← All stories
● Covered by 1 source · 1 reportHigh impact

Tailscale vulnerabilities allowed DoS and unauthorized root access

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Denial of service vulnerability in Tailscale Serve and Funnel
  • SSH root access via usernames with leading dashes
  • Fixed in Tailscale version 1.98.9 or newer
  • Affected users must upgrade to avoid exploitation

Overview of Vulnerabilities

Tailscale reported two critical vulnerabilities: one affecting Tailscale Serve and Funnel through denial of service (DoS) and another concerning Tailscale SSH, allowing unauthorized root access. Both vulnerabilities require immediate action from users running older versions of Tailscale.

Denial of Service Risk

The DoS vulnerability allows attackers to send malformed HTTP requests to nodes running Tailscale Serve or Funnel, causing a CPU core to spin indefinitely. This issue arises when the request path does not start with '/', resulting in an infinite loop without a timeout.

Unauthorized Root Access

The SSH vulnerability arises from Tailscale's acceptance of usernames with leading dashes. This allowed an attacker to connect using such a username and trigger commands that could access sensitive information. As a result, they could start a root session, violating access control lists.

Mitigation Steps

The vulnerabilities have been patched in Tailscale version 1.98.9 and users running affected versions are strongly encouraged to upgrade immediately. Organizations using Tailscale must ensure their systems are updated to avoid potential exploitation of these vulnerabilities.

Acknowledgements

Tailscale credited Anthropic and Ada Logics for identifying and reporting these vulnerabilities, which helped the company in ensuring their product's security.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Tailscale issued a security advisory for two vulnerabilities, one allowing denial of service through malformed HTTP requests and another permitting unauthorized root access via specially crafted SSH usernames. Affected users are advised to upgrade to Tailscale version 1.98.9 or newer to resolve these issues.