Upgrade Path

Vaultwarden 1.32.0 → 1.33.0

8 versions, 7 with upstream notes, vendor marks no changes as breaking, 0 required stops

Version by version, oldest first

1.32.1 2024-10-03

Note

Notable changes

  • Fixed syncing/login with native mobile clients
  • Added CLI option to backup SQLite database
  • Email Template changes regarding invites, 2FA Incomplete logins, and new logins

Full release notes for 1.32.1

1.32.2 2024-10-13

Note

Notable changes

  • Fixed collection management for managers

Full release notes for 1.32.2

1.32.3 2024-10-27

Note

Notable changes

  • Email template for org invites was updated again. The URL got HTML Encoded which resulted in a sometimes non-working URL (#5100)
  • Fixed SMTP issues with some providers which send erroneous response to QUIT messages (Like QQ) (Thanks to @paolobarbolini)
  • Fixed a long standing collection management issue where collections were not able to be managed via the Password Manager overview

Full release notes for 1.32.3

1.32.4 2024-11-10

Note

Security Fixes

This release has fixed some CVE Reports reported by a third party security auditor and we recommend everybody to update to the latest version as soon as possible. The contents of these reports will be disclosed publicly in the future.

Note

Notable changes

  • Added more compatibility fixes for the native mobile apps, datetimes are now formatted without too many decimals.
  • Email Template changes to the send emergency access invite. If you have modified this template, make sure to update it with the new changes.

Full release notes for 1.32.4

1.32.5 2024-11-18

Note

Security Fixes

This release further fixed some CVE Reports reported by a third party security auditor and we recommend everybody to update to the latest version as soon as possible. The contents of these reports will be disclosed publicly in the future.

Note

Notable changes

  • Added SSH-Key storage support. Currently only usable with Bitwarden Desktop v2024.12.0 and newer. You need to enable this feature by adding ssh-key-vault-item,ssh-agent to the EXPERIMENTAL_CLIENT_FEATURE_FLAGS config option. See .env.template

Full release notes for 1.32.5

1.32.6: no action items (1 version)

1.32.7 2024-12-20

Note

Security Fixes

This release contains a security fix for the following CVE https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-g65h-982x-4m5m.

This vulnerability affects any installations that have the ORG_GROUPS_ENABLED setting enabled, and we urge anyone doing so to update as soon as possible.

Full release notes for 1.32.7

1.33.0 2025-01-25

Note

Security Fixes

This release contains security fixes for the following advisories. And we strongly advice to update as soon as possible.

  • GHSA-f7r5-w49x-gxm3 This vulnerability is only possible if you do not have an ADMIN_TOKEN configured and open links or pages you should not trust anyway. Ensure you have an ADMIN_TOKEN configured to keep your admin environment save.
  • GHSA-h6cc-rc6q-23j4 This vulnerability is only possible if someone was able to gain access to your Vaultwarden Admin Backend. The attacker could then change some settings to use sendmail as mail agent but adjust the settings in such a way that it would use a shell command. It then also needed to craft a special favicon image which would have the commands embedded to run during for example sending a test email.
  • GHSA-j4h8-vch3-f797 This vulnerability affects all users who have multiple Organizations and users which are able to create a new organization or have admin or owner rights on at least one organization. The attacker does need to know the Organization UUID of the Organization it want's to attack or compromise though.

Note

Notable changes

  • Updated web-vault to v2025.1.1
  • Added partial manage role support for collections
  • Manager role is converted to a Custom role with either Manage All Collections or per collection. Admins and Owners probably want to check and verify if the rights are still correct.
  • The OCI containers and binaries are signed via GitHub Attestations This allows you to verify an OCI image or even the vaultwarden binary located within the OCI image.

These vulnerabilities affects

Full release notes for 1.33.0

Release notes from github.com/dani-garcia/vaultwarden/releases, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Vaultwarden's release notes have no breaking-changes section. Sections titled Note, Notes, Notable changes, Important, General mention, Major changes, Other changes and Security Fixes, the Docker image notices of 1.16.0, 1.17.0 and 1.21.0, and paragraphs starting with ⚠️, are quoted instead, labelled “Note” or “Warning”.