megachangelog
Security1.98.9

Tailscale v1.98.9 Security and Stability Fixes

This release addresses six security vulnerabilities in Tailscale SSH, Serve, Funnel, and Services, plus fixes an issue where users could be unexpectedly logged out when changing device tags via CLI.

All Platforms

  • Fixed: Tailscale SSH Unix socket forwarding respects symlink permissions. This fix addresses a security vulnerability described in TS-2026-004.
  • Fixed: Tailscale Serve Unix socket proxy targets are restricted to the root user. This fix addresses a security vulnerability described in TS-2026-005.
  • Fixed: Tailscale SSH does not allow the use of UIDs or numeric-only usernames. This fix addresses a security vulnerability described in TS-2026-006.
  • Fixed: Nodes advertising Tailscale Services filter and reject packets from service IPs on ports they do not advertise. This fix addresses a security vulnerability described in TS-2026-007.
  • Fixed: Tailscale Serve and Tailscale Funnel terminate path walks for non-absolute paths, preventing CPU core pinning. This fix addresses a security vulnerability described in TS-2026-008.
  • Fixed: Tailscale SSH does not allow the use of usernames with leading dashes. This fix addresses a security vulnerability described in TS-2026-009.
  • Fixed: An issue where a user could be logged out of Tailscale when changing the tag on a device via CLI has been resolved.
securitysshservefunnelauth

Source: original entry ↗