Is it safe to update Vaultwarden?
Tracking dani-garcia/vaultwarden
Update with care.
This release patches six security advisories (SSO CSRF, user/org enumeration, SSO existing-user binding, and SSRF via Icon Endpoint) and the maintainers explicitly urge updating 'as soon as possible,' making the upgrade strongly recommended. No breaking changes or required manual migration steps are called out in the notes. However, the multiple SSO-related fixes (CSRF, identifier handling, user binding) and the Web Vault bump to v2026.4.1 warrant reading the individual advisories—especially if SSO is enabled—before updating in production.
What changed
Source
Every verdict on Bumplog traces back to a GitHub release. No invented details.