Software-update: Vaultwarden 1.37.4

Vaultwarden logo Vaultwarden is een onofficiële in Rust ontwikkelde implementatie van de Bitwarden-wachtwoordmanager. Het gaat alleen om de serverkant van de wachtwoordmanager; voor de clients kan de officiële software van Bitwarden worden gebruikt. Vaultwarden is lichter in gebruik en heeft ook functionaliteit waarvoor bij Bitwarden moet worden betaald, waaronder het kunnen opslaan van bijlagen en beheer van wachtwoorden op organisatieniveau. Versie 1.37.4 van Vaultwarden is uitgekomen en hier zijn de volgende verbeteringen in aangebracht:

Security Fixes

This release contains security fixes for the following advisories. We strongly advise updating as soon as possible.

These are private for now, pending CVE assignment and publishing at a later date.

Note: If an organization has Admins you don't fully trust, consider rotating its API key after updating (Admin Console → Settings → Rotate API key). Before this release, Admins could also view the key. Upgrade notes
  • Reverse proxies: with IP_HEADER=X-Forwarded-For, the client IP is now the rightmost address that isn't in IP_HEADER_TRUSTED_PROXIES (it used to be the leftmost). If you have several proxies in a row, for example a CDN in front of nginx, add all of them to IP_HEADER_TRUSTED_PROXIES. Otherwise the address of the proxy in front is used for rate limiting and logs.
  • Sends: bw send receive on CLI 2026.4.2 and older no longer works, the same as against Bitwarden's own servers since v2026.8.0. Creating and managing Sends works on all clients.
  • Feature flags: these flags were removed because no client reads them anymore: ssh-agent, ssh-key-vault-item, mutual-tls, anon-addy-self-host-alias, simple-login-self-host-alias, pm-25373-windows-biometrics-v2, pm-26340-linux-biometrics-v2, desktop-ui-migration-milestone-1 to -4, cxp-import-mobile and cxp-export-mobile. If EXPERIMENTAL_CLIENT_FEATURE_FLAGS still lists one of them, startup logs a warning and saving settings in the admin panel fails until it's removed.
  • Duo: DUO_USE_IFRAME (the deprecated Traditional Prompt) is removed and ignored if set.
  • Custom templates: there's a new email template, email/recover_twofactor, sent after a login with a two-step recovery code.
  • The legacy POST /identity/accounts/register and POST /api/accounts/prelogin endpoints are removed. No current client uses them.
What's Changed
  • [Web 2026.9.0] Support the vault banner policy in #7748
  • Add support for basic auth response client feature flag in #7745
  • [web-v2026.8.1] store the user key ID in #7693
  • Add organizationsNew and policiesNew to sync response in #7666
  • Add pm-32009-new-item-types feature flag in #7478
  • Update Crates, GHA and JS in #7751
  • Add pm-34171-card-scanner feature flag in #7477
  • set user_created bool for each separate invitation in #7753
  • Fix revoked org members retaining access to org ciphers in #7554
  • Ensure all user checked routes are confirmed in #7763
  • Fix cortex-a53 build issues when using xx-cargo in #7774
  • Add undetermined-cipher-scenario-logic feature flag (closes #7801) in #7802
  • Add Windows native credential sync to supported feature flags in #7798
  • Hide the whole change-email section when EMAIL_CHANGE_ALLOWED is false in #7759
  • Fix Clippy warnings across all targets in #7782
  • Admin reset: 2fa email fallback need a verified email in #7770
  • Sends cleanup: remove legacy endpoints and align with upstream in #7806
  • Remove legacy API endpoints and compatibility code in #7809
  • Align API with upstream and remove unwraps in #7810
  • Update crates, Rust and other dependencies in #7814

Vaultwarden

Versienummer 1.37.4
Releasestatus Final
Besturingssystemen Linux
Website Vaultwarden
Download https://github.com/dani-garcia/vaultwarden/releases/tag/1.37.4
Licentietype GPL

Door Bart van Klaveren

Downloads en Best Buy Guide

06-10-2026 • 12:00

1

Submitter: belkin

Bron: Vaultwarden

Reacties (1)

Sorteer op:

Weergave:


Om te kunnen reageren moet je ingelogd zijn