Executive brief
TSDProxy, a tool used to manage Tailscale-based proxy services, contains a vulnerability where it accidentally shares its internal administrative password with the very services it is supposed to be protecting. If an attacker can control or compromise one of these backend services, they can steal this password and use it to take over the entire TSDProxy management system. This allows the attacker to shut down services, view private network configurations, or redirect traffic, potentially leading to a total loss of control over the proxy infrastructure.
Technical details
A vulnerability in TSDProxy's request rewriting logic causes the internal `x-tsdproxy-auth-token` to be injected into upstream HTTP requests sent to backend services when `identityHeaders` is enabled. This token is the same secret used by the management HTTP server to authenticate administrative requests from localhost. An attacker with the ability to observe headers on a proxied backend service can capture this token and replay it to the TSDProxy management port (typically 127.0.0.1:8080) along with a spoofed `x-tsdproxy-id` header. This bypasses Tailscale authentication and grants the attacker full administrative access to the management API, including the ability to enumerate proxies, trigger webhooks (SSRF), and modify service states. The issue is fixed in version 1.4.4-0.20260603142855-434819b4421e.
Affected products
- almeidapaulopt TSDProxy < 1.4.4-0.20260603142855-434819b4421e
Timeline
- 2026-06-03: patched: First patched version released
- 2026-07-10: disclosed: Advisory published on GitHub