Briefing

Tailscale Serves Two Critical Vulnerabilities Fixed in 1.98.9

security
by jervant ·

Patch Tailscale to 1.98.9 or newer to fix CPU core denial of service and SSH root access.

What to do now

Patch Tailscale to 1.98.9 or newer immediately.

Summary

Tailscale has disclosed two critical vulnerabilities that affect its Serve and Funnel services. The first flaw allows a single malformed HTTP request to spin a goroutine indefinitely, pinning a CPU core and causing a denial of service. The second flaw permits an attacker to use a username beginning with a dash, such as –i, to bypass ACLs and gain a root session on Linux nodes. Both issues are triggered by untrusted input and are not mitigated by timeouts or input validation.

The denial‑of‑service vulnerability can be triggered by any peer on a tailnet for Serve or by any unauthenticated host for Funnel, while the privilege escalation flaw affects Linux hosts that rely on autogroup:nonroot ACLs. Tailscale has patched both bugs in version 1.98.9, which now terminates non‑absolute path walks and rejects usernames with leading dashes. All nodes running Serve or Funnel before 1.98.9 are required to upgrade immediately to eliminate the risk.

Key changes

  • CPU core denial of service via malformed HTTP request in Serve/Funnel
  • Non‑absolute path walk bug fixed in 1.98.9
  • SSH username leading dash rejected to prevent root session
  • Root session via –i username prevented
  • Fixed in Tailscale 1.98.9 or newer
  • Affected nodes: Serve/Funnel before 1.98.9

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting