Upgrade Path

Vaultwarden 1.35.0 → 1.37.3

13 versions, 10 with upstream notes, vendor marks no changes as breaking, 0 required stops

Version by version, oldest first

1.35.1 2025-12-30

Note

Notable changes

  • Fixed issue with applications being logged out after upgrading due to changes to refresh token parsing
  • Updated web vault to 2025.12.1
  • Correctly publish alpine tag, which was missing in 1.35.0

Full release notes for 1.35.1

1.35.2 2026-01-09

Note

Notable changes

Fixed an issue with the web-vault which prevent creating an organization.

Full release notes for 1.35.2

1.35.3 2026-02-10

Note

Security Fixes

This release contains security fixes for the following advisory. We strongly advice to update as soon as possible if you believe it could affect you.

  • GHSA-h265-g7rm-h337 (Publication in process, waiting for CVE assignment) This vulnerability would allow an authenticated attacker that is part of an organization to access items from collections to which the attacker does not belong.

Full release notes for 1.35.3

1.35.4 2026-02-23

Note

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

  • GHSA-w9f8-m526-h7fh. This vulnerability would allow an attacker to access a cipher from a different user (fully encrypted) if they already know its internal UUID.
  • GHSA-h4hq-rgvh-wh27. This vulnerability allows an attacker with manager-level access within an organization to modify collections they can access, even if they do not have management permissions for them.
  • GHSA-r32r-j5jq-3w4m. This vulnerability allows an attacker with manager-level access within an organization to modify collections they are not assigned.

These are private for now, pending CVE assignment.

Full release notes for 1.35.4

1.35.5 2026-04-12

Note

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment.

Note

Notes

  • The admin templates have changed, please update them if you override these via templates.
  • Two Factor Remember Tokens are now valid for max 30 days. Old tokens are invalid directly after upgrading.

Full release notes for 1.35.5

1.35.6 2026-04-12

Note

Notes

The previous release contained an issue where Two Factor Remember Tokens and Recovery Tokens were not accepted at all. This has been fixed now in this release.

Full release notes for 1.35.6

1.35.7 – 1.35.8: no action items (2 versions)

1.36.0 2026-05-03

Note

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment.

Full release notes for 1.36.0

1.37.0 2026-07-24

Note

Note

This update is required for support with clients with version 2026.7.0+, please update before reporting any issues with them.

Note

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment and publishing at a later date.

Full release notes for 1.37.0

1.37.1 2026-07-29

Note

Note

This patch release resolves the issues with invites. If you have applied any workaround to fix this locally, please revert those fixes to prevent possible other issues.

I'm sorry that it took some time to check and validate this fix.

Also, this release fixes an issue (#7475) with all the Alpine based images which are build using https://github.com/BlackDex/rust-musl/. An issue with the build image OpenSSL compilation is resolved and those are used to build the new alpine tagged containers.

Full release notes for 1.37.1

1.37.2 2026-08-22

Note

Note

This update is required for support with clients with version 2026.8.0+, please update before reporting any issues with them.

Important

Also read #7615 for more details if you still have client issues!

Full release notes for 1.37.2

1.37.3: no action items (1 version)

Release notes from github.com/dani-garcia/vaultwarden/releases, checked 17 hours ago. Only text the vendor marks as breaking, or puts in a warning/caution/important note, is shown; read the full notes for anything else. Vaultwarden's release notes have no breaking-changes section. Sections titled Note, Notes, Notable changes, Important, General mention, Major changes, Other changes and Security Fixes, the Docker image notices of 1.16.0, 1.17.0 and 1.21.0, and paragraphs starting with ⚠️, are quoted instead, labelled “Note” or “Warning”.