronous, asynchronous and one-way API's JAX-WS 2.x Dynamic Invocation Interface (DII) API JAX-RS for RESTful clients Support for wrapped and non-wrapped styles XML messaging API Support for JavaScript and ECMAScript 4 XML (E4X) - both client and server Support for CORBA Support for JBI with ServiceMix Tooling Generating Code: WSDL to Java, WSDL to JavaScript, Java to JavaScript Generating WSDL: Java to WSDL, XSD to WSDL, IDL to WSDL, WSDL to XML Adding Endpoints: WSDL to SOAP, WSDL to CORBA, WSDL to service Generating Support Files: WSDL to IDL Validating Files: WSDL Validation Getting Involved Apache CXF is currently under heavy development. To get involved you can subscribe to the mailing lists. You can also grab the code from the Source Repository. You also need to read about Building CXF. For Eclipse users, you should read about Setting up Eclipse. Privacy Policy - (edit page) (add comment) Apache CXF, CXF, Apache, the Apache feather logo are trademarks of The Apache Software Foundation. All other marks mentioned may be trademarks or registered trademarks of their respective owners.