Upgrade Path

Vaultwarden 1.24.0 → 1.37.3

46 versions, 34 with upstream notes (4 repeat an earlier entry), vendor marks no changes as breaking, 0 required stops

Version by version, oldest first

1.25.0 2022-05-23

Warning

⚠️ Reminder: If you are still using the bitwardenrs/server* Docker images, you need to migrate to the new vaultwarden image. Check https://github.com/dani-garcia/vaultwarden/discussions/1642 for an explanation. The old images will not receive any new updates any longer.

Full release notes for 1.25.0

1.25.1 2022-07-16

Warning

Same text as in 1.25.0, above.

Full release notes for 1.25.1

1.25.2 2022-07-27

Warning

Same text as in 1.25.0, above.

Note

Important

An incompatibility between the format in which some Bitwarden clients upload attachments and sends could lead to those uploads being silently corrupted. We believe this is occurring only when using the mobile clients and only on the latest vaultwarden 1.25.1. To mitigate this issue, we're releasing this quick patch to make any upload that could lead to a corrupted file explicitly return an error, notifying the user of the problem. We recommend updating as soon as possible, and checking that any recently uploaded attachments can be downloaded and opened correctly (The corrupted uploads will return an error when downloading or download a very small file).

We've also fixed the docker volume check added in 1.25.1, if you previously needed to set I_REALLY_WANT_VOLATILE_STORAGE=true to start the container, please try again without it, and open an issue if it still won't start.

Full release notes for 1.25.2

1.26.0 – 1.27.0: no action items (2 versions)

1.28.0 2023-03-26

Note

Major changes

  • The project has changed license to the AGPLv3. If you're hosting a Vaultwarden instance, you now have a requirement to distribute the Vaultwarden source code to your users if they request it. The source code, and any changes you have made, need to be under the same AGPLv3 license. If you simply use our code without modifications, just pointing them to this repository is enough.
  • Added support for Argon2 key derivation on the clients. To enable it for your account, make sure all your clients are using version v2023.2.0 or greater, then go to account settings > security > keys, and change the algorithm from PBKDF2 to Argon2id.
  • Added support for Argon2 key derivation for the admin page token. To update your admin token to use it, check the wiki
  • New alternative registries for the docker images are available (In BETA for now):
  • Github Container Registry: https://ghcr.io/dani-garcia/vaultwarden
  • Quay: https://quay.io/vaultwarden/server

Full release notes for 1.28.0

1.28.1: no action items (1 version)

1.29.0 2023-07-09

Note

Major changes and New Features

  • WebSocket notifications now work via the default HTTP port. No need for WEBSOCKET_ENABLED and a separate port anymore. The proxy examples still need to be updated for this. Support for the old websockets port 3012 will remain for the time being.
  • Mobile Client push notification support, see #3304 thanks @GeekCornerGH!
  • Web-Vault updated to v2023.5.0 (v2023.5.1 does not add any improvements for us)
  • The latest Bitwarden Directory Connector can be used now (v2022.11.0)
  • Storing passkeys is supported, though the clients are not yet released. So, it might be we need to make some changes once they are released. See: #3593, thanks @GeekCornerGH!

Full release notes for 1.29.0

1.29.1 – 1.29.2: no action items (2 versions)

1.30.0 2023-11-05

Warning

⚠️ Note: The WebSockets service for live sync has been integrated in the main HTTP server, which means simpler proxy setups that don't require a separate rule to redirect WS traffic to port 3012. Please check the updated examples in the wiki. It's recommended to migrate to this new setup as using the old server on port 3012 is deprecated, won't receive new features and will be removed in a future release.

Note

Major changes and New Features

  • Added passkey support, allowing the browser extensions to store and use your passkeys, make sure the extension is updated to version 2023.10.0 or newer for passkey support.
  • Updated web vault to 2023.10.0.
  • Fixed crashes in ARMv6 devices
  • Fixed crashes when trying to create/edit a cipher in the mobile applications.

Full release notes for 1.30.0

1.30.1 2023-11-19

Warning

Same text as in 1.30.0, above.

Full release notes for 1.30.1

1.30.2 2024-01-30

Warning

⚠️ Note: The WebSockets service for live sync has been integrated in the main HTTP server, which means simpler proxy setups that don't require a separate rule to redirect WS traffic to port 3012. Please check the updated examples in the wiki. It's recommended to migrate to this new setup as using the old server on port 3012 is deprecated, won't receive new features and will be removed in the next release.

Full release notes for 1.30.2

1.30.3 2024-02-01

Warning

Same text as in 1.30.2, above.

