<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/tailscale/10</id>
  <title>Most recent entries from tailscale</title>
  <updated>2026-10-02T07:59:00.143416+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ts-2026-011</id>
    <title>ts-2026-011 — &lt;p&gt;&lt;strong&gt;&lt;em&gt;Description&lt;/em&gt;&lt;/strong&gt;: Insufficient validation of 4via6 subnet router destinations permitted access…</title>
    <updated>2026-10-02T07:59:00.146762+00:00</updated>
    <content>ts-2026-011</content>
    <link href="https://cve.radiocsirt.org/vuln/ts-2026-011"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ts-2026-010</id>
    <title>ts-2026-010 — &lt;p&gt;&lt;strong&gt;&lt;em&gt;Description&lt;/em&gt;&lt;/strong&gt;: Tailscale SSH exposed accepted environment variable values on the command lin…</title>
    <updated>2026-10-02T07:59:00.146804+00:00</updated>
    <content>ts-2026-010</content>
    <link href="https://cve.radiocsirt.org/vuln/ts-2026-010"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ts-2026-009</id>
    <title>ts-2026-009 — &lt;p&gt;&lt;strong&gt;&lt;em&gt;Description&lt;/em&gt;&lt;/strong&gt;: Insecure command line argument handling in Tailscale SSH permitted &lt;code&gt;root…</title>
    <updated>2026-10-02T07:59:00.146827+00:00</updated>
    <content>ts-2026-009</content>
    <link href="https://cve.radiocsirt.org/vuln/ts-2026-009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ts-2026-008</id>
    <title>ts-2026-008 — &lt;p&gt;&lt;strong&gt;&lt;em&gt;Description&lt;/em&gt;&lt;/strong&gt;: A single malformed HTTP request to a node running Tailscale Serve or Funnel c…</title>
    <updated>2026-10-02T07:59:00.146845+00:00</updated>
    <content>ts-2026-008</content>
    <link href="https://cve.radiocsirt.org/vuln/ts-2026-008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ts-2026-007</id>
    <title>ts-2026-007 — &lt;p&gt;&lt;strong&gt;&lt;em&gt;Description&lt;/em&gt;&lt;/strong&gt;: Insufficient inbound packet filtering in Services permitted access to loopbac…</title>
    <updated>2026-10-02T07:59:00.146863+00:00</updated>
    <content>ts-2026-007</content>
    <link href="https://cve.radiocsirt.org/vuln/ts-2026-007"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ts-2026-006</id>
    <title>ts-2026-006 — &lt;p&gt;&lt;strong&gt;&lt;em&gt;Description&lt;/em&gt;&lt;/strong&gt;: Tailscale SSH allowed users to be addressed by numeric UID, bypassing &lt;code&gt;r…</title>
    <updated>2026-10-02T07:59:00.146878+00:00</updated>
    <content>ts-2026-006</content>
    <link href="https://cve.radiocsirt.org/vuln/ts-2026-006"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ts-2026-005</id>
    <title>ts-2026-005 — &lt;p&gt;&lt;strong&gt;&lt;em&gt;Description&lt;/em&gt;&lt;/strong&gt;: Tailscale Serve Unix socket proxy targets were not restricted to &lt;code&gt;root&lt;/…</title>
    <updated>2026-10-02T07:59:00.146892+00:00</updated>
    <content>ts-2026-005</content>
    <link href="https://cve.radiocsirt.org/vuln/ts-2026-005"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ts-2026-004</id>
    <title>ts-2026-004 — &lt;p&gt;&lt;strong&gt;&lt;em&gt;Description&lt;/em&gt;&lt;/strong&gt;: Tailscale SSH Unix socket forwarding did not respect symlink permissions, all…</title>
    <updated>2026-10-02T07:59:00.146909+00:00</updated>
    <content>ts-2026-004</content>
    <link href="https://cve.radiocsirt.org/vuln/ts-2026-004"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ts-2026-003</id>
    <title>ts-2026-003 — &lt;p&gt;&lt;strong&gt;&lt;em&gt;Description&lt;/em&gt;&lt;/strong&gt;: OAuth access tokens recorded in tailnet audit logs.&lt;/p&gt;
&lt;h4&gt;What happened?&lt;/h…</title>
    <updated>2026-10-02T07:59:00.146927+00:00</updated>
    <content>ts-2026-003</content>
    <link href="https://cve.radiocsirt.org/vuln/ts-2026-003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ts-2026-002</id>
    <title>ts-2026-002 — &lt;p&gt;&lt;strong&gt;&lt;em&gt;Description&lt;/em&gt;&lt;/strong&gt;: ACL capability bypass in the Tailscale client's web interface&lt;/p&gt;
&lt;h4&gt;What ha…</title>
    <updated>2026-10-02T07:59:00.146941+00:00</updated>
    <content>ts-2026-002</content>
    <link href="https://cve.radiocsirt.org/vuln/ts-2026-002"/>
  </entry>
</feed>
