The open-source password server Vaultwarden shipped version 1.37.3 on 13 September 2026. The maintenance release of the Bitwarden-compatible self-hosting project centres on securing the login flow and closes several security-relevant gaps.
The login gets tougher
Vaultwarden now rate-limits the prelogin and auth-request endpoints, making automated attacks harder. When users change their credentials or two-factor settings, existing “remember 2FA” tokens are revoked. The server also logs the IP address and username of failed two-factor email logins.
New administrative controls
Administrators can now reset an account’s two-factor authentication, which helps when staff lose access to their device. The release also adds the SSO_SIGNUPS_ALLOWED option, giving operators finer control over single sign-on registrations.
Bug fixes
The update fixes password changes with newer web-vault builds and a migration error on MariaDB 12.2.2. It also resolves organization-import failures and a registration issue affecting iOS clients.
Sources: The details are based on the official release notes for Vaultwarden 1.37.3 on GitHub.









