Update vaultwarden/server Docker tag in stack bitwarden from 1.37.3 to v1.37.4 #562

Merged
Kevin merged 1 commit from renovate/vaultwarden-server-1.x into main 2026-10-06 09:04:41 -04:00
Collaborator

This PR contains the following updates:

Package Update Change
vaultwarden/server patch 1.37.3 → 1.37.4

Release Notes

dani-garcia/vaultwarden (vaultwarden/server)

v1.37.4

Compare Source

Security Fixes

This release contains security fixes for the following advisories. We strongly advise updating as soon as possible.

These are private for now, pending CVE assignment and publishing at a later date.

[!NOTE]
If an organization has Admins you don't fully trust, consider rotating its API key after updating (Admin Console → Settings → Rotate API key). Before this release, Admins could also view the key.

Upgrade notes

  • Reverse proxies: with IP_HEADER=X-Forwarded-For, the client IP is now the rightmost address that isn't in IP_HEADER_TRUSTED_PROXIES (it used to be the leftmost). If you have several proxies in a row, for example a CDN in front of nginx, add all of them to IP_HEADER_TRUSTED_PROXIES. Otherwise the address of the proxy in front is used for rate limiting and logs.
  • Sends: bw send receive on CLI 2026.4.2 and older no longer works, the same as against Bitwarden's own servers since v2026.8.0. Creating and managing Sends works on all clients.
  • Feature flags: these flags were removed because no client reads them anymore: ssh-agent, ssh-key-vault-item, mutual-tls, anon-addy-self-host-alias, simple-login-self-host-alias, pm-25373-windows-biometrics-v2, pm-26340-linux-biometrics-v2, desktop-ui-migration-milestone-1 to -4, cxp-import-mobile and cxp-export-mobile. If EXPERIMENTAL_CLIENT_FEATURE_FLAGS still lists one of them, startup logs a warning and saving settings in the admin panel fails until it's removed.
  • Duo: DUO_USE_IFRAME (the deprecated Traditional Prompt) is removed and ignored if set.
  • Custom templates: there's a new email template, email/recover_twofactor, sent after a login with a two-step recovery code.
  • The legacy POST /identity/accounts/register and POST /api/accounts/prelogin endpoints are removed. No current client uses them.

