CVE-2022-41925Active Exploitation(tailscale / tailscale)

LOWCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for tailscale tailscale systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability identified in the Tailscale client allows a malicious website to access the peer API, which can then be used to access Tailscale environment variables. In the Tailscale client, the peer API was vulnerable to DNS rebinding. This allowed an attacker-controlled website visited by the node to rebind DNS for the peer API to an attacker-controlled DNS server, and then making peer API requests in the client, including accessing the node’s Tailscale environment variables. An attacker with access to the peer API on a node could use that access to read the node’s environment variables, including any credentials or secrets stored in environment variables. This may include Tailscale authentication keys, which could then be used to add new nodes to the user’s tailnet. The peer API access could also be used to learn of other nodes in the tailnet or send files via Taildrop. All Tailscale clients prior to version v1.32.3 are affected. Upgrade to v1.32.3 or later to remediate the issue.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tailscale

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
tailscale

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-21: 1Active Exploitation · 2026-03-21: 103-21
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets3 URLs
Full discourse1 post
  • SH TC@shtc_social
    Active Exploitation

    @skyhancloud @caginus27175 @saffetceliktr "Tailscale veya diğer tunneller" bypass edilemez" demek biraz fazla özgüven kokuyor 🙂 Kriptoyu kırmana gerek yok zaten. Real life'de sistemler algoritmadan değil, implementasyondan kırılır. https://cybersecuritynews.com/hackers-actively-exploiting-cloudflare-tunnels/ https://nvd.nist.gov/vuln/detail/CVE-2022-41925 https://nvd.nist.gov/vuln/detail/CVE-2022-41924

    Post summary

    The tweet references a report indicating active exploitation of Cloudflare tunnels for CVE-2022-41925 and CVE-2022-41924, but provides no PoC, exploit code, or technical details.

    1001060
    109 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptailscaletailscale---

Explore more