posted in Selfhosted

PSA: the bitwarden clients got an upgrade that makes them incompatible with vaultwarden

If you got the automatic updates on the bitwarden clients, they will show an empty vault if you are selfhosting vaultwarden.

It seems to be an accidental bug in the bitwarden clients that are assuming that they’re talking with official servers

It’s fixed with the latest release of the vaultwarden server that was published a few minutes ago

github.com/dani-garcia/vaultwarden/releases/tag/1.37.0
Note
This update is required for support with clients with version 2026.7.0+, please update before reporting any issues with them.
Security Fixes
This release contains security fixes for the follow...GitHubRelease 1.37.0 · dani-garcia/vaultwardenNote This update is required for support with clients with version 2026.7.0+, please update before reporting any issues with them. Security Fixes This release contains security fixes for the follow...

Replying to @⁨Wispy2891@lemmy.world⁩

I found this comment on what happened by dani-garcia, one of the main devs:

The short version is that around 8-ish years ago, Bitwarden changed the way the vault items were structured, and Vaultwarden added some backwards compatibility fields to ensure both old and new versions of the clients worked.

These backwards compatibility fields were supposed to be a temporary measure, but for at least the next three years the clients still required them, until we eventually forgot to keep track of them. At some point between 2021 and today, the clients stopped requiring these backwards compatibility fields, but Vaultwarden was still sending them.

This wasn’t a problem until Bitwarden decided to use the backwards compatibility fields in a completely different way, which caused the clients to crash.

Found here: github.com/dani-garcia/vaultwarden/…/7473

Note This update is required for support with clients with version 2026.7.0+, please update before reporting any issues with them. Security Fixes This release contains security fixes for the follow...GitHubv1.37.0 (Upgrade to this version when using clients v2026.7.0+) · dani-garcia vaultwarden · Discussion #7473Note This update is required for support with clients with version 2026.7.0+, please update before reporting any issues with them. Security Fixes This release contains security fixes for the follow...

Replying to @⁨SmoothLiquidation@lemmy.world⁩

There’s a reason you don’t do things like that…

Apparently nobody in that software team has heard about Knight Capital. They reused a flag and that coupled with a deployment failure that only lasted ~45 minutes caused an over 400 million dollar loss nearly bankrupting the entire company. Ultimately they ended up combining with another company.

The immediate cause of the incident was a deployment failure that left one of eight servers running outdated code, creating an inconsistency in how the system interpreted incoming instructions. The new software reused a flag associated with a legacy function known as “Power Peg,” which had been disabled but not removed from the codebase, and on the unpatched server this flag activated obsolete logic that continuously generated child orders in response to parent orders that the system did not correctly recognize as already filled.

More details

Henrico DolfingCase Study 4: The $440 Million Software Error at Knight Capital - Henrico DolfingOn the morning of August 1, 2012, Knight Capital Group opened its systems for what should have been a routine trading day, yet within minutes the firm began sending a flood of unintended orders into the U.S. equity market, buying high and selling low across dozens of stocks in a pattern that made no economic ... Read more

Replying to an earlier post

I hadn’t heard of this one before, thanks for posting.

Edit: this website is very strange. The article is dated 5th June 2019 and the other “case studies” are dated to look like they’ve been writing regularly since 2019 up until now. But the article reads like LLM output, and the waybackmachine has no record of this article before December 2025, and no record of the domain name henricodolfing.ch before April 2025. The whois database says that the domain was registered in January 2025. So are they really trying to launder slop by back-dating it to make it look like it was written before LLMs existed? Fuck.

Edited ⁨⁨Jul⁩ ⁨31⁩, ⁨2026⁩, ⁨11:15⁩⁩en