What's Changed

New Contributors

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.37.3...1.37.4


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [vaultwarden/server](https://github.com/dani-garcia/vaultwarden) | patch | `1.37.3` → `1.37.4` | --- ### Release Notes <details> <summary>dani-garcia/vaultwarden (vaultwarden/server)</summary> ### [`v1.37.4`](https://github.com/dani-garcia/vaultwarden/releases/tag/1.37.4) [Compare Source](https://github.com/dani-garcia/vaultwarden/compare/1.37.3...1.37.4) #### Security Fixes This release contains security fixes for the following advisories. We strongly advise updating as soon as possible. - Organization member revocation [\[GHSA-69q9-v8p6-xvx3\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-69q9-v8p6-xvx3) (**High**, 8.1) - Two-factor authentication [\[GHSA-7jg8-8m5x-6j9r\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-7jg8-8m5x-6j9r) (**Medium**, 6.8) - Organization invitations [\[GHSA-v576-3wvq-xh3c\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-v576-3wvq-xh3c) (**Medium**, 6.8) - Attachments [\[GHSA-q5x6-grh5-fqgc\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-q5x6-grh5-fqgc) (**Medium**, 6.5) - Organization event logs [\[GHSA-64mc-4p6f-r7x9\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-64mc-4p6f-r7x9) (**Medium**, 4.3) - Cipher sharing [\[GHSA-7ccc-c43j-4p36\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-7ccc-c43j-4p36) (**Medium**, 4.3) - Organization API key [\[GHSA-qwx4-wcv4-mpcv\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-qwx4-wcv4-mpcv) (**Low**, 3.8) - Additional dependency updates and minor security enhancements These are private for now, pending CVE assignment and publishing at a later date. > \[!NOTE] > If an organization has Admins you don't fully trust, consider rotating its API key after updating (Admin Console → Settings → Rotate API key). Before this release, Admins could also view the key. #### Upgrade notes - **Reverse proxies:** with `IP_HEADER=X-Forwarded-For`, the client IP is now the rightmost address that isn't in `IP_HEADER_TRUSTED_PROXIES` (it used to be the leftmost). If you have several proxies in a row, for example a CDN in front of nginx, add all of them to `IP_HEADER_TRUSTED_PROXIES`. Otherwise the address of the proxy in front is used for rate limiting and logs. - **Sends:** `bw send receive` on CLI 2026.4.2 and older no longer works, the same as against Bitwarden's own servers since v2026.8.0. Creating and managing Sends works on all clients. - **Feature flags:** these flags were removed because no client reads them anymore: `ssh-agent`, `ssh-key-vault-item`, `mutual-tls`, `anon-addy-self-host-alias`, `simple-login-self-host-alias`, `pm-25373-windows-biometrics-v2`, `pm-26340-linux-biometrics-v2`, `desktop-ui-migration-milestone-1` to `-4`, `cxp-import-mobile` and `cxp-export-mobile`. If `EXPERIMENTAL_CLIENT_FEATURE_FLAGS` still lists one of them, startup logs a warning and saving settings in the admin panel fails until it's removed. - **Duo:** `DUO_USE_IFRAME` (the deprecated Traditional Prompt) is removed and ignored if set. - **Custom templates:** there's a new email template, `email/recover_twofactor`, sent after a login with a two-step recovery code. - The legacy `POST /identity/accounts/register` and `POST /api/accounts/prelogin` endpoints are removed. No current client uses them. #### What's Changed - \[Web 2026.9.0] Support the vault banner policy by [@&#8203;tom27052006](https://github.com/tom27052006) in [#&#8203;7748](https://github.com/dani-garcia/vaultwarden/pull/7748) - Add support for basic auth response client feature flag by [@&#8203;tom27052006](https://github.com/tom27052006) in [#&#8203;7745](https://github.com/dani-garcia/vaultwarden/pull/7745) - \[web-v2026.8.1] store the user key ID by [@&#8203;Timshel](https://github.com/Timshel) in [#&#8203;7693](https://github.com/dani-garcia/vaultwarden/pull/7693) - Add organizationsNew and policiesNew to sync response by [@&#8203;tom27052006](https://github.com/tom27052006) in [#&#8203;7666](https://github.com/dani-garcia/vaultwarden/pull/7666) - Add `pm-32009-new-item-types` feature flag by [@&#8203;bdd](https://github.com/bdd) in [#&#8203;7478](https://github.com/dani-garcia/vaultwarden/pull/7478) - Update Crates, GHA and JS by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7751](https://github.com/dani-garcia/vaultwarden/pull/7751) - Add `pm-34171-card-scanner` feature flag by [@&#8203;bdd](https://github.com/bdd) in [#&#8203;7477](https://github.com/dani-garcia/vaultwarden/pull/7477) - set user\_created bool for each separate invitation by [@&#8203;stefan0xC](https://github.com/stefan0xC) in [#&#8203;7753](https://github.com/dani-garcia/vaultwarden/pull/7753) - Fix revoked org members retaining access to org ciphers by [@&#8203;abhiShandy](https://github.com/abhiShandy) in [#&#8203;7554](https://github.com/dani-garcia/vaultwarden/pull/7554) - Ensure all user checked routes are confirmed by [@&#8203;dani-garcia](https://github.com/dani-garcia) in [#&#8203;7763](https://github.com/dani-garcia/vaultwarden/pull/7763) - Fix cortex-a53 build issues when using xx-cargo by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7774](https://github.com/dani-garcia/vaultwarden/pull/7774) - Add `undetermined-cipher-scenario-logic` feature flag (closes [#&#8203;7801](https://github.com/dani-garcia/vaultwarden/issues/7801)) by [@&#8203;cad0p](https://github.com/cad0p) in [#&#8203;7802](https://github.com/dani-garcia/vaultwarden/pull/7802) - Add Windows native credential sync to supported feature flags by [@&#8203;KingIronMan2011](https://github.com/KingIronMan2011) in [#&#8203;7798](https://github.com/dani-garcia/vaultwarden/pull/7798) - Hide the whole change-email section when EMAIL\_CHANGE\_ALLOWED is false by [@&#8203;tom27052006](https://github.com/tom27052006) in [#&#8203;7759](https://github.com/dani-garcia/vaultwarden/pull/7759) - Fix Clippy warnings across all targets by [@&#8203;tom27052006](https://github.com/tom27052006) in [#&#8203;7782](https://github.com/dani-garcia/vaultwarden/pull/7782) - Admin reset: 2fa email fallback need a verified email by [@&#8203;Timshel](https://github.com/Timshel) in [#&#8203;7770](https://github.com/dani-garcia/vaultwarden/pull/7770) - Sends cleanup: remove legacy endpoints and align with upstream by [@&#8203;dani-garcia](https://github.com/dani-garcia) in [#&#8203;7806](https://github.com/dani-garcia/vaultwarden/pull/7806) - Remove legacy API endpoints and compatibility code by [@&#8203;dani-garcia](https://github.com/dani-garcia) in [#&#8203;7809](https://github.com/dani-garcia/vaultwarden/pull/7809) - Align API with upstream and remove unwraps by [@&#8203;dani-garcia](https://github.com/dani-garcia) in [#&#8203;7810](https://github.com/dani-garcia/vaultwarden/pull/7810) - Update crates, Rust and other dependencies by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7814](https://github.com/dani-garcia/vaultwarden/pull/7814) #### New Contributors - [@&#8203;bdd](https://github.com/bdd) made their first contribution in [#&#8203;7478](https://github.com/dani-garcia/vaultwarden/pull/7478) - [@&#8203;abhiShandy](https://github.com/abhiShandy) made their first contribution in [#&#8203;7554](https://github.com/dani-garcia/vaultwarden/pull/7554) - [@&#8203;cad0p](https://github.com/cad0p) made their first contribution in [#&#8203;7802](https://github.com/dani-garcia/vaultwarden/pull/7802) - [@&#8203;KingIronMan2011](https://github.com/KingIronMan2011) made their first contribution in [#&#8203;7798](https://github.com/dani-garcia/vaultwarden/pull/7798) **Full Changelog**: <https://github.com/dani-garcia/vaultwarden/compare/1.37.3...1.37.4> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMjMuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEyMy4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJwYXRjaCIsInJlbm92YXRlIl19-->
renovate-bot scheduled this pull request to auto merge when all checks succeed 2026-10-06 01:02:34 -04:00
Kevin merged commit 071b3d0f3e into main 2026-10-06 09:04:41 -04:00
Sign in to join this conversation.
No reviewers
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Kevin/docker-l2!562
No description provided.