What changed
OpenSSH 10.6 was released on October 6, 2026. It enables the hybrid ssh-mldsa44-ed25519 signature algorithm, combining ML-DSA-44 with Ed25519. The project also disables the LZ77 dictionary coder used by ssh and sshd compression to mitigate side-channel information leakage, reducing the effectiveness of the Compression option. The scp -R mode for copying between two remote hosts is deprecated because of security risks and is intended to be ignored in a future release. OpenSSH also says a large volume of AI-assisted security reports is leading it to make more frequent releases rather than batch fixes for the next planned version.
Why it matters
SSH sits underneath routine server administration, CI/CD and automated infrastructure access, so changes to its cryptographic and transport defaults have a wide operational blast radius. Post-quantum signatures move another everyday infrastructure protocol toward hybrid cryptography without requiring operators to invent their own scheme. Disabling the compression dictionary deliberately trades compression efficiency for a tighter side-channel boundary, while scp -R deprecation matters to scripts that still depend on remote-to-remote copies.
Hybrid post-quantum signatures become available by default
OpenSSH 10.6 enables ssh-mldsa44-ed25519, a hybrid signature that combines ML-DSA-44 with Ed25519. Hybrid construction keeps a conventional signature alongside the post-quantum algorithm rather than betting the authentication path on a single newer primitive.
Compression gives up efficiency for a smaller side-channel surface
The LZ77 dictionary coder in ssh and sshd is disabled. Compression still exists, but the change reduces how much repeated-data history can influence compressed output, at the cost of less effective compression.
scp -R is on the way out
The remote-to-remote scp -R mode is deprecated on security grounds. Operators with automation that copies directly between two remote systems should identify those workflows before a later OpenSSH release ignores the option.
AI-assisted vulnerability reports are changing release cadence
The OpenSSH project says it is receiving many AI-assisted security reports and welcomes them when paired with human triage, analysis, tests and especially fixes. Rather than accumulate verified fixes for scheduled releases, it expects to release more frequently.