vaultwarden
crates.io7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting vaultwardenpage 1 of 1
- CVE-2024-55224CRITICALCVSS 9.6EG 9.6✓ Fixed in 1.32.52025-01-09
An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.
- CVE-2024-55225CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.32.52025-01-09
An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.
- CVE-2024-55226MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.32.52025-01-09
Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.
- CVE-2026-27801MEDIUMCVSS 5.9EG 5.9✓ Fixed in 1.35.02026-03-04
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authen…
- CVE-2026-27802HIGHCVSS 8.3EG 8.3✓ Fixed in 1.35.42026-03-04
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized collections by Mana…
- CVE-2026-27803HIGHCVSS 8.3EG 8.3✓ Fixed in 1.35.42026-03-04
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations…
- CVE-2026-27898MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.35.42026-03-04
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial…
Check whether vaultwarden is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for vaultwarden CVEs against the assets you own.
Start Free Scan →