Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Tailscale/
  3. Tailscale

Tailscale

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 11 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

WireGuard-based zero trust mesh networking platform for secure connectivity.

by Tailscale · tailscale.com · source ↗

Known CVEs (11)1 newAbout this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-64175 ↗HIGH 7.5new2026

    In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: stop TX during firmware restart When iwlwifi firmware crashes (e.g., NMI_INTERRUPT_UNKNOWN on Intel BE201/Wi-F…

  • CVE-2026-57999 ↗HIGH 8.82026

    luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability ex…

  • CVE-2026-41687 ↗MEDIUM 4.32026

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.8.1, the SSRF protection in endpoints/subscription/add.php (line 42) and endpoints/payments/add.php (line 40) …

  • CVE-2026-41913 ↗LOW 3.72026

    OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent asynchronous requests to bypass the per-key rate-limit budget. Attackers can exp…

  • CVE-2026-30976 ↗HIGH 8.62026

    Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any file readable by the Sonarr process. Th…

  • CVE-2026-30975 ↗HIGH 8.12026

    Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled authentication for local addresses (Authentication Re…

  • CVE-2026-32045 ↗MEDIUM 5.92026

    OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and password requirements. Attackers on trusted networ…

  • CVE-2025-29266 ↗CRITICAL 9.62025

    Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication if a container is running in Host networking mode with Use Tailscale enabled.

  • CVE-2023-28436 ↗MEDIUM 5.72023

    Tailscale is software for using Wireguard and multi-factor authentication (MFA). A vulnerability identified in the implementation of Tailscale SSH starting in version 1.34.0 and prior to prior to 1.38…

  • CVE-2022-41925 ↗HIGH 8.82022

    A vulnerability identified in the Tailscale client allows a malicious website to access the peer API, which can then be used to access Tailscale environment variables. In the Tailscale client, the pee…

  • CVE-2022-41924 ↗CRITICAL 9.62022

    A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can then be used to remotely execute code. In the Tailscal…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other VPN products

see all →
  • AVG Secure VPN · AVG
  • Array AG Series SSL VPN Remote Access · Array Networks
  • Aviatrix High-Performance Encryption · Aviatrix
  • Avira Phantom VPN Pro · Avira
  • CYSEC ARCA SATCOM VPN · CYSEC
  • Cloudbric VPN · Cloudbric
  • Cohesive VNS3 People VPN · Cohesive Networks
  • CyberGhost VPN · CyberGhost