In my experience it is really very quick and easy to get a CVE if you contact MITRE directly, and on paper you do not need to disclose too much. The GitHub CNA is (ironically) very slow by comparison but that is a GitHub issue.
Tailscale can also just apply to be their own CNA and issue CVEs for their products themselves, eliminating any such issues entirely.
Tailscale can also just apply to be their own CNA and issue CVEs for their products themselves, eliminating any such issues entirely.