Vaultwarden 1.36.0

1.36.0
Added 3
  • Add support for archiving items
  • Add new /identity/accounts/prelogin/password endpoint
  • Add DuckDuckGo browser device type
Changed 4
  • Update web vault to v2026.4.1
  • SSO fallback to UserInfo preferred_username
  • Allow SQLite to be linked against dynamically
  • Update hickory dependency
Fixed 5
  • Fix hardcoded SSO identifier
  • Fix host and IP resolving
  • Fix favicon fetching to check all icon links instead of just the first one
  • Replace organization_uuid unwrap with proper error handling
  • Return error instead of panic on unknown cipher atype in to_json
Security 5
  • Fix SSO login CSRF vulnerability
  • Fix user and organization enumeration vulnerability
  • Fix SSO existing-user binding vulnerability
  • Fix SSRF vulnerability via icon endpoint
  • Update crates and apply minor security enhancements
Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment.

Notes
What's Changed
New Contributors

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.35.8...1.36.0

You can discuss this release here https://github.com/dani-garcia/vaultwarden/discussions/7177

View original

Upgraded? How did it go?

Discussion