Skip to content

Client crash "invalid type... expected a string" reproducible even on freshly duplicated ciphers (related to #7334) #7469

Description

@Marefi09

Prerequisites

Vaultwarden Support String

Your environment (Generated via diagnostics page)

  • Vaultwarden version: v1.36.0
  • Web-vault version: v2026.4.1
  • OS/Arch: linux/x86_64
  • Running within a container: true (Base: Debian)
  • Database type: SQLite
  • Database version: 3.51.3
  • Uses config.json: true
  • Uses a reverse proxy: true
  • IP Header check: true (X-Forwarded-For)
  • Internet access: true
  • Internet access via a proxy: false
  • DNS Check: true
  • TZ environment: Europe/Berlin
  • Browser/Server Time Check: true
  • Server/NTP Time Check: true
  • Domain Configuration Check: true
  • HTTPS Check: true
  • Websocket Check: true
  • HTTP Response Checks: true

Config & Details (Generated via diagnostics page)

Show Config & Details

Environment settings which are overridden: INCOMPLETE_2FA_TIME_LIMIT, SIGNUPS_ALLOWED, ADMIN_TOKEN

Config:

{
  "_duo_akey": null,
  "_enable_duo": true,
  "_enable_email_2fa": false,
  "_enable_smtp": true,
  "_enable_yubico": true,
  "_icon_service_csp": "",
  "_icon_service_url": "",
  "_ip_header_enabled": true,
  "_max_note_size": 10000,
  "_smtp_img_src": "***:",
  "admin_ratelimit_max_burst": 3,
  "admin_ratelimit_seconds": 300,
  "admin_session_lifetime": 10,
  "admin_token": "***",
  "allowed_connect_src": "",
  "allowed_iframe_ancestors": "",
  "attachments_folder": "data/attachments",
  "auth_request_purge_schedule": "30 * * * * *",
  "authenticator_disable_time_drift": false,
  "data_folder": "data",
  "database_conn_init": "",
  "database_idle_timeout": 600,
  "database_max_conns": 10,
  "database_min_conns": 2,
  "database_timeout": 30,
  "database_url": "***************",
  "db_connection_retries": 15,
  "disable_2fa_remember": false,
  "disable_admin_token": false,
  "disable_icon_download": false,
  "dns_prefer_ipv6": false,
  "domain": "*****://***************************",
  "domain_origin": "*****://***************************",
  "domain_path": "",
  "domain_set": true,
  "duo_context_purge_schedule": "30 * * * * *",
  "duo_host": null,
  "duo_ikey": null,
  "duo_skey": null,
  "duo_use_iframe": false,
  "email_2fa_auto_fallback": false,
  "email_2fa_enforce_on_verified_invite": false,
  "email_attempts_limit": 3,
  "email_change_allowed": true,
  "email_expiration_time": 600,
  "email_token_size": 6,
  "emergency_access_allowed": true,
  "emergency_notification_reminder_schedule": "0 3 * * * *",
  "emergency_request_timeout_schedule": "0 7 * * * *",
  "enable_db_wal": true,
  "enable_websocket": true,
  "enforce_single_org_with_reset_pw_policy": false,
  "event_cleanup_schedule": "0 10 0 * * *",
  "events_days_retain": null,
  "experimental_client_feature_flags": "",
  "extended_logging": true,
  "helo_name": null,
  "hibp_api_key": null,
  "http_request_block_non_global_ips": true,
  "http_request_block_regex": null,
  "icon_blacklist_non_global_ips": true,
  "icon_blacklist_regex": null,
  "icon_cache_folder": "data/icon_cache",
  "icon_cache_negttl": 259200,
  "icon_cache_ttl": 2592000,
  "icon_download_timeout": 10,
  "icon_redirect_code": 302,
  "icon_service": "internal",
  "incomplete_2fa_schedule": "30 * * * * *",
  "incomplete_2fa_time_limit": 2,
  "increase_note_size_limit": false,
  "invitation_expiration_hours": 120,
  "invitation_org_name": "REDACTED",
  "invitations_allowed": true,
  "ip_header": "X-Forwarded-For",
  "job_poll_interval_ms": 30000,
  "log_file": "/data/log/my.log",
  "log_level": "info",
  "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f",
  "login_ratelimit_max_burst": 10,
  "login_ratelimit_seconds": 60,
  "org_attachment_limit": null,
  "org_creation_users": "",
  "org_events_enabled": false,
  "org_groups_enabled": false,
  "password_hints_allowed": true,
  "password_iterations": 600000,
  "purge_incomplete_sso_auth": "0 20 0 * * *",
  "push_enabled": false,
  "push_identity_uri": "https://identity.bitwarden.com",
  "push_installation_id": "***",
  "push_installation_key": "***",
  "push_relay_uri": "https://push.bitwarden.com",
  "reload_templates": false,
  "require_device_email": false,
  "rsa_key_filename": "data/rsa_key",
  "send_purge_schedule": "0 5 * * * *",
  "sendmail_command": null,
  "sends_allowed": true,
  "sends_folder": "data/sends",
  "show_password_hint": false,
  "signups_allowed": false,
  "signups_domains_whitelist": "",
  "signups_verify": true,
  "signups_verify_resend_limit": 3,
  "signups_verify_resend_time": 3600,
  "smtp_accept_invalid_certs": false,
  "smtp_accept_invalid_hostnames": false,
  "smtp_auth_mechanism": "Plain",
  "smtp_debug": false,
  "smtp_embed_images": true,
  "smtp_explicit_tls": null,
  "smtp_from": "**********************",
  "smtp_from_name": "**********************",
  "smtp_host": "**********************",
  "smtp_password": "***",
  "smtp_port": 465,
  "smtp_security": "force_tls",
  "smtp_ssl": null,
  "smtp_timeout": 15,
  "smtp_username": "**********************",
  "sso_allow_unknown_email_verification": false,
  "sso_audience_trusted": null,
  "sso_auth_only_not_session": false,
  "sso_authority": "",
  "sso_authorize_extra_params": "",
  "sso_callback_path": "*****://********************************************************",
  "sso_client_cache_expiration": 0,
  "sso_client_id": "",
  "sso_client_secret": "***",
  "sso_debug_tokens": false,
  "sso_enabled": false,
  "sso_master_password_policy": null,
  "sso_only": false,
  "sso_pkce": true,
  "sso_scopes": "email profile",
  "sso_signups_match_email": true,
  "templates_folder": "data/templates",
  "tmp_folder": "data/tmp",
  "trash_auto_delete_days": 90,
  "trash_purge_schedule": "0 5 0 * * *",
  "use_sendmail": false,
  "use_syslog": false,
  "user_attachment_limit": null,
  "user_send_limit": null,
  "web_vault_enabled": true,
  "web_vault_folder": "web-vault/",
  "yubico_client_id": null,
  "yubico_secret_key": null,
  "yubico_server": null
}

