Vaultwarden is a Bitwarden-compatible server written in Rust. In versions prior to 1.35.4, the login brute-force protection can be bypassed when email 2FA is enabled on the instance. The unprotected `send_email_login` endpoint acts as an oracle for valid username-password combinations, allowing an attacker to brute-force passwords without rate-limiting. This affects all users on the instance, even those who have not configured email 2FA themselves.
Author: Robert
-
Vaultwarden
-
CVE-2026-43914 ‒ Brute-Force Protection Bypass in Vaultwarden via Email 2FA Endpoint
-
-
Gitea
-
Taiga