VW

Vaultwarden 1.37.3

Get release alerts
1.37.2β†’1.37.3SecurityFeatureBug fix
πŸ“… September 13, 2026πŸ—‚ SecurityπŸ“¦ Vaultwarden β†—πŸ“œ Full changelog β†—
✦ Editor's summary

Vaultwarden 1.37.3 is a security and maintenance release that strengthens authentication protections and improves compatibility with newer Bitwarden clients. Security-related changes include revoking remembered 2FA tokens when credentials or two-factor settings change and adding rate limiting to pre-login and authentication-request endpoints. The release also adds new SSO and administrative 2FA capabilities and fixes password changes, organization imports, iOS registration, MariaDB migrations, and archive-date handling.

⚠ Security impact
  • Remembered two-factor authentication tokens are now revoked when user credentials or 2FA settings are changed.
  • Rate limiting has been added to pre-login and authentication request endpoints to reduce authentication abuse.
  • Failed two-factor email-login credential attempts now include the source IP address and username in logs, improving security monitoring and investigation capabilities.

What's new

Vaultwarden 1.37.3 is a security and maintenance release introducing authentication hardening, SSO improvements, administrative capabilities, and multiple compatibility and reliability fixes.

What's new
  • Added rate limiting to pre-login and authentication request endpoints.
  • Remembered 2FA tokens are now revoked when credentials or two-factor authentication settings are changed.
  • Added support for administrators to reset two-factor authentication.
  • Added the SSO_SIGNUPS_ALLOWED configuration option for controlling account creation through SSO.
  • Improved security logging by recording the IP address and username for failed two-factor email-login credential attempts.
  • Fixed password changes when using newer versions of the Bitwarden web vault.
  • Fixed organization imports when the groups field is missing.
  • Fixed iOS registration token responses.
  • Fixed a database migration issue affecting MariaDB 12.2.2.
  • Fixed archiveDate updates and includes additional internal maintenance improvements.
Recommendation

Organizations running Vaultwarden 1.37.2 or earlier should prioritize upgrading to version 1.37.3 after standard validation. The authentication hardening changes, particularly 2FA token revocation and authentication endpoint rate limiting, make this update recommended for Internet-accessible and enterprise Vaultwarden deployments.

More from Vaultwarden
Vaultwarden 1.37.2Aug 22, 2026
Vaultwarden 1.37.1Bug fixJul 29, 2026
Latest in Security
authentik: authentik 2026.8.2SecurityBug fixSep 9, 2026
JumpServer: JumpServer v4.10.19 LTSSecurityBug fixPerformanceAug 20, 2026

πŸ’¬ Comments (0)

Have you installed this Vaultwarden update?

Share any installation issues, compatibility changes, or fixes you noticed.