Key details

  1. OpenSSH 10.6 was released October 6, 2026.
  2. The hybrid ssh-mldsa44-ed25519 signature algorithm is enabled.
  3. The LZ77 dictionary coder is disabled in ssh/sshd compression to mitigate side-channel leakage.
  4. Compression may therefore be less effective.
  5. scp -R remote-to-remote copying is deprecated and is planned to be ignored in the future.
  6. OpenSSH says AI-assisted security reports are contributing to a more frequent release cadence.

What builders should take away

  1. Inventory scripts that depend on scp -R before its future removal changes behaviour.
  2. If SSH compression matters on constrained links, test 10.6 rather than assuming previous compression ratios.
  3. Treat hybrid post-quantum authentication as an interoperability change: confirm both ends and policy tooling understand the algorithm before requiring it.
  4. For AI-assisted vulnerability reporting, OpenSSH's message is clear: human triage, reproducibility, tests and fixes matter more than raw generated reports.

What changed

OpenSSH 10.6 was released on October 6, 2026. It enables the hybrid ssh-mldsa44-ed25519 signature algorithm, combining ML-DSA-44 with Ed25519. The project also disables the LZ77 dictionary coder used by ssh and sshd compression to mitigate side-channel information leakage, reducing the effectiveness of the Compression option. The scp -R mode for copying between two remote hosts is deprecated because of security risks and is intended to be ignored in a future release. OpenSSH also says a large volume of AI-assisted security reports is leading it to make more frequent releases rather than batch fixes for the next planned version.

Why it matters

SSH sits underneath routine server administration, CI/CD and automated infrastructure access, so changes to its cryptographic and transport defaults have a wide operational blast radius. Post-quantum signatures move another everyday infrastructure protocol toward hybrid cryptography without requiring operators to invent their own scheme. Disabling the compression dictionary deliberately trades compression efficiency for a tighter side-channel boundary, while scp -R deprecation matters to scripts that still depend on remote-to-remote copies.

Hybrid post-quantum signatures become available by default

OpenSSH 10.6 enables ssh-mldsa44-ed25519, a hybrid signature that combines ML-DSA-44 with Ed25519. Hybrid construction keeps a conventional signature alongside the post-quantum algorithm rather than betting the authentication path on a single newer primitive.

Compression gives up efficiency for a smaller side-channel surface

The LZ77 dictionary coder in ssh and sshd is disabled. Compression still exists, but the change reduces how much repeated-data history can influence compressed output, at the cost of less effective compression.

scp -R is on the way out

The remote-to-remote scp -R mode is deprecated on security grounds. Operators with automation that copies directly between two remote systems should identify those workflows before a later OpenSSH release ignores the option.

AI-assisted vulnerability reports are changing release cadence

The OpenSSH project says it is receiving many AI-assisted security reports and welcomes them when paired with human triage, analysis, tests and especially fixes. Rather than accumulate verified fixes for scheduled releases, it expects to release more frequently.

What to watch next

  • When scp -R becomes ignored rather than merely deprecated.
  • Distribution adoption of OpenSSH 10.6 and whether downstream defaults differ.
  • Interoperability and policy guidance for ssh-mldsa44-ed25519.
  • Whether the faster security-driven release cadence becomes sustained.

Still unclear

  • Distribution packaging may enable or disable features differently from upstream OpenSSH.
  • The project has not specified the exact future release in which scp -R will be ignored.
  • The effect of disabled LZ77 dictionary coding depends on workload and whether SSH compression is used.

Sources

Direct reading behind this dossier.

3 sources
OpenSSH 10.6 release notes
OpenSSH primary

Upstream release notes for cryptographic, compression, scp and security-reporting changes.

OpenSSH 10.6 released
LWN.net independent specialist

Independent specialist summary confirming the release and notable security/compatibility changes.

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment