Tailscale

Security & Privacy

Changelog for the Tailscale mesh VPN.

Latest v1.102.3 · by TailscaleWebsiteRSS

Release activity

Release activity — 28 releases across 23 days since May 28, 2026. Each cell is one day; darker means more releases that day. Nothing is recorded before May 28, 2026. Older weeks are hidden at this screen width.
JunJulAugSep
SundayNo releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026No releases on Aug 16, 2026No releases on Aug 23, 2026No releases on Aug 30, 2026No releases on Sep 6, 2026
Monday1 release on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 20262 releases on Jun 29, 20261 release on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 20261 release on Aug 3, 2026No releases on Aug 10, 2026No releases on Aug 17, 2026No releases on Aug 24, 2026No releases on Aug 31, 2026No releases on Sep 7, 2026
TuesdayNo releases on Jun 2, 2026No releases on Jun 9, 20261 release on Jun 16, 2026No releases on Jun 23, 20261 release on Jun 30, 2026No releases on Jul 7, 20261 release on Jul 14, 2026No releases on Jul 21, 20261 release on Jul 28, 20261 release on Aug 4, 20261 release on Aug 11, 20261 release on Aug 18, 20261 release on Aug 25, 2026No releases on Sep 1, 2026No releases on Sep 8, 2026
WednesdayNo releases on Jun 3, 20261 release on Jun 10, 20261 release on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 20261 release on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 20261 release on Jul 29, 2026No releases on Aug 5, 2026No releases on Aug 12, 20263 releases on Aug 19, 20261 release on Aug 26, 2026No releases on Sep 2, 2026
Thursday1 release on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 20261 release on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026No releases on Aug 13, 2026No releases on Aug 20, 2026No releases on Aug 27, 2026No releases on Sep 3, 2026
Friday2 releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 20261 release on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 20262 releases on Aug 7, 2026No releases on Aug 14, 2026No releases on Aug 21, 2026No releases on Aug 28, 2026No releases on Sep 4, 2026
SaturdayNo releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026No releases on Aug 15, 2026No releases on Aug 22, 2026No releases on Aug 29, 2026No releases on Sep 5, 2026

28 releases since May 28, 2026, busiest day 3

Changelog

Tailscale PAM

Use Tailscale Privileged Access Management (PAM) ( beta ) to provide application-aware access to resources in your Tailscale network. New: Services can be defined for privileged access, including SSH…

Added 1
  • Services can be defined for privileged access, including SSH through Tailscale Privileged Access Management
View originalPermalink
How Tailscale PAM went

Aperture by Tailscale GA

Use Aperture ( generally available ) to secure and manage AI agents and LLM sessions with cost controls, request and response hooks, guardrails, logging, MCP support, and API proxying. New: A promotio…

Added 7
  • Aperture is now generally available for securing and managing AI agents and LLM sessions
  • Cost controls for AI agent and LLM session management
  • Request and response hooks for AI workflows
  • Guardrails for AI agent behavior
  • Logging capabilities for AI sessions
  • Model Context Protocol (MCP) support
  • API proxying for AI services
View originalPermalink
How Aperture by Tailscale GA went
v1.102.3Latest

Tailscale v1.102.3

All Platforms Changed: Go is updated to version 1.26.6. Fixed: Tailscale refuses host-scoped IPv4 destinations at every point that acts on an unmapped 4via6 address. This fix addresses a security vuln…

Changed 1
  • Go is updated to version 1.26.6
Security 1
  • Tailscale refuses host-scoped IPv4 destinations at every point that acts on an unmapped 4via6 address
View originalPermalink
How v1.102.3 went

Tailscale Kubernetes Operator v1.102.3

A new release of the Tailscale Kubernetes Operator is available. For guidance on installing and updating, refer to our installation instructions . Fixed: Peer relays on AWS are reachable regardless of…

Fixed 1
  • Peer relays on AWS are reachable regardless of network configuration
View originalPermalink
How Tailscale Kubernetes Operator v1.102.3 went

