--- snapshot-1789251397+++ snapshot-1789338460@@ -2,7 +2,11 @@
Release notes from vaultwarden
-2026-08-22T12:09:11Z tag:github.com,2008:Repository/121898717/1.37.2 2026-08-24T09:42:38Z
+2026-09-13T14:43:22Z tag:github.com,2008:Repository/121898717/1.37.3 2026-09-13T15:03:37Z
+
+1.37.3
+
+
What's Changed
New Contributors
Full Changelog: 1.37.2...1.37.3
BlackDex tag:github.com,2008:Repository/121898717/1.37.2 2026-08-24T09:42:38Z
1.37.2
@@ -38,8 +42,4 @@
1.35.4
-Security Fixes
This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.
- GHSA-w9f8-m526-h7fh. This vulnerability would allow an attacker to access a cipher from a different user (fully encrypted) if they already know its internal UUID.
- GHSA-h4hq-rgvh-wh27. This vulnerability allows an attacker with manager-level access within an organization to modify collections they can access, even if they do not have management permissions for them.
- GHSA-r32r-j5jq-3w4m. This vulnerability allows an attacker with manager-level access within an organization to modify collections they are not assigned.
These are private for now, pending CVE assignment.
What's Changed
New Contributors
Full Changelog: 1.35.3...1.35.4
dani-garcia tag:github.com,2008:Repository/121898717/1.35.3 2026-02-10T20:41:27Z
-
-1.35.3
-
-Security Fixes
This release contains security fixes for the following advisory. We strongly advice to update as soon as possible if you believe it could affect you.
- GHSA-h265-g7rm-h337 (Publication in process, waiting for CVE assignment)
This vulnerability would allow an authenticated attacker that is part of an organization to access items from collections to which the attacker does not belong.
What's Changed
Full Changelog: 1.35.2...1.35.3
dani-garcia+Security Fixes
This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.
- GHSA-w9f8-m526-h7fh. This vulnerability would allow an attacker to access a cipher from a different user (fully encrypted) if they already know its internal UUID.
- GHSA-h4hq-rgvh-wh27. This vulnerability allows an attacker with manager-level access within an organization to modify collections they can access, even if they do not have management permissions for them.
- GHSA-r32r-j5jq-3w4m. This vulnerability allows an attacker with manager-level access within an organization to modify collections they are not assigned.
These are private for now, pending CVE assignment.
What's Changed
New Contributors
Full Changelog: 1.35.3...1.35.4
dani-garcia