Skip to content

Releases: dani-garcia/vaultwarden

1.37.2

Choose a tag to compare

@BlackDex BlackDex released this 22 Aug 12:29
Immutable release. Only release title and notes can be modified.
1.37.2
46d7110

Note

This update is required for support with clients with version 2026.8.0+, please update before reporting any issues with them.

Important

Also read #7615 for more details if you still have client issues!

What's Changed

New Contributors

Full Changelog: 1.37.1...1.37.2

1.37.1

Choose a tag to compare

@BlackDex BlackDex released this 29 Jul 13:40
Immutable release. Only release title and notes can be modified.
1.37.1
2629bcb

Note

This patch release resolves the issues with invites.
If you have applied any workaround to fix this locally, please revert those fixes to prevent possible other issues.

I'm sorry that it took some time to check and validate this fix.

Also, this release fixes an issue (#7475) with all the Alpine based images which are build using https://github.com/BlackDex/rust-musl/.
An issue with the build image OpenSSL compilation is resolved and those are used to build the new alpine tagged containers.

What's Changed

  • Always send initOrganization and orgUserHasExistingUser in invite URL by @vikfox in #7482
  • Indirectly resolved #7475 by using newer rust-musl build images which had a compilation issue with OpenSSL.

New Contributors

Full Changelog: 1.37.0...1.37.1

1.37.0

Choose a tag to compare

@dani-garcia dani-garcia released this 24 Jul 17:04
Immutable release. Only release title and notes can be modified.
1.37.0
46ae59e

Note

This update is required for support with clients with version 2026.7.0+, please update before reporting any issues with them.

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment and publishing at a later date.

What's Changed

New Contributors

Full Changelog: 1.36.0...1.37.0

1.36.0

Choose a tag to compare

@BlackDex BlackDex released this 03 May 12:54
Immutable release. Only release title and notes can be modified.
1.36.0
f21a3ad

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment.

Notes

What's Changed

New Contributors

Full Changelog: 1.35.8...1.36.0

You can discuss this release here #7177

1.35.8

Choose a tag to compare

@BlackDex BlackDex released this 25 Apr 18:08
Immutable release. Only release title and notes can be modified.
1.35.8
7cf0c5d

What's Changed

Full Changelog: 1.35.7...1.35.8

1.35.7

Choose a tag to compare

@BlackDex BlackDex released this 13 Apr 21:51
Immutable release. Only release title and notes can be modified.
1.35.7
e7e4b9a

What's Changed

Full Changelog: 1.35.6...1.35.7

1.35.6

Choose a tag to compare

@BlackDex BlackDex released this 12 Apr 19:28
Immutable release. Only release title and notes can be modified.
1.35.6
bb54998

Notes

The previous release contained an issue where Two Factor Remember Tokens and Recovery Tokens were not accepted at all.
This has been fixed now in this release.

What's Changed

Full Changelog: 1.35.5...1.35.6

1.35.5

Choose a tag to compare

@BlackDex BlackDex released this 12 Apr 15:59
Immutable release. Only release title and notes can be modified.
1.35.5
39954af

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment.

Notes

  • The admin templates have changed, please update them if you override these via templates.
  • Two Factor Remember Tokens are now valid for max 30 days. Old tokens are invalid directly after upgrading.

What's Changed

New Contributors

Full Changelog: 1.35.4...1.35.5

1.35.4

Choose a tag to compare

@dani-garcia dani-garcia released this 23 Feb 21:43
Immutable release. Only release title and notes can be modified.
1.35.4
c555f7d

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

  • GHSA-w9f8-m526-h7fh. This vulnerability would allow an attacker to access a cipher from a different user (fully encrypted) if they already know its internal UUID.
  • GHSA-h4hq-rgvh-wh27. This vulnerability allows an attacker with manager-level access within an organization to modify collections they can access, even if they do not have management permissions for them.
  • GHSA-r32r-j5jq-3w4m. This vulnerability allows an attacker with manager-level access within an organization to modify collections they are not assigned.

These are private for now, pending CVE assignment.

What's Changed

New Contributors

Full Changelog: 1.35.3...1.35.4

1.35.3

Choose a tag to compare

@dani-garcia dani-garcia released this 10 Feb 20:37
Immutable release. Only release title and notes can be modified.
1.35.3
36f0620

Security Fixes

This release contains security fixes for the following advisory. We strongly advice to update as soon as possible if you believe it could affect you.

  • GHSA-h265-g7rm-h337 (Publication in process, waiting for CVE assignment)
    This vulnerability would allow an authenticated attacker that is part of an organization to access items from collections to which the attacker does not belong.

What's Changed

Full Changelog: 1.35.2...1.35.3