OpenSSH 10.6 Fixes Critical Flaws in Compression, SFTP, and Username Handling
OpenSSH 10.6, released October 6, 2026, addresses three critical vulnerabilities that could lead to plaintext recovery, arbitrary file writes, and shell injection.

OpenSSH 10.6, released on October 6, 2026, addresses a trio of critical security vulnerabilities affecting both its client and server components. These flaws could potentially expose sensitive secrets through traffic analysis, allow malicious SFTP servers to write files outside designated directories, and enable shell injection attacks under specific circumstances.
The most intricate of the vulnerabilities, dubbed "Crossing the Streams," involves the LZ77 compression algorithm used in SSH. When compression is enabled, different channels within a single SSH connection share a compression dictionary. Researchers Fabian Bäumer and Marcus Brinkmann demonstrated that an attacker capable of injecting chosen text into one channel and observing encrypted traffic lengths could infer secrets transmitted through another channel. This exploit leverages information leakage from the compression process before encryption, rather than breaking SSH's encryption itself. While the researchers achieved an eight-character secret recovery with a limited number of guesses under specific test conditions, the OpenSSH developers have mitigated this by disabling the LZ77 dictionary coder in both ssh and sshd. Compression remains available but is now less effective, with a recommendation to use application-level compression instead of sharing SSH compression between trusted and untrusted traffic.
A second critical flaw addressed in OpenSSH 10.6 concerns the handling of paths returned by SFTP servers. Previously, a malicious SFTP server could manipulate paths to trick the SSH client into writing files outside of the intended destination directory during recursive copy operations. This vulnerability, reported by Junghoon Cho, impacts the client's interpretation of server responses and could allow an attacker controlling an SFTP server to overwrite arbitrary files on the client system. The fix strengthens the validation of paths provided by the server to prevent such out-of-bounds writes.
The third significant vulnerability patched in this release targets shell injection risks associated with untrusted usernames. The update introduces filtering for dollar signs and backslashes in destination usernames provided via the SSH command line. In certain configurations, these characters could be passed to shell contexts through features like ProxyCommand or Match exec, leading to command injection. While the developers note that character filtering cannot entirely eliminate all shell injection risks, especially when untrusted input is directly passed to SSH command lines, this measure significantly enhances security for common use cases. This fix is distinct from earlier username and ProxyJump related security patches.
Beyond these three primary vulnerabilities, OpenSSH 10.6 also includes fixes for GSSAPI credential handling, tunnel restrictions, oversized decompressed packets, and certificate date conversion. On older platforms like QNX 6 and SCO OpenServer 5, forwarding options tied to retained root privileges have been disabled. Administrators are advised to review these changes, particularly if compression or forwarding features are critical to their operations.
The release notes emphasize that while AI is accelerating vulnerability discovery, human review and robust testing remain essential for validating security reports and proposed fixes. The developers also indicated plans for more frequent releases to address the increasing volume of AI-assisted vulnerability disclosures.
This update underscores the ongoing need for vigilance in maintaining secure remote access infrastructure. The combination of subtle information leakage through compression, path manipulation in file transfer protocols, and injection flaws highlights the diverse attack vectors that threat actors continue to explore against widely used security tools like OpenSSH.