Published on October 7, 2026

Multiple OpenSSH Vulnerabilities Could Enable Plaintext Recovery, File Write and Injection Attacks


Severity

Medium

Detail

OpenSSH has released version 10.6 to address multiple security vulnerabilities that could expose sensitive information, enable unauthorized file write operations, and facilitate shell injection attacks under specific conditions. The vulnerabilities affect both SSH client and server components and may impact organizations that rely on SSH for remote administration and secure file transfers.

One of the vulnerabilities involves SSH compression, where shared compression dictionaries could allow an attacker to infer sensitive plaintext information by analyzing encrypted traffic patterns. OpenSSH also fixed an issue that could allow a malicious SFTP server to manipulate file paths during recursive file transfers, potentially resulting in files being written outside the intended directory.

Additionally, OpenSSH addressed a shell injection vulnerability involving untrusted usernames supplied through SSH command-line parameters. The release includes several other security improvements, and organizations are advised to upgrade to OpenSSH version 10.6 or later to mitigate the associated risks.

How?

The plaintext recovery vulnerability occurs when SSH compression is enabled and multiple channels share the same compression dictionary. An attacker may inject controlled data into one channel and analyze encrypted traffic characteristics to infer portions of sensitive information transmitted through another channel.

The SFTP-related vulnerability can be exploited by a malicious or compromised SFTP server that returns manipulated file paths during recursive file transfer operations. This may cause files to be written outside their intended destination folders.

The shell injection vulnerability arises when untrusted usernames are passed directly to SSH command-line operations. In environments using ProxyCommand, Match exec, or similar SSH features, specially crafted usernames may influence shell command execution and lead to unintended system actions.

Successful exploitation requires specific conditions and configurations. The vulnerabilities do not provide direct unauthenticated remote code execution against SSH servers but may lead to information disclosure, unauthorized file write operations, or command execution when deployment conditions are met.

Conclusion

These vulnerabilities highlight the security risks associated with complex SSH and SFTP deployments that process untrusted data or rely on shared compression mechanisms. While the identified issues require specific attack scenarios and are not known to be actively exploited, affected systems may be exposed to information disclosure, unauthorized file write operations, and command injection risks.

Organizations should upgrade to OpenSSH version 10.6 or later, review SSH compression settings, validate trusted SFTP server relationships, and avoid passing untrusted input to SSH command-line parameters. Security teams should also monitor SSH-related activity and apply vendor-recommended hardening measures to reduce potential exposure.

Source