Tailscale Patches Root Access, DoS Bugs in v1.98.9
16 Jul 2026
Tailscale has published security advisory TS-2026-009, disclosing two vulnerabilities affecting its Serve, Funnel, and SSH features. Both issues are fixed in version 1.98.9, and founders running Tailscale for internal networking or public-facing services should treat this as a priority patch.
What was disclosed
The advisory covers two distinct vulnerabilities:
1. CPU-pinning denial-of-service in Serve/Funnel. A malformed HTTP request sent to a node running Tailscale Serve or Funnel could pin a CPU core indefinitely, causing a denial of service. The attack surface differs by feature:
- For Tailscale Serve, the malicious request could come from any peer already on the tailnet with access to the node.
- For Tailscale Funnel, which exposes services to the public internet, the request could originate from any unauthenticated host on the internet — a notably broader attack surface.
Nodes running versions prior to 1.98.9 were affected.
2. Root access via crafted SSH usernames. Tailscale SSH on Linux contained insecure command-line argument handling that could grant root access in violation of configured ACLs. Specifically, if a user connected with the username -i, it was misinterpreted as the flag --no-idn, causing the underlying getent command to print the entire passwd file starting with the root user — and opening an interactive root session in the process. This affected deployments relying on autogroup:nonroot ACL restrictions to prevent root-level SSH access.
Both vulnerabilities were reported by Anthropic and Ada Logics.
The fix
Tailscale version 1.98.9 contains fixes for both issues. There is no word yet on the earliest affected version, discovery/report dates, CVSS severity scores, or whether either flaw was exploited before the patch shipped — the advisory is notably light on these details.
Why founders should care
If your startup uses Tailscale for internal networking or to expose services via Funnel, there's a reasonable likelihood these issues are directly relevant to your infrastructure, especially if you haven't upgraded recently:
- Teams using Tailscale SSH with
autogroup:nonrootACLs to restrict root access should assume their privilege-separation model was likely undermined until they patch — this is arguably the more severe of the two issues given it grants root access outright. - Teams exposing services via Tailscale Funnel face a wider attack surface than Serve users, since any unauthenticated internet host could potentially trigger the CPU-pinning DoS. This makes patching more urgent for public-facing deployments.
- Internal-only Serve users face a narrower but still real risk, since any tailnet peer with node access could attempt the attack.
- The involvement of external researchers (Anthropic, Ada Logics) suggests Tailscale's disclosure process functioned as intended, though this alone shouldn't be read as a broader signal about the product's overall security posture.
What to do now
- Upgrade to Tailscale 1.98.9 or newer — this is the single action that remediates both vulnerabilities.
- Audit any ACLs relying on
autogroup:nonrootto confirm they weren't bypassed via the crafted-username issue before patching. - Review Serve/Funnel-exposed nodes to gauge denial-of-service exposure, particularly for Funnel deployments reachable from the open internet.
Given the missing detail on exploitability and timeline, founders can't yet gauge how urgent this was in practice — but the nature of the fixes (root access bypass, internet-facing DoS) argues for treating the upgrade as a near-term priority rather than routine maintenance.