Last 7 days
1
Features: 0
Changes: 1
Fixes: 0
Deprecations: 0
Identity-based private networking service built on WireGuard.
Latest Tailscale changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this Tailscale release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
1
4
7
27
No detailed release notes provided in this entry.
Changelog details not included in the input.
Changelog details not included in this entry.
No specific changes listed; refer to the provided URL for details.
Changelog details are available at https://tailscale.com/changelog.
No specific changes listed in this entry.
No detailed release notes provided in this entry
No detailed release notes provided for v1.98.3.
Changelog details not included in this entry.
No detailed changelog provided in this entry.
No detailed changelog provided in this entry.
No detailed changes provided in this entry.
Changelog details not included in this entry.
No detailed changes provided in this entry; see the official Tailscale changelog for v1.94.1.
Changelog details not included in this entry.
No detailed change entries provided in this release.
Version bump to v1.92.2 with no detailed changes listed.
Refer to the official changelog for detailed release notes.
Changelog details are available online.
Refer to the official Tailscale changelog for the complete list of updates in v1.90.8.
No specific changes listed in this entry
No specific change details provided in this entry
No change details provided in this release note.
Changelog details are not included; refer to the provided link for full release notes.
No detailed release notes provided; refer to the official changelog.
No specific changes described in this release note.
- No inline changes are listed in this entry
Changelog details are hosted externally; see the provided URL for the full list of changes.
Release v1.86.0 announced; details are available via the official changelog link
No specific change details are provided in this entry.
No specific change details are provided in this entry.
Refer to the official Tailscale changelog for v1.84.0 details.
No specific changes listed in the provided text.
Refer to the official Tailscale changelog at https://tailscale.com/changelog for v1.82.0 details.
No specific changelog details provided; see external link for full list.
No specific changes detailed in this entry.
No specific changes listed for this release; refer to the official changelog for details.
Changelog details are not included in the request.
No specific changes provided in this release note.
Check the official Tailscale changelog for v1.78.0 details.
No specific changes detailed in this entry.
No specific changes detailed in this entry.
No specific change details were provided in the supplied text.
Changelog details not provided; refer to the official Tailscale changelog page.
Changelog for version v1.74.0 is available at https://tailscale.com/changelog.
No change details provided in the entry; refer to the external Tailscale changelog.
Changelog details are not provided in the request.
Introduced AllowedSuggestedExitNodes policy and auto:any exit-node selection for Enterprise, with CLI and UI improvements for exit-node handling.
Fixed tailnet lock validation to allow multiple nodes signed by the same pre‑signed reusable auth key.
Fixed 4via6 subnet router advertisement across all platforms.
Added container auto‑updates (including ignoring the tailnet default) and ensured updates apply even when a node is down; upgraded build to Go 1.22.4.
Restores UDP connectivity on all platforms when using Mullvad exit nodes.
Internal release
Android UI and VPN behavior refined (Quick Settings title restored, improved connection logic, mutable VPN status notification that can be disabled) and platform‑wide bug fixes (login URLs display, exit‑node button color, container secre...
Add netfilter mode, SNAT subnet routes, and stateful filtering flags to the Linux `tailscale set` command.
Added client‑side quarantining and a stateful‑filtering flag to mitigate TS‑2024‑005, which may break setups that forward external traffic
Windows installers are now built with the WiX 3.14.1 toolchain, incorporating recent WiX security updates.
Fixes a startup freeze that occurred when cleaning unused routes
Added macOS Standalone support for Tailscale SSH, nc, and Internet Access Policy integration with Little Snitch; new alerts for client‑preference errors
Added new Linux capability to send a load‑balancing hint HTTP request header.
Added ACL‑based access control to the web interface, introduced a new macOS .pkg installer, and expanded support for custom control servers, Kubernetes ingress, and Mullvad family‑friendly DoH server
Fixed port 8080 exposure to other devices on the tailnet across all platforms.
Updated all platforms to build with Go 1.22 and improved authentication flows, including a persistent login page after inactivity.
Fixed app connectors scheduling and route merging issues across all platforms
Improved app connectors scheduling and merging of route changes under certain conditions
Improved portmap handling across platforms, increased 4via6 site IDs to 65,536, and resolved a portmap response bug that paused the 1.58.0 rollout;
Added a security fix for privilege escalation in Tailscale Serve and Funnel on Windows 7/8.
