OpenSSH Vulnerability in SSHD and SSH Affecting Multiple Versions
CVE-2026-106582

3.7LOW

Key Information:

Vendor

OpenBSD

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106582?

OpenSSH before version 10.6 features a vulnerability in the sshd and ssh components where an LZ77 dictionary coder can be employed. This practice contradicts the recommendations made in the arXiv document 'Crossing the Streams' (2609.07709), highlighting potential risks in secure communication channels. The improper implementation could compromise the security and integrity of data transmission, making it critical for users to upgrade their installations to the latest version to safeguard their systems.

Affected Version(s)

OpenSSH 0 < 10.6

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.