Back Linuxsecurity Fedora 43 vaultwarden Critical DoS and Access Issues Fix 2026
* Wed Jun 3 2026 Jonathan Wright - 1.36.0-1 - update to 1.36.0 rhbz#2368636 - Fix bitwarden mobile app not working rhbz#2437599 - Fix CVE-2025-58160 vaultwarden: Tracing log pollution - Fix CVE-2026-25537 vaultwarden: jsonwebtoken has Type Confusion that leads to potential authorization bypass - Fix CVE-2026-25727 vaultwarden: time affected by a stack exhaustion denial of service attack - Fix CVE-2026-26012 vaultwarden: Information disclosure due to bypassed collection permissions - Fix CVE-2026-27898 vaultwarden: Information disclosure via API partial update - Fix CVE-2026-27803 vaultwarden: Unauthorized collection management operations due to improper access control - Fix CVE-2026-27801 vaultwarden: Two-factor authentication bypass allows unauthorized access and data deletion * Sat Jan 17 2026 Fedora Release Engineering - 1.34.2-2 - Rebuilt for * Tue Jul 29 2025 Jonathan Wright - 1.34.2-1 - update to 1.34.2 rhbz#2368636
* Wed Jun 3 2026 Jonathan Wright - 1.36.0-1 - update to 1.36.0 rhbz#2368636 - Fix bitwarden mobile app not working rhbz#2437599 - Fix CVE-2025-58160 vaultwarden: Tracing log pollution - Fix CVE-2026-25537 vaultwarden: jsonwebtoken has Type Confusion that leads to potential authorization bypass - Fix CVE-2026-25727 vaultwarden: time affected by a stack exhaustion denial of service attack - Fix CVE-2026-26012 vaultwarden: Information disclosure due to bypassed collection permissions - Fix CVE-2026-27898 vaultwarden: Information disclosure via API partial update - Fix CVE-2026-27803 vaultwarden: Unauthorized collection management operations due to improper access control - Fix CVE-2026-27801 vaultwarden: Two-factor authentication bypass allows unauthorized access and data deletion * Sat Jan 17 2026 Fedora Release Engineering - 1.34.2-2 - Rebuilt for * Tue Jul 29 2025 Jonathan Wright - 1.34.2-1 - update to 1.34.2 rhbz#2368636
[ 1 ] Bug #2437473 - CVE-2026-25537 vaultwarden: jsonwebtoken has Type Confusion that leads to potential authorization bypass [fedora-43] [ 2 ] Bug #2438166 - CVE-2026-25727 vaultwarden: time affected by a stack exhaustion denial of service attack [fedora-43] [ 3 ] Bug #2439261 - CVE-2026-26012 vaultwarden: Vaultwarden: Information disclosure due to bypassed collection permissions [fedora-43]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-264f9ef567' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