Vaultwarden Build Version

1.36.0

Deployment method

Official Container Image

Custom deployment method

Description

I hit the same client-side crash described in #7334 (invalid type: JsValue(Object({...})), expected a string) on Vaultwarden 1.36.0 / Web-Vault 2026.4.1, with Bitwarden Browser Extension and Desktop app both v2026.7.x. The Web-Vault itself loads and displays all items correctly — the crash only happens in the browser extension and desktop app (both use the WASM SDK), which strongly suggests the issue is in client-side deserialization, not (only) legacy server-side data.

Key new finding

I identified 3 legacy personal login ciphers (created early-to-mid 2025) that each individually crash the WASM client on sync. Confirmed via server logs (panic at 'Error loading ciphers... Wrong type' style errors were already fixed by #7068, so the server now returns the ciphers instead of crashing — but the client then fails to deserialize them).

Important: I tried the commonly suggested workaround of duplicating the broken item in the Web-Vault (create a copy, delete original) to "normalize" the format. This did not fix it — the newly created duplicate (created today, at 2026-07-24) still triggers the exact same crash in the client, just with a different name ciphertext (since re-encryption produces a different ciphertext each time, but the structural issue clearly persists into freshly created items too).

This means the bug isn't purely a legacy-data-migration issue — something about how these specific cipher structures are generated (or the client's assumptions about wrapped-key strings) reproduces itself even on brand-new items copied from the broken ones.

Steps to reproduce

  1. Have a Vaultwarden instance with a legacy cipher (from ~Feb/March 2025 in my case) that triggers the client crash on sync.
  2. In the Web-Vault, open that item, "Clone" it, save the clone, delete the original.
  3. Sync in the browser extension or desktop app.
  4. Same crash occurs, referencing the new item (different name ciphertext, same error shape).

Environment

  • Vaultwarden: 1.36.0 (Docker vaultwarden/server:latest)
  • Web-Vault: 2026.4.1
  • Browser extension: 2026.7.x (Firefox + Chrome, both affected)
  • Desktop app: 2026.7.x (also affected — vault shows empty)
  • OS: Synology DSM (Docker), accessed via Tailscale

What I've tried

Question / request

Given that cloning a broken item via the Web-Vault reproduces the same client crash on the new item, could this point to something in how Vaultwarden serializes/wraps certain field types (e.g. EncString MAC formatting, as discussed in #7334) that persists across re-encryption? Happy to provide DB row structure (with values redacted) if useful for debugging.

Related: #7334, #7068

Reverse Proxy

Reverse Proxy: None (accessed directly via Tailscale Serve/HTTPS, no nginx/Caddy/Traefik in front)

Host/Server Operating System

NAS/SAN

Operating System Version

DSM 7.3.2-86009 Update 4

Clients

Browser Extension

Client Version

Firefox 2026.7.0

Steps To Reproduce

  1. Go to '...'
  2. Click on '....'
  3. Scroll down to '....'
  4. Click on '...'
  5. Etc '...'

Expected Result

Hier ein passender Text für dieses Feld:

The browser extension and desktop app should successfully sync and display all vault items after login, the same way the Web-Vault does.

Actual Result

The browser extension (Firefox and Chrome) and desktop app fail to load the vault - the item list stays stuck in a loading/skeleton state indefinitely. The extension console shows: "Unhandled error in angular Error: Error: invalid type: JsValue(Object({...})), expected a string" originating from the WASM SDK when processing certain legacy cipher entries. The Web-Vault itself loads and displays all items correctly, so this only affects clients using the WASM SDK (browser extension, desktop app).

Logs


Screenshots or Videos

No response

Additional Context

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions