CVE-2026-106582: Low severity OpenSSH sshd vulnerability
Published Oct 6, 2026
·Updated
In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary coder can be used even though this is contraindicated by the arXiv 2609.07709 "Crossing the Streams" findings.
Affected Software
2 affected components
OpenSSH sshd<10.6
OpenSSH ssh<10.6
Event History
Oct 6, 2026
CVE Published
via MITRE·08:35 PM
Data Sourced
via MITRE·08:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
The issue affects both OpenSSH sshd and the OpenSSH ssh client in versions before 10.6.
2
What access does an attacker need?
The vector is network-based and requires no privileges or user interaction, but exploitation has high attack complexity.
3
What is the expected impact?
The stated impact is limited to low confidentiality impact. No integrity or availability impact is listed.
4
What should be done to remediate the issue?
Upgrade OpenSSH sshd and ssh to version 10.6 or later.