Fixed web UI redirect to the correct self IP on Linux
Improved responsiveness under load, added a new `tailscale whois` subcommand, and enabled System Policies beta on Linux.
Fixed stability issue on macOS when setting an existing system policy value to nil.
Updated all platforms to Go 1.21.4 and boosted Linux UDP‑over‑TUN throughput on recent kernels.
Fixed incompatibility with other software using wintun NAS on Windows.
Background certificate renewal and auto‑update flags added for all platforms with UI notifications for newer client versions
Fixed multiple container‑related issues: serve config loss (#9558), tailnet lock signing failure (#9539), and a potential UPnP crash.
Added numerous features including Wikimedia DNS-over-HTTPS, first‑class tvOS support, Fast User Switching, Siri shortcuts, UI enhancements for Mullvad exit nodes, and improved Tailnet Lock.
Improved stability for Mullvad exit nodes
Fix nftables/ufw interaction on Linux that blocked subnet‑routed traffic
Added Tailscale Lock beta, new exit‑node, funnel, and serve subcommands with interactive web UI prompts
Fixed Tailnet lock signature verification across all platforms
Fix Android issue where device name always showed as 'localhost'.
Fix custom HTTP port handling in Tailscale Serve on all platforms
Added remote port forwarding for Tailscale SSH, HTTP support in Tailscale Serve, recursive DNS resolution, and usernames up to 256 characters;
Drop support for Windows 7/8, Windows Server 2008/2012, and older macOS versions; future releases will not install on them (breaking change).
Added LDAP and other user support for Tailscale SSH on Linux, including local SSH session recording
Dropped support for older OS versions (Windows 7/8, Server 2008/2012, macOS 10.13‑10.14) and updated UI labels (macOS Settings, Windows migration robustness).
Upgrade Go runtime to 1.20.3, fixing CVE‑2023‑24536, CVE‑2023‑24537, and CVE‑2023‑24538 to prevent DoS attacks on DNS over HTTPS, Funnel, and PeerAPI.
Funnel is now in beta with trimmed mount point prefixes and corrected X‑Forwarded‑For IP handling
Rename `tailnet lock tskey wrap` to `tailnet lock sign` on all platforms
Added new debug commands (portmap, derp, capture), a configure helper, and overhauled serve with Funnel as a separate command; tailnet lock now works with preauth keys.
v1.38.0 tag exists but no official binaries were released; developers can build from the tag themselves
Fixed exit node usage on macOS when acting as an exit node
Resolved a potential infinite loop when a node key expires on all platforms.
Added extensive JSON output options, node expiry handling, UPnP port mapping for HA gateways, and support for arbitrary IP protocols (EOIP, GRE).
Fixed Linux handling of many SplitDNS domains when using an exit node
- Fixed Windows Tailscale SSH issues and common case failures.
Added a third “4via6” DNS option with punycode display, plus new CLI commands `tailscale set` for config tweaks and `tailscale lock` for tailnet locking.
Patch Windows client remote code execution vulnerability (CVE‑2022‑41924).
Fixed intermittent DNS resolution issue affecting Android devices
Fix high CPU usage issue on macOS
Fix NextDNS IP fragmentation handling for exit nodes and improve network checks (IPv6 ICMP echo, captive portal detection)
Fixed handling of IPv6-mapped IPv4 addresses in STUN responses.
Fixed exit node handling in tun=userspace mode when IPv6 is unavailable, preventing Chrome 104+ breakage.
Added new platform support and capabilities, including native ARM backend, OpenBSD hybrid netstack subnet routing, macOS variant reporting, DNS‑over‑HTTPS for Mullvad, and ability for clients to use Noise on any HTTPS port.
MagicDNS now returns SERVFAIL on upstream failures and adds TCP support; Android can act as an exit node and ExitNodeStatus is exposed in status JSON.
All platforms: prevent tailscaled restarts while a mosh server is active from an SSH session.
Added PeerAPI ping, Wake‑on‑LAN, LoginInteractive support, timeout flag for `tailscale up`, and a standalone macOS client with MagicDNS (including Split DNS) and iOS bug‑report UI.
Fixed HTTP proxy handling across all platforms, including Synology-specific issues
Fix two control‑plane connection failures on all platforms
Improved netstack performance with GC tuning and defaulted to userspace networking mode on gokrazy; set tailscale0 link speed to UNKNOWN
Fix a potential crash on Linux at startup when BGP is used
Improve gokrazy compatibility
Added DERP Return Path Optimization and an in‑memory state mode, plus a TS_PERMIT_CERT_UID env var for TLS certificate fetching
Fixed DNS lookups through exit nodes in many scenarios.
