# OpenSSH 10.6 fixes compression leaks and enables hybrid post-quantum signatures

_Published Tuesday, October 6, 2026 at 5:15 PM EDT · Science, Security · Latest · Tier 2 — Notable_

OpenSSH released version 10.6 on October 6, disabling a compression dictionary coder to mitigate an attack that can recover secrets across channels sharing an SSH connection. The change reduces compression effectiveness; the project encourages application-level compression where possible.

The release also enables the hybrid post-quantum ssh-mldsa44-ed25519 signature algorithm and adds server warnings when clients use key agreement that is not post-quantum safe. Keys created with the previous experimental signature implementation must be regenerated or removed.

The team says it will release fixes more frequently after seeing AI-identified security bugs independently discovered by other researchers.

## Sources

- [openssh.org](https://www.openssh.org/releasenotes.html#10.6)

---
Canonical: https://techandbusiness.org/newswire/dSLm8b3GPWGfBMYcEittF8
Published: 2026-10-06T21:15:41.580Z
Story chronology: 2026-10-06T00:00:00.000Z
Retrieved: 2026-10-06T23:05:50.871Z
Publisher: Tech & Business (techandbusiness.org)