Full release notes for 1.30.3

1.30.4 2024-03-02

Warning

Same text as in 1.30.2, above.

Full release notes for 1.30.4

1.30.5: no action items (1 version)

1.31.0 2024-07-08

Note

Major changes and New Features

  • Initial support for the beta releases of the new native mobile apps
  • Removed support for WebSocket traffic on port 3012, as it's been integrated on the main HTTP port for a few releases
  • Updated included web vault to 2024.5.1

Note

General mention

Bitwarden has changed the push API endpoints which affects the EU region endpoint users. So if you use the push functionality and use the EU region you need to make some changes. You have to update push.bitwarden.eu to api.bitwarden.eu. This is also an issue with any previous version of Vaultwarden.

Full release notes for 1.31.0

1.32.0 2024-08-11

Note

Security Fixes

This release has several CVE Reports fixed and we recommend everybody to update to the latest version as soon as possible.

Note

Other changes

  • Updated web-vault to v2024.6.2
  • Fixed issues with password reset enrollment by rolling back a web-vault commit

Full release notes for 1.32.0

1.32.1 2024-10-03

Note

Notable changes

  • Fixed syncing/login with native mobile clients
  • Added CLI option to backup SQLite database
  • Email Template changes regarding invites, 2FA Incomplete logins, and new logins

Full release notes for 1.32.1

1.32.2 2024-10-13

Note

Notable changes

  • Fixed collection management for managers

Full release notes for 1.32.2

1.32.3 2024-10-27

Note

Notable changes

  • Email template for org invites was updated again. The URL got HTML Encoded which resulted in a sometimes non-working URL (#5100)
  • Fixed SMTP issues with some providers which send erroneous response to QUIT messages (Like QQ) (Thanks to @paolobarbolini)
  • Fixed a long standing collection management issue where collections were not able to be managed via the Password Manager overview

Full release notes for 1.32.3

1.32.4 2024-11-10

Note

Security Fixes

This release has fixed some CVE Reports reported by a third party security auditor and we recommend everybody to update to the latest version as soon as possible. The contents of these reports will be disclosed publicly in the future.

Note

Notable changes

  • Added more compatibility fixes for the native mobile apps, datetimes are now formatted without too many decimals.
  • Email Template changes to the send emergency access invite. If you have modified this template, make sure to update it with the new changes.

Full release notes for 1.32.4

1.32.5 2024-11-18

Note

Security Fixes

This release further fixed some CVE Reports reported by a third party security auditor and we recommend everybody to update to the latest version as soon as possible. The contents of these reports will be disclosed publicly in the future.

Note

Notable changes

  • Added SSH-Key storage support. Currently only usable with Bitwarden Desktop v2024.12.0 and newer. You need to enable this feature by adding ssh-key-vault-item,ssh-agent to the EXPERIMENTAL_CLIENT_FEATURE_FLAGS config option. See .env.template

Full release notes for 1.32.5

1.32.6: no action items (1 version)

1.32.7 2024-12-20

Note

Security Fixes

This release contains a security fix for the following CVE https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-g65h-982x-4m5m.

This vulnerability affects any installations that have the ORG_GROUPS_ENABLED setting enabled, and we urge anyone doing so to update as soon as possible.

Full release notes for 1.32.7

1.33.0 2025-01-25

Note

Security Fixes

This release contains security fixes for the following advisories. And we strongly advice to update as soon as possible.

  • GHSA-f7r5-w49x-gxm3 This vulnerability is only possible if you do not have an ADMIN_TOKEN configured and open links or pages you should not trust anyway. Ensure you have an ADMIN_TOKEN configured to keep your admin environment save.
  • GHSA-h6cc-rc6q-23j4 This vulnerability is only possible if someone was able to gain access to your Vaultwarden Admin Backend. The attacker could then change some settings to use sendmail as mail agent but adjust the settings in such a way that it would use a shell command. It then also needed to craft a special favicon image which would have the commands embedded to run during for example sending a test email.
  • GHSA-j4h8-vch3-f797 This vulnerability affects all users who have multiple Organizations and users which are able to create a new organization or have admin or owner rights on at least one organization. The attacker does need to know the Organization UUID of the Organization it want's to attack or compromise though.

Note

Notable changes

  • Updated web-vault to v2025.1.1
  • Added partial manage role support for collections
  • Manager role is converted to a Custom role with either Manage All Collections or per collection. Admins and Owners probably want to check and verify if the rights are still correct.
  • The OCI containers and binaries are signed via GitHub Attestations This allows you to verify an OCI image or even the vaultwarden binary located within the OCI image.

