Vaultwarden 1.35.0 → 1.36.0
9 versions, 7 with upstream notes, vendor marks no changes as breaking, 0 required stops
Version by version, oldest first
1.35.1 2025-12-30
Note
Notable changes
- Fixed issue with applications being logged out after upgrading due to changes to refresh token parsing
- Updated web vault to 2025.12.1
- Correctly publish
alpinetag, which was missing in 1.35.0
1.35.2 2026-01-09
Note
Notable changes
Fixed an issue with the web-vault which prevent creating an organization.
1.35.3 2026-02-10
Note
Security Fixes
This release contains security fixes for the following advisory. We strongly advice to update as soon as possible if you believe it could affect you.
- GHSA-h265-g7rm-h337 (Publication in process, waiting for CVE assignment) This vulnerability would allow an authenticated attacker that is part of an organization to access items from collections to which the attacker does not belong.
1.35.4 2026-02-23
Note
Security Fixes
This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.
- GHSA-w9f8-m526-h7fh. This vulnerability would allow an attacker to access a cipher from a different user (fully encrypted) if they already know its internal UUID.
- GHSA-h4hq-rgvh-wh27. This vulnerability allows an attacker with manager-level access within an organization to modify collections they can access, even if they do not have management permissions for them.
- GHSA-r32r-j5jq-3w4m. This vulnerability allows an attacker with manager-level access within an organization to modify collections they are not assigned.
These are private for now, pending CVE assignment.
1.35.5 2026-04-12
Note
Security Fixes
This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.
- GHSA-937x-3j8m-7w7p Unconfirmed Owner Can Purge Entire Organization Vault.
- GHSA-569v-845w-g82p Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Another Organization
- GHSA-6j4w-g4jh-xjfx Refresh tokens not invalidated on security stamp rotation
These are private for now, pending CVE assignment.
Note
Notes
- The admin templates have changed, please update them if you override these via templates.
- Two Factor Remember Tokens are now valid for max 30 days. Old tokens are invalid directly after upgrading.
1.35.6 2026-04-12
Note
Notes
The previous release contained an issue where Two Factor Remember Tokens and Recovery Tokens were not accepted at all. This has been fixed now in this release.
1.35.7 – 1.35.8: no action items (2 versions)
1.36.0 2026-05-03
Note
Security Fixes
This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.
- SSO Login CSRF GHSA-pfp2-jhgq-6hg5 GHSA-w6h6-8r66-hcv7
- User/Organization Enumeration GHSA-hxqh-ff5p-wfr3
- SSO existing-user binding GHSA-j4j8-gpvj-7fqr GHSA-6x5c-84vm-5j56
- SSRF via Icon Endpoint GHSA-72vh-x5jq-m82g
- Some crate's updated and other minor security enhancements
These are private for now, pending CVE assignment.
Note
Notes
- Archiving of items is available https://bitwarden.com/blog/keep-your-vault-tidy-with-item-archiving/ https://bitwarden.com/nl-nl/help/managing-items/#archive
- Web Vault updated to v2026.4.1
Release notes from github.com/dani-garcia/vaultwarden/releases, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Vaultwarden's release notes have no breaking-changes section. Sections titled Note, Notes, Notable changes, Important, General mention, Major changes, Other changes and Security Fixes, the Docker image notices of 1.16.0, 1.17.0 and 1.21.0, and paragraphs starting with ⚠️, are quoted instead, labelled “Note” or “Warning”.