VYPR

Vaultwarden

by Dani Garcia

cargo: vaultwarden

Source repositories

CVEs (25)

  • CVE-2026-33420MedMay 5, 2026
    risk 0.27cvss 5.3epss 0.00

    Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the has_full_access() authorization check that exists on the sibling…

  • CVE-2026-47164HigJul 15, 2026
    risk 0.00cvss 7.7epss 0.00

    Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true linked an IdP identity to an existing local account, allowing an…

  • CVE-2026-47160MedJul 15, 2026
    risk 0.00cvss 5.8epss 0.00

    Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that missed decimal, hexadecimal, and octal IP representations,…

  • CVE-2026-47159MedJul 15, 2026
    risk 0.00cvss —epss 0.01

    Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation…

  • CVE-2026-47158HigJul 15, 2026
    risk 0.00cvss 8.3epss 0.00

    Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left…

Page 2 of 2