Nixpkgs Security Tracker

Login with GitHub

Details of issue NIXPKGS-2026-0515

NIXPKGS-2026-0515
published on 5 Mar 2026
updated 4 days, 2 hours ago by @LeSuisse Activity log
  • Created automatic suggestion
  • @LeSuisse removed package vaultwarden-webvault
  • @LeSuisse accepted
  • @LeSuisse removed
    2 maintainers
    • @dotlambda
    • @SuperSandro2000
  • @LeSuisse published on GitHub
Vaultwarden: 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated access to a user’s account can exploit this bypass to perform protected actions such as accessing the user’s API key or deleting the user’s vault and organisations the user is an admin/owner of . This issue has been patched in version 1.35.0.

Affected products

vaultwarden
  • ==< 1.35.0

Matching in nixpkgs

Ignored packages (1)

Package maintainers

Ignored maintainers (2)
Upstream advisory: https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-v6pg-v89r-w8wr