OpenSSH 10.6 deliberately weakens SSH compression and restricts command-line username characters for security, The New Stack reports
OpenSSH version 10.6 introduces two deliberate breaking changes made in the name of security, according to The New Stack. The release weakens SSH compression and rejects $ and other special characters in command-line usernames, changes the outlet says are intended to close a plaintext leak and a shell injection risk in automation. The specifics rest on The New Stack's reporting, published Oct. 8, 2026.
OpenSSH version 10.6 introduces two deliberate breaking changes made in the name of security, according to The New Stack. The release weakens SSH compression and rejects $ and other special characters in command-line usernames, changes the outlet says are intended to close a plaintext leak and a shell injection risk in automation. The specifics rest on The New Stack's reporting, published Oct. 8, 2026.
Key facts
- The New Stack reports that OpenSSH version 10.6 deliberately breaks two features in the name of security.
- According to The New Stack, OpenSSH 10.6 weakens SSH compression.
- According to The New Stack, OpenSSH 10.6 rejects $ and other special characters in command-line usernames.
- The New Stack reports the changes are intended to close a plaintext leak and a shell injection risk in automation.
- The New Stack published its report on Oct. 8, 2026.
Sources · 1 source
- TN
The New Stack@thenewstackPost on X ·
OpenSSH 10.6 deliberately breaks two features in the name of security https://t.co/5orFAwzIw3
Open source - TN
The New Stack@thenewstackPost on X ·
OpenSSH 10.6 weakens SSH compression and rejects $ and in command-line usernames to close a plaintext leak and a shell injection risk in automation. https://t.co/yImN5Je7TO
Open source

