• Sources: Tailscale TS-2026-009, HN 48915004
  • Summary: Tailscale published bulletin TS-2026-009 on 2026-07-13 for an argument-injection flaw in Tailscale SSH. The feature allowed usernames with leading hyphens, which were passed to getent(1) and interpreted as command-line flags. A principal already permitted in the tailnet ACL who connected with the username -i could make getent print the entire passwd file starting with root. It is fixed in version 1.98.9, which rejects usernames with leading dashes. No CVE was assigned and Tailscale reports no evidence of exploitation. The same day Tailscale disclosed TS-2026-008, a CPU-exhaustion flaw in Serve and Funnel triggered by malformed HTTP requests.
  • Comments: HN commenter tptacek noted the bug is a venerable class going back to AIX 3. Another argued the proper fix is to separate arguments with -- rather than only rejecting leading-dash usernames.
  • Why it matters: Tailscale SSH is a drop-in alternative to OpenSSH inside a tailnet, so an operator who enabled it exposed local account data to anyone already authorized to connect.

send feedback on this story