Vaultwarden 1.31.0 → 1.37.3
29 versions, 23 with upstream notes, vendor marks no changes as breaking, 0 required stops
Version by version, oldest first
1.32.0 2024-08-11
Note
Security Fixes
This release has several CVE Reports fixed and we recommend everybody to update to the latest version as soon as possible.
- CVE-2024-39924 Fixed via #4715
- CVE-2024-39925 Fixed via #4837
- CVE-2024-39926 Fixed via #4737
Note
Other changes
- Updated web-vault to v2024.6.2
- Fixed issues with password reset enrollment by rolling back a web-vault commit
1.32.1 2024-10-03
Note
Notable changes
- Fixed syncing/login with native mobile clients
- Added CLI option to backup SQLite database
- Email Template changes regarding invites, 2FA Incomplete logins, and new logins
1.32.2 2024-10-13
Note
Notable changes
- Fixed collection management for managers
1.32.3 2024-10-27
Note
Notable changes
- Email template for org invites was updated again. The URL got HTML Encoded which resulted in a sometimes non-working URL (#5100)
- Fixed SMTP issues with some providers which send erroneous response to
QUITmessages (Like QQ) (Thanks to @paolobarbolini) - Fixed a long standing collection management issue where collections were not able to be managed via the Password Manager overview
1.32.4 2024-11-10
Note
Security Fixes
This release has fixed some CVE Reports reported by a third party security auditor and we recommend everybody to update to the latest version as soon as possible. The contents of these reports will be disclosed publicly in the future.
Note
Notable changes
- Added more compatibility fixes for the native mobile apps, datetimes are now formatted without too many decimals.
- Email Template changes to the send emergency access invite. If you have modified this template, make sure to update it with the new changes.
1.32.5 2024-11-18
Note
Security Fixes
This release further fixed some CVE Reports reported by a third party security auditor and we recommend everybody to update to the latest version as soon as possible. The contents of these reports will be disclosed publicly in the future.
Note
Notable changes
- Added SSH-Key storage support. Currently only usable with Bitwarden Desktop v2024.12.0 and newer. You need to enable this feature by adding
ssh-key-vault-item,ssh-agentto theEXPERIMENTAL_CLIENT_FEATURE_FLAGSconfig option. See .env.template
1.32.6: no action items (1 version)
1.32.7 2024-12-20
Note
Security Fixes
This release contains a security fix for the following CVE https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-g65h-982x-4m5m.
This vulnerability affects any installations that have the ORG_GROUPS_ENABLED setting enabled, and we urge anyone doing so to update as soon as possible.
1.33.0 2025-01-25
Note
Security Fixes
This release contains security fixes for the following advisories. And we strongly advice to update as soon as possible.
- GHSA-f7r5-w49x-gxm3 This vulnerability is only possible if you do not have an
ADMIN_TOKENconfigured and open links or pages you should not trust anyway. Ensure you have anADMIN_TOKENconfigured to keep your admin environment save. - GHSA-h6cc-rc6q-23j4 This vulnerability is only possible if someone was able to gain access to your Vaultwarden Admin Backend. The attacker could then change some settings to use sendmail as mail agent but adjust the settings in such a way that it would use a shell command. It then also needed to craft a special favicon image which would have the commands embedded to run during for example sending a test email.
- GHSA-j4h8-vch3-f797 This vulnerability affects all users who have multiple Organizations and users which are able to create a new organization or have admin or owner rights on at least one organization. The attacker does need to know the Organization UUID of the Organization it want's to attack or compromise though.
Note
Notable changes
- Updated web-vault to v2025.1.1
- Added partial manage role support for collections
- Manager role is converted to a Custom role with either Manage All Collections or per collection. Admins and Owners probably want to check and verify if the rights are still correct.
- The OCI containers and binaries are signed via GitHub Attestations This allows you to verify an OCI image or even the
vaultwardenbinary located within the OCI image.
These vulnerabilities affects
1.33.1 2025-02-03
Note
General mention
This release has some minor issues fixed like:
- Icon's not working on the Desktop clients
- Invites not always working
- DUO settings not able to configure
- Manager rights
- Mobile client sync issues fixed
1.33.2: no action items (1 version)
1.34.0 2025-05-26
Note
Notable changes
- Updated web-vault to v2025.5.0
- Implemented new registration flow with email verification
- Added support for some feature flags (mutual TLS, attachment export, AnonAddy/SimpleLogin self host)
1.34.1: no action items (1 version)
1.34.2 2025-07-27
Note
Notable changes
- Updated web vault to 2025.7.0
- Included experimental support for S3 file backend using OpenDAL. This currently requires compiling from source with the
s3feature flag, check https://github.com/dani-garcia/vaultwarden/pull/5626 for more details.
1.34.3 2025-07-30
Note
Notable changes
This release should fix an issue with MySQL/MariaDB database connections when using the Alpine images. The alpine build image has reverted to use MariaDB Connector/C v3.4.5 which resolved the issue.
1.35.0 2025-12-27
Note
Notable changes
- Implemented support for SSO with OpenID Connect, https://github.com/dani-garcia/vaultwarden/wiki/Enabling-SSO-support-using-OpenId-Connect
- Updated web vault to 2025.12.0
- Added support for future mobile apps with versions 2026.1.0+
- This is the first vaultwarden release using immutable releases and release attestation!
