Differences

This shows you the differences between the selected revisions of the page.

history 2006-07-10 history 2026-09-11 (current)
Line 1: Line 1:
====== Recent Version History ====== ====== Recent Version History ======
-This is list of changes for each release of WinSCP. See also [[project_history|project history]].+This is a full list of changes for each release of WinSCP. See also [[project_history|Project history]] and [[incompatible_changes|Incompatible changes between versions]].
-rushasa by h@cker tarafından hacklenmiştir+===== [[6.8]] 6.8 (not released yet) ((2026-08-22)) =====
-===== 3.8.2 ===== +··* Word wrapping in the internal editor can be toggled from toolbar menu. [[bug>2451]]
-=== 2006-06-19 ===+
-··* Change to overcome URL handler vulnerability: When protocol (''%%sftp://%%'' or ''%%scp://%%'') is provided on command line (possible execution from web browser/Windows Explorer), all command-like parameters that cause any automatic action are ignored, including ''/defaults'', ''/log'', ''/script'' and ''/command''. +===== [[6.6.4]] 6.6.4 (not released yet) ((2026-09-11)) ===== 
-  * Function //Copy path to clipboard// has keyboard shortcut ''Shift-Ctrl-P'' in Explorer-like interface. +  
-  * Address bar of Explorer-like interface has dedicated context menu, with option to //Copy path to clipboard//. +  * Increased length limit of proxy host name for updates preferences. [[bug>2456]] 
-· * Partial files (''.filepart'') are no longer considered for synchronization (SFTP-only). +  * Optionally default to keeping Login dialog open after opening session in PuTTY. [[bug>2459]] 
-  * Permissions input box has the same context menu as permissions popup box+  * Improving placement of widows, particularly those opened, while the main window is not visible (notably during command-line operations). 
-  * In scripting mode, the WinSCP can read commands from redirected standard input+  * Bug fix: When selecting a site to perform a command-line operation with, it was possible to select a workspace or a folder, resulting in unexpected behaviour or failure. [[bug>2457]] 
-  * UTF-8 encoded script files are supported (byte-order-mask is required). +  * Bug fix: After opening session in PuTTY, WinSCP process is never closed. [[bug>2458]] 
-  * Bug fix: Sorting arrows on synchronization checklist were corrupted on Windows 2000 and older. +  * Bug fix: Invalid language code for Serbian was used for Microsoft Store package. [[bug>2460]]
-  * Bug fix: Permissions popup box was occasionally dismissed, when its context menu was revealed. +
-· * Bug fix: Menu item //Leave as is// of permissions box was visible, even if it made no sense in the context. +
-  * Bug fix: When recursive setting of permissions was turned off on properties dialog, permissions may have possibly retained undefined state, although no longer allowed. +
-··* Bug fix: Path labels were redrawn each time mouse was moved over them, causing unnecessary flickering. +
-  * Bug fix: Some dialog labels were not disabled along with associated control. +
-· * Bug fix: Log window was showing log file name with patterns, instead of actual current log file name. +
-··* Bug fix: When patterns were used in log file name, the log file was recreated every time configuration has changed. +
-RUSHASA BY H@CKER TARAFINDAN TÜRKİYE İÇİN HACKLENMİŞTİR SAYGILARIMLA+===== [[6.6.3]] 6.6.3 RC ((2026-09-03)) =====
-===== 3.8 beta ===== +··* Translations completed: Belarusian, Brazilian Portuguese, Catalan, Croatian, Czech, Danish, Dutch, Finnish, French, German, Hungarian, Italian, Japanese, Korean, Lithuanian, Macedonian, Polish, Portuguese, Romanian, Russian, Serbian, Simplified Chinese, Slovak, Slovenian, Spanish, Swedish, Tamil, Traditional Chinese and Turkish. 
-=== 2005-12-20 ===+  * Some parts of GUI (panel headers, scrollbars, buttons, checkboxes) show dark in dark theme even when system-wide app theme is light. 
