Vaultwarden是Daniel García个人开发者的一个用 Rust 编写的 Bitwarden 服务器 API 的替代实现。 Vaultwarden 1.35.4之前版本存在安全漏洞,该漏洞源于如果启用电子邮件双因素认证,则允许绕过登录暴力破解保护,未受保护的双因素功能send_email_login也充当判断用户名密码组合是否正确的预言机,攻击者可滥用该端点无速率限制地暴力破解密码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dani-garcia | vaultwarden | < 1.35.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| dani-garcia | vaultwarden | < 1.35.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43912 | 8.7 HIGH | Vaultwarden: Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Anoth |
| CVE-2026-43913 | 8.1 HIGH | Vaultwarden: Unconfirmed Owner Can Purge Entire Organization Vault |
| CVE-2026-43911 | 6.8 MEDIUM | Vaultwarden: Refresh tokens not invalidated on security stamp rotation |
No comments yet