{
 "schema": "bumplog.app.v1",
 "generatedAt": "2026-07-26T13:02:49.518Z",
 "slug": "vaultwarden",
 "name": "Vaultwarden",
 "repo": "dani-garcia/vaultwarden",
 "latestVersion": "1.36.0",
 "safeToUpdate": "caution",
 "rationale": "This release patches six security advisories (SSO CSRF, user/org enumeration, SSO existing-user binding, and SSRF via Icon Endpoint) and the maintainers explicitly urge updating 'as soon as possible,' making the upgrade strongly recommended. No breaking changes or required manual migration steps are called out in the notes. However, the multiple SSO-related fixes (CSRF, identifier handling, user binding) and the Web Vault bump to v2026.4.1 warrant reading the individual advisories—especially if SSO is enabled—before updating in production.",
 "changelogSummary": "Vaultwarden 1.36.0 is a security-critical release that patches multiple vulnerabilities including SSO login CSRF, user/organization enumeration, SSO existing-user binding issues, and server-side request forgery (SSRF) via the icon endpoint — an immediate upgrade is strongly advised. On the features side, vault item archiving is now supported, letting users tidy their vault without permanently deleting entries. The bundled Web Vault has been updated to v2026.4.1, and DuckDuckGo has been added as a recognized browser device type. Several SSO improvements and a fix for favicon fetching (which now checks all icon links rather than only the first) round out the release.",
 "sourceUrl": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.36.0",
 "lastChecked": "2026-06-28",
 "successor": null,
 "url": "https://bumplog.org/apps/vaultwarden/",
 "badge": "https://bumplog.org/badge/vaultwarden.svg",
 "lifecycle": null
}