Dani-garcia

Vaultwarden

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 15.07.2026 15:04:15
  • Zuletzt bearbeitet 15.07.2026 18:15:13

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that missed decimal, hexadecimal, and oc...

  • EPSS 0.27%
  • Veröffentlicht 15.07.2026 15:03:22
  • Zuletzt bearbeitet 15.07.2026 18:15:13

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true linked an IdP identity to an existin...

  • EPSS 0.37%
  • Veröffentlicht 15.07.2026 15:02:46
  • Zuletzt bearbeitet 15.07.2026 18:15:13

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and al...

  • EPSS 0.16%
  • Veröffentlicht 15.07.2026 15:01:51
  • Zuletzt bearbeitet 15.07.2026 19:17:17

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled P...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 11.05.2026 22:03:58
  • Zuletzt bearbeitet 13.05.2026 19:35:51

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is enabled. If email 2fa is enabled, the unprotected 2...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 11.05.2026 22:01:35
  • Zuletzt bearbeitet 13.05.2026 19:29:54

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The organization invite flow uses a two-step process: accepting an invite tran...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 11.05.2026 21:56:30
  • Zuletzt bearbeitet 15.05.2026 20:19:43

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as groups.groups_uuid, or a collections_groups.collections...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 11.05.2026 21:54:41
  • Zuletzt bearbeitet 18.05.2026 16:58:20

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (password change, KDF change, key rotation, email change...

  • EPSS 0.17%
  • Veröffentlicht 05.05.2026 20:16:36
  • Zuletzt bearbeitet 24.07.2026 23:10:00

Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the has_full_access() authorization check that exis...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 05.05.2026 18:51:35
  • Zuletzt bearbeitet 25.07.2026 11:10:00

Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flow in `validate_webauthn_login()` updates persistent credential metadata (1backup_eligible1 and 1backup_state flags1) based on...