OpenSSH 10.6, released October 6, enables the hybrid post-quantum signature algorithm ssh-mldsa44-ed25519. Keys generated with earlier experimental support must be regenerated or removed. The maintainers say they will ship releases more often for now after receiving a large number of security reports, many found by AI models or with AI help, and in several cases the same bug was independently found later by a different researcher. They warn that adversaries who do not report bugs to open-source projects are likely able to discover these bugs too.

Both the server and client now disable the LZ77 dictionary coder, making the Compression option less effective. This follows an attack described by Fabian Bäumer and Marcus Brinkmann in which someone who controls input on one channel can recover secrets from another, because every channel in a session shares one compression dictionary and repeated strings change ciphertext length. The maintainers recommend application-level compression, which they say is typically more effective and immune to this attack.

Other fixes include refusing command-line usernames containing a dollar sign or backslash, since an untrusted name could inject into a shell context through ProxyCommand or Match exec; names set with the User directive are exempt. sshd now stores GSSAPI credentials only after authentication succeeds, sftp validates server-returned paths more strictly, and ssh-keygen no longer mishandles Daylight Saving Time when setting certificate expiry. The maintainers note that mitigations like the username check cannot be absolute.