These vulnerabilities affects

Full release notes for 1.33.0

1.33.1 2025-02-03

Note

General mention

This release has some minor issues fixed like:

  • Icon's not working on the Desktop clients
  • Invites not always working
  • DUO settings not able to configure
  • Manager rights
  • Mobile client sync issues fixed

Full release notes for 1.33.1

1.33.2: no action items (1 version)

1.34.0 2025-05-26

Note

Notable changes

  • Updated web-vault to v2025.5.0
  • Implemented new registration flow with email verification
  • Added support for some feature flags (mutual TLS, attachment export, AnonAddy/SimpleLogin self host)

Full release notes for 1.34.0

1.34.1: no action items (1 version)

1.34.2 2025-07-27

Note

Notable changes

Full release notes for 1.34.2

1.34.3 2025-07-30

Note

Notable changes

This release should fix an issue with MySQL/MariaDB database connections when using the Alpine images. The alpine build image has reverted to use MariaDB Connector/C v3.4.5 which resolved the issue.

Full release notes for 1.34.3

1.35.0 2025-12-27

Note

Notable changes

Full release notes for 1.35.0

1.35.1 2025-12-30

Note

Notable changes

  • Fixed issue with applications being logged out after upgrading due to changes to refresh token parsing
  • Updated web vault to 2025.12.1
  • Correctly publish alpine tag, which was missing in 1.35.0

Full release notes for 1.35.1

1.35.2 2026-01-09

Note

Notable changes

Fixed an issue with the web-vault which prevent creating an organization.

Full release notes for 1.35.2

1.35.3 2026-02-10

Note

Security Fixes

This release contains security fixes for the following advisory. We strongly advice to update as soon as possible if you believe it could affect you.

  • GHSA-h265-g7rm-h337 (Publication in process, waiting for CVE assignment) This vulnerability would allow an authenticated attacker that is part of an organization to access items from collections to which the attacker does not belong.

Full release notes for 1.35.3

1.35.4 2026-02-23

Note

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

  • GHSA-w9f8-m526-h7fh. This vulnerability would allow an attacker to access a cipher from a different user (fully encrypted) if they already know its internal UUID.
  • GHSA-h4hq-rgvh-wh27. This vulnerability allows an attacker with manager-level access within an organization to modify collections they can access, even if they do not have management permissions for them.
  • GHSA-r32r-j5jq-3w4m. This vulnerability allows an attacker with manager-level access within an organization to modify collections they are not assigned.

These are private for now, pending CVE assignment.

Full release notes for 1.35.4

1.35.5 2026-04-12

Note

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment.

Note

Notes

  • The admin templates have changed, please update them if you override these via templates.
  • Two Factor Remember Tokens are now valid for max 30 days. Old tokens are invalid directly after upgrading.

Full release notes for 1.35.5

1.35.6 2026-04-12

Note

Notes

The previous release contained an issue where Two Factor Remember Tokens and Recovery Tokens were not accepted at all. This has been fixed now in this release.

Full release notes for 1.35.6

1.35.7 – 1.35.8: no action items (2 versions)

1.36.0 2026-05-03

Note

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment.

Full release notes for 1.36.0

1.37.0 2026-07-24

Note

Note

This update is required for support with clients with version 2026.7.0+, please update before reporting any issues with them.

Note

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment and publishing at a later date.

Full release notes for 1.37.0

1.37.1 2026-07-29

Note

Note

This patch release resolves the issues with invites. If you have applied any workaround to fix this locally, please revert those fixes to prevent possible other issues.

I'm sorry that it took some time to check and validate this fix.

Also, this release fixes an issue (#7475) with all the Alpine based images which are build using https://github.com/BlackDex/rust-musl/. An issue with the build image OpenSSL compilation is resolved and those are used to build the new alpine tagged containers.

Full release notes for 1.37.1

1.37.2 2026-08-22

Note

Note

This update is required for support with clients with version 2026.8.0+, please update before reporting any issues with them.

Important

Also read #7615 for more details if you still have client issues!

Full release notes for 1.37.2

1.37.3: no action items (1 version)

Release notes from github.com/dani-garcia/vaultwarden/releases, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Vaultwarden's release notes have no breaking-changes section. Sections titled Note, Notes, Notable changes, Important, General mention, Major changes, Other changes and Security Fixes, the Docker image notices of 1.16.0, 1.17.0 and 1.21.0, and paragraphs starting with ⚠️, are quoted instead, labelled “Note” or “Warning”.