Tailscale fixed two vulnerabilities in version 1.98.9. A malformed HTTP request to Tailscale Serve or Funnel could pin a CPU core indefinitely due to an infinite path-walk loop. Separately, Tailscale SSH accepted usernames with leading dashes, permitting root access in violation of ACLs on Linux. Both issues were reported by Anthropic and Ada Logics. Users should upgrade to version 1.98.9 or newer.
No score is assigned. Sources and their independence are shown in the citation chain below.