OpenSSH 10.6 Patches a 30-Year Compression Flaw and Enables Post-Quantum Cryptography by Default

OpenSSH 10.6 shipped on October 6, 2026, and it closes a compression-related side-channel that has been lurking in SSH implementations for decades, while also pushing forward on post-quantum cryptography. For anyone running servers or managing infrastructure, this is a meaningful update worth deploying promptly.

The Compression Flaw

The headline security fix is the removal of the LZ77 dictionary coder used for SSH compression. LZ77-based compression is vulnerable to a chosen-plaintext side-channel attack: when attacker-controlled data and secret data share the same compression context, observable differences in compressed size can leak information about the secret data. This class of attack — sometimes called CRIME or BREACH in the TLS world — has been known since at least 2002, but SSH compression remained enabled as an option in many deployments. OpenSSH 10.6 disables it entirely rather than leaving it as a footgun for administrators to misconfigure.

SFTP also gets tighter path validation to prevent a malicious server from using recursive copy operations to write files outside the intended destination directory — a traversal-style bug that affected some copy workflows.

Post-Quantum Cryptography Moves Forward

OpenSSH 10.6 enables the hybrid post-quantum signature algorithm ssh-mldsa44-ed25519 by default. This pairs the ML-DSA lattice-based algorithm (standardized by NIST in 2024) with the established Ed25519 for a hybrid scheme that is secure if either algorithm holds — defense in depth against a future cryptographically-relevant quantum computer.

The server also gains a new WarnWeakCrypto option, enabled by default, which logs connections using key exchange methods that aren't considered post-quantum safe. This gives administrators visibility into clients still negotiating classical-only key exchanges, which is particularly useful in environments beginning a migration to quantum-resistant cryptography.

Quality-of-Life Changes

The release notes list a few smaller but welcome additions: SFTP now supports mkdir -p for recursive directory creation (something that required workarounds before), and ChannelTimeout now accepts fractional-second values for finer-grained control over idle connection handling. Usernames supplied directly on the ssh command line can no longer contain $ or \, reducing shell-injection risks in setups using ProxyCommand or Match exec.

Faster Release Cadence Going Forward

The project noted that it expects to move to more frequent releases rather than batching fixes until the next planned major version. This is a welcome shift — OpenSSH occupies such critical infrastructure that sitting on security fixes for months to maintain a stable release schedule has real costs. Shorter cycles mean patches reach users faster.

Should You Update?

Yes, and soon. The compression side-channel fix alone is reason enough, particularly for deployments where SSH compression is enabled and external parties can influence any portion of the encrypted traffic. The post-quantum additions are forward-looking rather than urgent — no cryptographically-relevant quantum computer exists yet — but they're increasingly relevant as organizations begin planning quantum-resistant infrastructure. Most major Linux distributions will have packages available within days of the upstream release.