Vaultwarden 1.37.3
Vaultwarden 1.37.3 is a security and maintenance release that strengthens authentication protections and improves compatibility with newer Bitwarden clients. Security-related changes include revoking remembered 2FA tokens when credentials or two-factor settings change and adding rate limiting to pre-login and authentication-request endpoints. The release also adds new SSO and administrative 2FA capabilities and fixes password changes, organization imports, iOS registration, MariaDB migrations, and archive-date handling.
- Remembered two-factor authentication tokens are now revoked when user credentials or 2FA settings are changed.
- Rate limiting has been added to pre-login and authentication request endpoints to reduce authentication abuse.
- Failed two-factor email-login credential attempts now include the source IP address and username in logs, improving security monitoring and investigation capabilities.
What's new
Vaultwarden 1.37.3 is a security and maintenance release introducing authentication hardening, SSO improvements, administrative capabilities, and multiple compatibility and reliability fixes.
What's new- Added rate limiting to pre-login and authentication request endpoints.
- Remembered 2FA tokens are now revoked when credentials or two-factor authentication settings are changed.
- Added support for administrators to reset two-factor authentication.
- Added the SSO_SIGNUPS_ALLOWED configuration option for controlling account creation through SSO.
- Improved security logging by recording the IP address and username for failed two-factor email-login credential attempts.
- Fixed password changes when using newer versions of the Bitwarden web vault.
- Fixed organization imports when the groups field is missing.
- Fixed iOS registration token responses.
- Fixed a database migration issue affecting MariaDB 12.2.2.
- Fixed archiveDate updates and includes additional internal maintenance improvements.
Organizations running Vaultwarden 1.37.2 or earlier should prioritize upgrading to version 1.37.3 after standard validation. The authentication hardening changes, particularly 2FA token revocation and authentication endpoint rate limiting, make this update recommended for Internet-accessible and enterprise Vaultwarden deployments.
π¬ Comments (0)
Share any installation issues, compatibility changes, or fixes you noticed.