Fixed the Synology options page UI issue on Synology platforms.
Fix memory footprint growth in userspace networking mode.
Resolve potential deadlock in DERPmap handling
Added exit‑node DNS forwarding and unified SOCKS5/HTTP proxy on a single port, with subnet‑router and userspace networking support.
Exit node selection applies almost immediately and Linux now permits non‑TCP/UDP protocols when allowed by ACLs.
Fix regression on specific kernel configs caused by direct netlink usage
Added platform‑independent UPnP discovery, AWS SSM state storage, Prometheus metrics endpoint, and iOS DNS‑over‑HTTPS concurrency improvements.
Fixed UPnP discovery issues on specific Wi‑Fi routers such as eero.
Fixed DISCO key mapping bug that could misinterpret multiple possible nodes, restoring reliable connectivity.
Added secret‑based node state storage and new tailscale up options (authkey from file, QR codes) across all platforms
Added alternate Let’s Encrypt ISRG Root X1 for TLS fallback and noted the requirement to run as root
No publicly released changes for version 1.14.5.
On Windows, state files are now stored in C:\ProgramData instead of C:\Windows to improve compatibility with Windows Updates.
`tailscale up` now waits for the tailscaled socket instead of exiting, removing the need for looped retries.
Added PCP response support to NAT PMP with UPnP fallback for better port‑mapping and direct connectivity, reducing DERP reliance.
Added Synology-specific build for updating to version 1.9.156 in the Synology Package Center.
Fix iOS memory-related crashes (issue #2566)
Fixed crash caused by oversized EDNS packets (issue #2533).
Added DNS‑over‑HTTPS for MagicDNS, UPnP portmapper support, EDNS clamping and WSL2 DNS improvements.
Linux Tailscale now reliably saves preferences; run `tailscale down` before updating and `tailscale up` after to avoid issue 2321.
Fixed a data race that could crash the backend under heavy load.
Bugfix and stabilization release: deforked wireguard-go, tailscale ping now returns non‑zero on no direct connection, MTU can be set via TS_DEBUG_MTU, and fixes for DNS server usage across Linux, macOS, iOS, Android.
Fixed issue 1996 affecting Windows clients
Communicate all login errors to the Tailscale web UI (fix #1939).
Fixed issue #1963 by initializing DNS maps unconditionally
Ensure Magic DNS consistently answers queries to 100.100.100.100 (fixes #1886)
Resolve issue #1892 causing problems with systemd-resolved integration
Add stable PeerStatus.ID to Tailscale status JSON
Fixed DNS application on older NetworkManager versions on Linux
Added new CLI commands (ping tsmp, ip, bugreport, logout) and enabled Windows, macOS, Linux, and Synology to serve as subnet routers and exit nodes via the CLI; SOCKS5 proxy now works for all addresses
Added exit node routing, IPv6 tunnel support, NAT‑PMP port mapping, userspace networking (tun=userspace) and a built‑in SOCKS5 server.
Fix Windows connectivity failure
Added ping support for MagicDNS virtual IP, improved Linux router resilience with error handling and IPv6 route monitoring.
Fixed DERP reader hang regression in wgengine/magicsock during concurrent reads
Fix Tailscale failing to reconnect to home DERP after network changes.
Fixed Linux IPv6 probing and clarified the “IPv6 disabled” log message.
Fix accidental rate limiting of connectivity debug logs on all platforms
MagicDNS now shows device names in GUIs and status, status output is sorted and more readable, and Linux requires sudo for `tailscale up` while adding systemd notify support.
Added MagicDNS embedded DNS server, Windows unattended mode, new DERP servers, and enhanced ACL editor with syntax highlighting
Fixed NAT traversal and connectivity issues, improving reliability, reducing CPU usage, and enhancing logging.
New release v0.100.0-153 is now available.
Fixed tailscaled crash on Linux when interacting with older iproute2 versions (issue 434)
Introduced “Shields Up” mode to block all inbound connections while allowing outbound, with UI checkbox on Windows/macOS/iOS.
Added IPv6‑preferred routing, MTU adjustments, and enhanced network‑change handling plus DERP fallback (including a new Sydney relay) for more reliable connections