1.35.1 2025-12-30
Note
Notable changes
- Fixed issue with applications being logged out after upgrading due to changes to refresh token parsing
- Updated web vault to 2025.12.1
- Correctly publish
alpinetag, which was missing in 1.35.0
1.35.2 2026-01-09
Note
Notable changes
Fixed an issue with the web-vault which prevent creating an organization.
1.35.3 2026-02-10
Note
Security Fixes
This release contains security fixes for the following advisory. We strongly advice to update as soon as possible if you believe it could affect you.
- GHSA-h265-g7rm-h337 (Publication in process, waiting for CVE assignment) This vulnerability would allow an authenticated attacker that is part of an organization to access items from collections to which the attacker does not belong.
1.35.4 2026-02-23
Note
Security Fixes
This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.
- GHSA-w9f8-m526-h7fh. This vulnerability would allow an attacker to access a cipher from a different user (fully encrypted) if they already know its internal UUID.
- GHSA-h4hq-rgvh-wh27. This vulnerability allows an attacker with manager-level access within an organization to modify collections they can access, even if they do not have management permissions for them.
- GHSA-r32r-j5jq-3w4m. This vulnerability allows an attacker with manager-level access within an organization to modify collections they are not assigned.
These are private for now, pending CVE assignment.
1.35.5 2026-04-12
Note
Security Fixes
This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.
- GHSA-937x-3j8m-7w7p Unconfirmed Owner Can Purge Entire Organization Vault.
- GHSA-569v-845w-g82p Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Another Organization
- GHSA-6j4w-g4jh-xjfx Refresh tokens not invalidated on security stamp rotation
These are private for now, pending CVE assignment.
Note
Notes
- The admin templates have changed, please update them if you override these via templates.
- Two Factor Remember Tokens are now valid for max 30 days. Old tokens are invalid directly after upgrading.
1.35.6 2026-04-12
Note
Notes
The previous release contained an issue where Two Factor Remember Tokens and Recovery Tokens were not accepted at all. This has been fixed now in this release.
1.35.7 – 1.35.8: no action items (2 versions)
1.36.0 2026-05-03
Note
Security Fixes
This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.
- SSO Login CSRF GHSA-pfp2-jhgq-6hg5 GHSA-w6h6-8r66-hcv7
- User/Organization Enumeration GHSA-hxqh-ff5p-wfr3
- SSO existing-user binding GHSA-j4j8-gpvj-7fqr GHSA-6x5c-84vm-5j56
- SSRF via Icon Endpoint GHSA-72vh-x5jq-m82g
- Some crate's updated and other minor security enhancements
These are private for now, pending CVE assignment.
Note
Notes
- Archiving of items is available https://bitwarden.com/blog/keep-your-vault-tidy-with-item-archiving/ https://bitwarden.com/nl-nl/help/managing-items/#archive
- Web Vault updated to v2026.4.1
1.37.0 2026-07-24
Note
Note
This update is required for support with clients with version 2026.7.0+, please update before reporting any issues with them.
Note
Security Fixes
This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.
- SSRF via the icon endpoint [[GHSA-hw4g-2v3f-74x5]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-hw4g-2v3f-74x5) [[GHSA-vh5m-fc9v-m84g]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-vh5m-fc9v-m84g) (Medium, 5.8 / 6.3)
- Cross-Organization Cipher Access [[GHSA-xwf8-pjh7-h589]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-xwf8-pjh7-h589) (Medium, 5.9)
- Organization Policy Bypass on Directory Import [[GHSA-88qc-6ch9-mc3j]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-88qc-6ch9-mc3j) (Medium, 5.5)
- Send Access-Count Bypass [[GHSA-rxhg-2pw9-vf25]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-rxhg-2pw9-vf25) (Medium, 5.3)
- Unauthenticated WebSocket Flooding DDOS [[GHSA-96f7-78q5-j345]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-96f7-78q5-j345) (Medium, 5.3)
- Cross-Organization Secret Sharing [[GHSA-455c-vgg9-jxw8]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-455c-vgg9-jxw8) (Medium, 4.3)
- Organization Import Authorization [[GHSA-f3qw-qg77-hmm4]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-f3qw-qg77-hmm4)[[GHSA-jq2g-h4xr-4mcr]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-jq2g-h4xr-4mcr) (Medium, 4.3)
- Organization Data Enumeration via the Manager role [[GHSA-rqf8-2568-r7mc]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-rqf8-2568-r7mc) (Medium, 4.3)
These are private for now, pending CVE assignment and publishing at a later date.
1.37.1 2026-07-29
Note
Note
This patch release resolves the issues with invites. If you have applied any workaround to fix this locally, please revert those fixes to prevent possible other issues.
I'm sorry that it took some time to check and validate this fix.
Also, this release fixes an issue (#7475) with all the Alpine based images which are build using https://github.com/BlackDex/rust-musl/. An issue with the build image OpenSSL compilation is resolved and those are used to build the new alpine tagged containers.
1.37.2 2026-08-22
Note
Note
This update is required for support with clients with version 2026.8.0+, please update before reporting any issues with them.
Important
Also read #7615 for more details if you still have client issues!
1.37.3: no action items (1 version)
Release notes from github.com/dani-garcia/vaultwarden/releases, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Vaultwarden's release notes have no breaking-changes section. Sections titled Note, Notes, Notable changes, Important, General mention, Major changes, Other changes and Security Fixes, the Docker image notices of 1.16.0, 1.17.0 and 1.21.0, and paragraphs starting with ⚠️, are quoted instead, labelled “Note” or “Warning”.