Tailscale container image v1.102.3

A new release of the Tailscale container image is available. You can download it from Docker Hub or from our GitHub packages repository . New: The container waits longer for its initial connection to…

View originalPermalink
How Tailscale container image v1.102.3 went

Tailnet list API pagination

Changed: The list tailnets endpoint paginates results. By default, organizations with more than 100 tailnets now receive only the first 100 results, with totalCount and cursor parameters to retrieve a…

Changed 1
  • The list tailnets endpoint now paginates results, returning the first 100 results by default for organizations with more than 100 tailnets, with totalCount and cursor parameters to retrieve additional results
View originalPermalink
How Tailnet list API pagination went

Tailscale Kubernetes Operator v1.102.2

A new release of the Tailscale Kubernetes Operator is available. For guidance on installing and updating, refer to our installation instructions . New: PeerRelays are deployable in-cluster via a custo…

Added 1
  • PeerRelays are deployable in-cluster via a custom resource
View originalPermalink
How Tailscale Kubernetes Operator v1.102.2 went

Tailscale container image v1.102.2

A new release of the Tailscale container image is available. You can download it from Docker Hub or from our GitHub packages repository . This version contains no changes except for library updates.

Changed 1
  • Updated libraries
View originalPermalink
How Tailscale container image v1.102.2 went
v1.102.2

Tailscale tsrecorder v1.102.2

A new release of the Tailscale tsrecorder is available. You can download it from Docker Hub . Fixed: Recorder does not attempt to index empty recording placeholder files on startup.

Fixed 1
  • Recorder does not attempt to index empty recording placeholder files on startup
View originalPermalink
How v1.102.2 went
v1.102.2

Tailscale v1.102.2

All Platforms Fixed: A regression causing incoming Tailscale Funnel connections to fail is resolved.

Fixed 1
  • A regression causing incoming Tailscale Funnel connections to fail is resolved
View originalPermalink
How v1.102.2 went
v1.102.1

Tailscale v1.102.1

All Platforms New: tailscaled_serve_outbound_bytes_total and tailscaled_serve_inbound_bytes_total client metrics report bytes sent to and received from peers on Tailscale Serve connections for Tailsca…

Added 1
  • Add tailscaled_serve_outbound_bytes_total and tailscaled_serve_inbound_bytes_total client metrics to report bytes sent to and received from peers on Tailscale Serve connections
View originalPermalink
How v1.102.1 went

Tailnet creation API

New: Use the tailnet creation API to create, list, and delete API-only tailnets in your organization ( alpha ).

Added 1
  • Use the tailnet creation API to create, list, and delete API-only tailnets in your organization
View originalPermalink
How Tailnet creation API went
v1.98.10

Tailscale v1.98.10

All Platforms Fixed: Tailscale SSH Unix socket forwarding respects symlink permissions. This fix addresses a security vulnerability described in TS-2026-004 . Fixed: Tailscale SSH performs additional…

Fixed 1
  • Tailscale SSH Unix socket forwarding respects symlink permissions
Security 1
  • Fixed security vulnerability TS-2026-004
View originalPermalink
How v1.98.10 went

Admin console URL change

Changed: The Tailscale admin console is now available at console.tailscale.com . Authentication continues to use login.tailscale.com , and requests to login.tailscale.com/admin/ automatically redirect…

Changed 1
  • The Tailscale admin console is now available at console.tailscale.com
View originalPermalink
How Admin console URL change went
v1.98.9

Tailscale v1.98.9

All Platforms Fixed: Tailscale Serve Unix socket proxy targets are restricted to the root user. This fix addresses a security vulnerability described in TS-2026-005 . Fixed: Tailscale SSH does not all…

Security 1
  • Restrict Tailscale Serve Unix socket proxy targets to the root user to address security vulnerability TS-2026-005
View originalPermalink
How v1.98.9 went

Nested group support for synced groups

New: Microsoft Entra ID and Google Workspace group sync includes members of nested groups.

Added 1
  • Microsoft Entra ID and Google Workspace group sync now includes members of nested groups
View originalPermalink
How Nested group support for synced groups went

Self-serve identity provider changes

New: Users with the Owner role can switch their tailnet's identity provider from the admin console for supported providers ( beta ).

