CVE-2026-43914

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is enabled. If email 2fa is enabled, the unprotected 2fa-function send_email_login (email.rs, api endpoint /api/two-factor/send-email-login) also acts as an oracle determining whether a username-password combination is correct. An attacker can abuse that endpoint to brute-force passwords without rate-limiting. This works even for users who don't have email 2fa configured. This vulnerability is fixed in 1.35.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dani-garcia:vaultwarden:*:*:*:*:*:*:*:*

History

13 May 2026, 19:35

Type Values Removed Values Added
References () https://github.com/dani-garcia/vaultwarden/pull/6867 - () https://github.com/dani-garcia/vaultwarden/pull/6867 - Issue Tracking, Patch
References () https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.4 - () https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.4 - Product, Release Notes
References () https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-c5rv-q295-7w4g - () https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-c5rv-q295-7w4g - Exploit, Patch, Vendor Advisory
CPE cpe:2.3:a:dani-garcia:vaultwarden:*:*:*:*:*:*:*:*
First Time Dani-garcia vaultwarden
Dani-garcia

12 May 2026, 14:17

Type Values Removed Values Added
References () https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-c5rv-q295-7w4g - () https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-c5rv-q295-7w4g -

11 May 2026, 23:20

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-11 23:20

Updated : 2026-05-13 19:35


NVD link : CVE-2026-43914

Mitre link : CVE-2026-43914

CVE.ORG link : CVE-2026-43914


JSON object : View

Products Affected

dani-garcia

  • vaultwarden
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts