Vaultwarden 1.37.0

1.37.0
Added 5
  • Add OpenDAL S3 parameter support
  • Serve Apple app site association file
  • Add SSO_AUTHORIZE_BODY configuration option
  • Add pm-26340-linux-biometrics-v2 feature flag
  • Add trusted proxy support and unauthenticated rate limit
Changed 2
  • Reject unrecognised DATABASE_URL instead of silent SQLite fallback
  • Switch to Rust Edition 2024
Fixed 6
  • Fix SSO Cookie path
  • Fix email 2fa for bw cli
  • Fix enforce blocked
  • Fix hideEmail as non-null boolean in sync response
  • Fix Custom Role CSS for new dialog markup
  • Fix compilation with newer rust-musl version
Security 8
  • Fix SSRF via the icon endpoint
  • Fix Cross-Organization Cipher Access
  • Fix Organization Policy Bypass on Directory Import
  • Fix Send Access-Count Bypass
  • Fix Unauthenticated WebSocket Flooding DDOS
  • Fix Cross-Organization Secret Sharing
  • Fix Organization Import Authorization
  • Fix Organization Data Enumeration via the Manager role
Note

This update is required for support with clients with version 2026.7.0+, please update before reporting any issues with them.

Security Fixes

This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

These are private for now, pending CVE assignment and publishing at a later date.

What's Changed
New Contributors

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.36.0...1.37.0

View original

Upgraded? How did it go?

Discussion