github dani-garcia/vaultwarden 1.37.4

7 hours ago

Security Fixes

This release contains security fixes for the following advisories. We strongly advise updating as soon as possible.

These are private for now, pending CVE assignment and publishing at a later date.

Note

If an organization has Admins you don't fully trust, consider rotating its API key after updating (Admin Console → Settings → Rotate API key). Before this release, Admins could also view the key.

Upgrade notes

  • Reverse proxies: with IP_HEADER=X-Forwarded-For, the client IP is now the rightmost address that isn't in IP_HEADER_TRUSTED_PROXIES (it used to be the leftmost). If you have several proxies in a row, for example a CDN in front of nginx, add all of them to IP_HEADER_TRUSTED_PROXIES. Otherwise the address of the proxy in front is used for rate limiting and logs.
  • Sends: bw send receive on CLI 2026.4.2 and older no longer works, the same as against Bitwarden's own servers since v2026.8.0. Creating and managing Sends works on all clients.
  • Feature flags: these flags were removed because no client reads them anymore: ssh-agent, ssh-key-vault-item, mutual-tls, anon-addy-self-host-alias, simple-login-self-host-alias, pm-25373-windows-biometrics-v2, pm-26340-linux-biometrics-v2, desktop-ui-migration-milestone-1 to -4, cxp-import-mobile and cxp-export-mobile. If EXPERIMENTAL_CLIENT_FEATURE_FLAGS still lists one of them, startup logs a warning and saving settings in the admin panel fails until it's removed.
  • Duo: DUO_USE_IFRAME (the deprecated Traditional Prompt) is removed and ignored if set.
  • Custom templates: there's a new email template, email/recover_twofactor, sent after a login with a two-step recovery code.
  • The legacy POST /identity/accounts/register and POST /api/accounts/prelogin endpoints are removed. No current client uses them.

What's Changed

New Contributors

Full Changelog: 1.37.3...1.37.4

Don't miss a new vaultwarden release

NewReleases is sending notifications on new releases.