Vulnerability
Published 2026-10-06
Verified 2026-10-07

OpenSSH 10.6 (6 Oct): turns off the shared LZ77 compression dictionary after the "Crossing the Streams" plaintext-recovery research, tightens SFTP client path checks against malicious servers, and blocks $ and \ in command-line usernames to stop shell injection

OpenSSH 10.6 / 10.6p1 was released on 6 October 2026 with a batch of security fixes for both the ssh client and the sshd server. The headline change disables the LZ77 dictionary coder in compression: researchers Fabian Bäumer and Marcus Brinkmann showed in "Crossing the Streams" that, when compression is on, all channels in one SSH connection share one compression dictionary, so an attacker who can feed chosen text into one channel and watch ciphertext lengths can recover secrets carried in another channel. Compression still works but is less effective. The sftp client now validates paths returned by a server more strictly, so a malicious server can no longer steer a recursive download into writing outside its target folder (reported by Junghoon Cho). The ssh client now refuses destination usernames containing $ or \ on the command line, because usernames from untrusted sources could reach a shell through ProxyCommand or Match exec (reported by KeenLab Tencent); usernames set with the User directive in config files are not restricted. Other fixes cover GSSAPI credentials from a failed attempt persisting into a later login, the authorized_keys "restrict" keyword not applying to tunnel forwarding, compressed packets inflating past the size limit, and a root-privileged session process on old platforms without file-descriptor passing (GatewayPorts and StreamLocalForwarding are now forced off there). The OpenSSH team says it is getting many AI-assisted bug reports, has seen AI-found bugs rediscovered independently, and will ship releases more often. The release notes assign no CVE numbers or CVSS scores. Primary: OpenSSH 10.6 release notes; wire: Cyber Security News (7 Oct).

Product
OpenSSH (ssh, sshd, sftp, ssh-keygen)
Versions
OpenSSH 10.5 and earlier (fixed in 10.6 / 10.6p1). Distribution packages will carry their own backport versions.
CVSS
Not assigned in the release notes
Exploited in Australia?
unknown
Patch to
Upgrade to OpenSSH 10.6 / 10.6p1, or your distribution's patched package when it ships. Until then, leave SSH compression off for connections that mix trusted and untrusted traffic (it is off by default in recent releases), use application-level compression instead, only run recursive sftp downloads from servers you trust, and never build ssh command lines from untrusted input such as usernames from a web form.

Primary: OpenSSH — Release notes, OpenSSH 10.6/10.6p1 (6 Oct 2026) · Vendor: Bäumer and Brinkmann — Crossing the Streams: SSH plaintext recovery via a common compression context in multiplexed channels (arXiv preprint) · Cyber Security News — Multiple OpenSSH vulnerabilities could enable plaintext recovery, file write and injection attacks (7 Oct 2026)

vulnerabilities network