Skip to content

Vaultwarden: bump to 1.35.7#1737

Merged
hadfl merged 1 commit intoomniosorg:masterfrom
extrowerk:vaultwarden-1.35.5
Apr 16, 2026
Merged

Vaultwarden: bump to 1.35.7#1737
hadfl merged 1 commit intoomniosorg:masterfrom
extrowerk:vaultwarden-1.35.5

Conversation

@extrowerk
Copy link
Copy Markdown
Contributor

No description provided.

@papertigers
Copy link
Copy Markdown
Contributor

btw there was a fast follow on with some bug fixes:

https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.6

@extrowerk extrowerk force-pushed the vaultwarden-1.35.5 branch from 2f8163d to a005ed2 Compare April 13, 2026 05:44
@extrowerk extrowerk changed the title Vaultwarden: bump to 1.35.5 Vaultwarden: bump to 1.35.6 Apr 13, 2026
@extrowerk
Copy link
Copy Markdown
Contributor Author

Bumped to 1.35.6

@sjorge
Copy link
Copy Markdown
Contributor

sjorge commented Apr 13, 2026

Might be worth noting there are a couple of CVE's that get fixed by this.

@extrowerk extrowerk force-pushed the vaultwarden-1.35.5 branch from a005ed2 to 3a3af9c Compare April 14, 2026 04:05
@extrowerk
Copy link
Copy Markdown
Contributor Author

Bumped to 1.35.7

@extrowerk extrowerk changed the title Vaultwarden: bump to 1.35.6 Vaultwarden: bump to 1.35.7 Apr 14, 2026
@extrowerk
Copy link
Copy Markdown
Contributor Author

Security Fixes
This release contains security fixes for the following advisories. We strongly advice to update as soon as possible.

[GHSA-937x-3j8m-7w7p](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-937x-3j8m-7w7p) Unconfirmed Owner Can Purge Entire Organization Vault.
[GHSA-569v-845w-g82p](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-569v-845w-g82p) Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Another Organization
[GHSA-6j4w-g4jh-xjfx](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-6j4w-g4jh-xjfx) Refresh tokens not invalidated on security stamp rotation
These are private for now, pending CVE assignment.

@hadfl hadfl merged commit 97c9eba into omniosorg:master Apr 16, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants