Vaultwarden is een onofficiële in Rust ontwikkelde implementatie van de Bitwarden wachtwoordmanager. Het gaat alleen om de serverkant van de wachtwoordmanager; voor de clients kan de officiële software van Bitwarden worden gebruikt. Vaultwarden is lichter in gebruik en heeft ook functionaliteit waarvoor bij Bitwarden moet worden betaald, waaronder het kunnen opslaan van bijlagen en beheer van wachtwoorden op organisatieniveau. Versie 1.37.0 van Vaultwarden is uitgekomen en hierin zijn de volgende veranderingen en verbeteringen aangebracht:
NoteThis update is required for support with clients with version 2026.7.0+, please update before reporting any issues with them.
Security FixesThis release contains security fixes for the following advisories. We strongly advice to update as soon as possible.
- SSRF via the icon endpoint [GHSA-hw4g-2v3f-74x5] [GHSA-vh5m-fc9v-m84g] (Medium, 5.8 / 6.3)
- Cross-Organization Cipher Access [GHSA-xwf8-pjh7-h589] (Medium, 5.9)
- Organization Policy Bypass on Directory Import [GHSA-88qc-6ch9-mc3j] (Medium, 5.5)
- Send Access-Count Bypass [GHSA-rxhg-2pw9-vf25] (Medium, 5.3)
- Unauthenticated WebSocket Flooding DDOS [GHSA-96f7-78q5-j345] (Medium, 5.3)
- Cross-Organization Secret Sharing [GHSA-455c-vgg9-jxw8] (Medium, 4.3)
- Organization Import Authorization [GHSA-f3qw-qg77-hmm4][GHSA-jq2g-h4xr-4mcr] (Medium, 4.3)
- Organization Data Enumeration via the Manager role [GHSA-rqf8-2568-r7mc] (Medium, 4.3)
These are private for now, pending CVE assignment and publishing at a later date.
What's Changed
- OpenDAL S3 parameter support in #6127
- Fix SSO Cookie path in #7187
- fix email 2fa for bw cli in #7225
- sso_auth improvements in #7197
- Reject unrecognised DATABASE_URL instead of silent SQLite fallback in #7061
- Switch to
xx-cargoin #6640- Updates and fixes in #7235
- Switch to Edition 2024, more clippy lints, and less macro calls in #7200
- Serve Apple app site association file in #7191
- Update Rust, Crates and GHA in #7307
- Fix enforce blocked in #7246
- Admin password recovery endpoint change in #7270
- fix(sends): emit hideEmail as non-null boolean in sync response in #7283
- Org membership delete remove Invitation in #7284
- [v2026.5.0] Registration request update in #7295
- [v2026.5.0] PutPolicy now using vnext format in #7296
- 2026.6.0 send support in #7346
- Add SSO_AUTHORIZE_BODY in #7357
- Add
pm-26340-linux-biometrics-v2feature flag in #7358- improve CI in #6991
- Misc updates and fixes in #7406
- Remove old compatibility code in #7434
- Fix compilation with newer
rust-muslversion in #7453- Fix Custom Role CSS for new dialog markup in #7442
- Remove unused fields in #7458
- Update API response, crates and GHA in #7470
- Trusted proxy support, unauthenticated rate limit & other fixes in #7472

/u/367546/crop6825fbafe3854_cropped.png?f=community)
/u/143137/crop5d1c4f96268ca_cropped.png?f=community)
:strip_icc():strip_exif()/u/439551/marvin-da-martian1.jpeg?f=community)
:strip_icc():strip_exif()/u/51415/crop683ca4502b799_cropped.jpg?f=community)