Added 1
  • Users with the Owner role can switch their tailnet's identity provider from the admin console for supported providers
View originalPermalink
How Self-serve identity provider changes went

Device Provisioning with OAuth Apps

New: Create and manage OAuth Apps for Device Provisoning with the Tailscale API (alpha) .

Added 1
  • Create and manage OAuth Apps for Device Provisioning with the Tailscale API
View originalPermalink
How Device Provisioning with OAuth Apps went

Public IP address device posture attribute

New: ip:publicAddress device posture attribute is available for use in postures and viewable on the Machines page of the admin console. To test, go to the Settings page of the admin console and toggle…

Added 1
  • ip:publicAddress device posture attribute is available for use in postures and viewable on the Machines page of the admin console
View originalPermalink
How Public IP address device posture attribute went
v1.98.8

Tailscale v1.98.8

Note : 1.98.6 and 1.98.7 were release candidates intended for testing only. All Platforms Fixed: An issue causing connectivity disruptions when the operating system wakes from sleep in wireguard-go is…

Fixed 1
  • An issue causing connectivity disruptions when the operating system wakes from sleep in wireguard-go
View originalPermalink
How v1.98.8 went

Tailnet system policy values

Changed: The Tailnet system policy accepts a comma-separated list of tailnet IDs or organization IDs.

Changed 1
  • The Tailnet system policy now accepts a comma-separated list of tailnet IDs or organization IDs
View originalPermalink
How Tailnet system policy values went

Log streaming integration with Azure Blob Storage

New: Tailscale network flow logs and configuration audit logs can be streamed to Azure Blob Storage .

Added 1
  • Network flow logs and configuration audit logs can be streamed to Azure Blob Storage
View originalPermalink
How Log streaming integration with Azure Blob Storage went

Aperture chat, connectors, and sandboxes

New: Use identity-aware connectors to let agents and users reach your data via MCP and API endpoints ( alpha ). Tailnet access controls apply to every request, giving you one identity system across th…

Added 1
  • Identity-aware connectors allow agents and users to reach data via MCP and API endpoints with Tailnet access controls applied to every request
View originalPermalink
How Aperture chat, connectors, and sandboxes went

Group visibility on Tailscale clients

New: Configure devices on your tailnet to receive group membership information from the Tailscale control plane ( alpha ).

Added 1
  • Configure devices on your tailnet to receive group membership information from the Tailscale control plane
View originalPermalink
How Group visibility on Tailscale clients went
v1.98.5

Tailscale v1.98.5

All Apple Platforms Changed: macOS and iOS clients are now built using the Xcode 26.5 toolchain.

Changed 1
  • macOS and iOS clients are now built using the Xcode 26.5 toolchain
View originalPermalink
How v1.98.5 went

Preset app support for Oracle Cloud Infrastructure (OCI)

New: Preset apps are available for Oracle Cloud Infrastructure (OCI) , including per-region compute and networking, per-region Object Storage, and a global preset for the Oracle Services Network (OSN)…

Added 1
  • Preset apps are now available for Oracle Cloud Infrastructure (OCI), including per-region compute and networking, per-region Object Storage, and a global preset for the Oracle Services Network (OSN)
View originalPermalink
How Preset app support for Oracle Cloud Infrastructure (OCI) went

Tailscale Kubernetes Operator v1.98.4

A new release of the Tailscale Kubernetes Operator is available. For guidance on installing and updating, refer to our installation instructions . Fixed: The operator no longer fails to perform token…

Fixed 1
  • The operator no longer fails to perform token operations
View originalPermalink
How Tailscale Kubernetes Operator v1.98.4 went

Tailscale v1.98.4

All Platforms Fixed: An issue causing a deadlock when processing peer changes and disconnecting from the Tailscale control server is resolved.

Fixed 1
  • An issue causing a deadlock when processing peer changes and disconnecting from the Tailscale control server
View originalPermalink
How Tailscale v1.98.4 went
View all

Discussion