Skip to content
Security & Trust

OpenSSH 10.6 arrives as maintainers plan more frequent releases

AI-assisted bug reports and duplicate finds drive the change. The release also alters compression, usernames and post-quantum keys.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
OpenSSH 10.6 arrives as maintainers plan more frequent releases
In brief
  • The OpenSSH team released 10.6 on Oct. 6 and plans more frequent releases, citing many security reports, many found by AI models or with AI help.
  • The release disables a compression method with a known attack, tightens username and path handling, and enables a hybrid post-quantum signature algorithm.
  • Teams should prepare for shorter update cycles and recreate or delete any keys made with the earlier experimental post-quantum support.

Patch cadence is now a security setting

Most organisations treat software updates as housekeeping. The OpenSSH release notes invite a different view: how often you update may belong in your defence plan.

The OpenSSH team shipped version 10.6 on Oct. 6. It said releases will come more often for now. The stated aim is to put bug fixes in users' hands sooner.

The maintainers gave a reason. Security reports have been arriving in volume, they said, many of them found by AI models or with AI help.

Some bugs were later turned up a second time by an unrelated researcher.

The maintainers drew a blunt conclusion. Adversaries who never report bugs to open-source projects, they wrote, "are likely to be able to discover these bugs too."

The maintainers did not say that bugs are now found faster. That step is our inference. Duplicate finds suggest a flaw one person can reach is reachable by others. If so, a slow update cycle leaves a longer gap between a fix existing and your servers having it.

Oct. 6, 2026
OpenSSH 10.6 release date
Source: Help Net Security, reporting the OpenSSH maintainers (October 7, 2026)

What the release actually fixes

The fixes are small and specific. Together they show how many ways a trusted tool can leak data or be steered.

Compression is the clearest case. Fabian Bäumer and Marcus Brinkmann laid out a way to abuse it. An attacker who can feed data into one channel of a session can pull secrets out of another.

The weakness comes from sharing. All channels in a session use one compression dictionary. When strings repeat, the encrypted output changes length, and that length leaks information. Think of guessing what is in a suitcase by watching how far it shrinks under vacuum.

Both the server (sshd) and the client (ssh) now switch off LZ77, the method that squeezes repeated text. The Compression option therefore does less. The maintainers suggest compressing inside the application instead. They say that is typically more effective and is not exposed to this attack.

Quieter gaps, also closed

The ssh client now refuses usernames typed on the command line if they contain a dollar sign or a backslash. The concern is a name from an untrusted source. It could slip commands into a shell through ProxyCommand or Match exec.

Names that come from the User setting inside a configuration file are exempt from the check. The maintainers caution that a filter like this cannot be absolute.

The server now stores GSSAPI credentials only once login succeeds. Before, a failed attempt could leave credentials behind. A later successful login could then expose them.

The sftp tool now checks file paths sent by the server more strictly. Weaker checks had missed cases where a server could make a recursive transfer land outside the destination directory.

ssh-keygen also mishandled Daylight Saving Time. Certificates could carry expiry times that were off by up to one hour.

Up to 1 hour (2 hours in Antarctica/Troll)
Certificate expiry error in ssh-keygen
Source: Help Net Security, reporting the OpenSSH 10.6 release (October 7, 2026)

Older platforms lose features

Three environments are affected: QNX 6, SCO OpenServer 5, and any build compiled with the –disable-fd-passing option. On these systems, the process that handles a user after sign-in does not drop its top-level (root) privileges. OpenSSH therefore turns off GatewayPorts and StreamLocalForwarding there.

The maintainers warn that support for these platforms will be removed in future if no alternative is found. If you run them, treat that as a planning notice.

A key migration hides in the release

Version 10.6 switches on a new signature method, ssh-mldsa44-ed25519. A signature is how a user or server proves who it is. This one pairs a post-quantum scheme with ed25519, an established one.

The catch is operational. Anyone who created keys while the feature was still experimental needs to either recreate or delete them.

Questions to put to your team

First, how fast can we roll out an OpenSSH update across servers, jump hosts and build systems? If the answer is weeks, a shorter release cycle will be hard to keep up with.

Second, do any systems use the Compression option, ProxyCommand or Match exec with usernames from outside sources? Those are the settings these changes touch.

Third, did anyone test the experimental post-quantum keys? If so, list them and plan their replacement.

Fourth, do we run QNX 6 or SCO OpenServer 5? If so, what is the exit plan before support is removed?

The maintainers have told users to expect updates on a shorter cycle. The practical answer is to make updating routine.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Help Net Security.

Share this insight