megachangelog
Security1.66

ACL syntax updates

ACL semantics for the * wildcard in src fields has changed to expand only to Tailscale IP addresses and approved subnet routes, addressing a security issue (TS-2024-005). A new autogroup:danger-all ACL type provides the previous behavior if needed.

  • Changed: As part of a security fix to address an issue related to exit nodes and subnet routing (TS-2024-005), changes are made to ACLs.
    • The meaning of * when used in the src field in ACLs has been changed. Previously, * expanded to include any IPv4 and IPv6 address. With this change, * expands to all Tailscale IP addresses and all IP addresses from approved subnet routes.
    • The new autogroup:danger-all ACL type has been added, which matches the previous definition of * when used in the src field. If you are using default ACLs or have specified * in src, you don't need to make any ACL changes to get the new secure behavior.
    • We recommend updating all Tailscale clients to v1.66 to benefit from the additional security improvements.
securityaclexit-nodessubnet-routing

Source: original entry ↗

More from Tailscale

Follow Tailscale to get its new changes in your feed and email digest.

Improvement1.104.1

Tailscale v1.104.1 — Performance and Features Release

Tailscale v1.104.1 delivers significant performance improvements including reduced WireGuard memory usage, client-side netmap caching for offline resilience, and enhanced features like device pinning, improved Taildrop support, and platform-specific fixes across all supported devices.

performancememorywireguardfeaturesmulti-platform
Feature

Declarative node sharing

Tailnet admins can now use policy to securely share resources between trusted tailnets in a declarative way, enabling controlled cross-tailnet access.

node-sharingpolicysecuritymulti-tailnetaccess-control
Fix1.102.5

Linux client reconnection stability fix

Fixed an issue where the Linux client would stop tailscaled when falling behind on status updates. The client now reconnects instead of exiting, and only terminates if it cannot reconnect within one minute.

linuxstabilityreconnection
See all Tailscale changes →