OpenSSH 10.6 was released on October 6, 2026, with security fixes for several vulnerabilities that could expose sensitive information, allow files to be written outside their intended locations, or lead to shell injection in certain configurations.
The update affects both OpenSSH client and server components, making it important for organizations and users that depend on SSH for remote administration, secure connections, and file transfers.
The vulnerabilities have different attack requirements and do not represent one universal attack against every OpenSSH installation. The main issues involve SSH compression, SFTP path handling, and usernames that may be passed into shell commands.
SSH Compression Flaw Could Expose Secrets
Researchers Fabian Bäumer and Marcus Brinkmann detailed the compression-related issue in their research paper, Crossing the Streams.
The problem occurs because multiple channels inside the same SSH connection can share a compression dictionary when compression is enabled. An attacker who can control data sent through one channel and observe changes in encrypted traffic sizes may be able to gather information about secrets being transferred through another channel.
The weakness is related to the way LZ77 compression works. Repeated data is replaced with references to information that has already appeared. If attacker-controlled content matches part of a secret, the compressed data can become smaller, creating a measurable difference in traffic size.
This does not mean that SSH encryption itself has been broken. Instead, information about the encrypted content can leak through compression behavior before the data is encrypted.
In one low-noise test conducted by the researchers, an eight-character secret using a 26-letter alphabet could be recovered in as many as 276 guesses. However, this result depends on the specific testing conditions and should not be considered a guaranteed recovery method for all SSH connections.
OpenSSH 10.6 addresses the problem by disabling the LZ77 dictionary coder in both ssh and sshd. Compression is still supported, but its effectiveness is reduced. OpenSSH developers recommend using compression at the application level when possible instead of sharing SSH compression between trusted and untrusted traffic.
SFTP and Username Injection Issues
OpenSSH 10.6 also improves security around SFTP path handling.
The update changes how paths returned by an SFTP server are handled. Previously, a malicious server could potentially return specially crafted paths that caused a recursive copy operation to write files outside the directory originally selected by the client.
This issue affects how the SSH client processes responses from an SFTP server. It does not mean that an unauthenticated attacker can simply write files to any SSH server.
Another security fix addresses usernames supplied through the SSH command line. OpenSSH 10.6 now blocks dollar signs and backslashes in destination usernames.
Under certain configurations, an attacker-controlled username could reach shell commands through features such as ProxyCommand or Match exec, potentially creating a shell injection condition.
The issue was reported by SecBuddyF KeenLab Tencent. The new restriction applies to usernames supplied through the command line, while usernames configured through the User option in configuration files are not affected by this particular check.
OpenSSH developers also point out that character filtering alone cannot protect every possible shell environment. Applications should therefore avoid placing untrusted input directly into SSH command lines.
Additional Security Improvements in OpenSSH 10.6
Beyond the three major issues, OpenSSH 10.6 includes several other security and reliability improvements.
The release addresses problems involving GSSAPI credentials, tunnel restrictions, oversized decompressed packets, and certificate date conversion. On some older operating systems, including QNX 6 and SCO OpenServer 5, certain forwarding options have also been disabled because of risks associated with retained root privileges.
For administrators, the release is a reminder that SSH security involves more than strong encryption and authentication. Features such as compression, forwarding, SFTP operations, and command-line processing can also introduce security risks when they interact with untrusted input.
Organizations using OpenSSH should review the release and plan their upgrades, particularly if their environments use SSH compression, SFTP transfers, proxy commands, or forwarding features.
OpenSSH maintainers have also indicated that releases may become more frequent as AI-assisted vulnerability research leads to more security reports. Human review, testing, and validation will remain important to determine whether reported issues are genuine and how they should be fixed.