 +  * SSH core and private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.85]]. \\ It brings the following change: 
 +    * Security issue: fixed a remotely triggerable use-after-free in Pageant. [[pbug>pageant-deferred-decryption-uaf]] 
 +    * Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. [[pbug>etm-large-packet-overflow]] 
 +    * Security issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. [[pbug>argon2-parameter-checks]] 
 +    * Denial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. [[pbug>maxpkt-0-tight-loop]] 
 +  * Bundled SSH private key tools (PuTTYgen and Pageant) are 64-bit. 
 +  * On Windows 11, using system dark tab theme, that uses different shades for active and disabled/disconnected tabs. [[bug>2452]] 
 +  * TLS/SSL core upgraded to OpenSSL 3.5.8
 +  * XML parser upgraded to Expat 2.8.4. 
 +··* Source code package build script supports 64-bit target. 
 +  * Installer upgraded to Inno Setup 6.7.3. 
 +  * 64-bit build is identified in version information. 
 +  * Resolving version of pwsh installed with MSIX. 
 +  * Thirdparty information from the About dialog can be copied to the clipboard even when the browser control malfunctions. 
 +  * Bug fix: No error is shown when connection fails. 
 +  * Bug fix: ''x-name'' URL parameter was incorrectly decoded. 
 +  * Bug fix: Incorrect number validation. 
 +  * Bug fix: Some controls (notably list view headers) do not correctly apply dark mode in 64-bit build. [[bug>2453]] 
 +  * Bug fix: 64-bit build did not identify its system to be 64-bit, what among other prevented it from identifying 64-bit COM registrations. 
 +  * Bug fix: Some strings use incorrect translation in 64-bit version. [[bug>2455]]
-··* Synchronization enhanced:  +===== [[6.6.2]] 6.6.2 RC ((2026-06-17)) =====
-····* When option //Preview changes// is turned on, checklist of synchronization actions is displayed, giving user option to review and confirm them all at once. +
-    * Option //Preview changes// works for timestamp synchronization too. +
-····* When list of directories watched by function //Keep Remote Directory Up To Date// is changed, new count is shown on log view. +
-    * Synchronization delay for function //Keep Remote Directory Up To Date// is configurable (only directly in configuration files). +
-   * Bug fix: When list of directories watched by function //Keep Remote Directory Up To Date// was changed, some of the subdirectories stopped being watched. +
-    * Bug fix: Option //Same size only// for timestamp synchronization was not working. +
-    * Bug fix: Newly added subdirectories were not watched for changes, when keeping remote directory up to date from script. +
-  * The connection can be automatically re-established when lost during file transfer (SFTP-only). +
-  * When the main session is reconnected the background transfer queue is now preserved. +
-  * The Server/Protocol Information dialog remade. It now also shows space available for current directory. +
-  * Color can be associated with session. It is used as background color for file panels. +
-  * Authentication window introduced. It combines progress display with authentication prompts. +
-  * Initial permissions can be set when creating new remote directory. +
-  * File panel can be sorted by extension by clicking on dedicated part of //Name/Ext// column title. +
-  * Permission errors when setting attributes (permissions and timestamp) of remote file can be suppressed using new transfer option //Ignore permissions errors// (SFTP-only). +
-  * Commands //Edit New File// and //Create Directory// moved to //New > File// and //New > Directory//. Command //Add/Edit Link// split into //Edit Link// and //New > Link//. Submenu //New// is also accessible from panel's context menu. +
-  * New panel option for Norton Commander-like interface: //Full row select// (turned on by default). Can be turned off to make panel's context menu more accessible. +
-  * New toolbar with custom commands. +
-  * New toolbar for Norton Commander-like interface with buttons //Upload// and //Download//, useful when you want to transfer file without having the source panel active. +
-  * New command (switch) for queue //Disconnect Once Empty// closes the session, if it's idle, when the last scheduled background transfer is finished. +
-  * System administrators can enforce display of authentication banners. +
-  * System administrators can restrict connection to servers without having their host keys accepted in advance. +
-  * Context menu of console output display includes command to resize the console window to fit the command output. +
-  * If the SFTP server does not provide file permissions/owner/group in directory listing, WinSCP requests them explicitly before showing Properties dialog. +
-  * Pressing button //OK// on fatal error message box for the initial session re-opens the Login dialog. +
-  * Only the last ''@'' in connection string is considered as username/hostname separator, making it possible to easier type username and/or password containing ''@'' from command-line. +
-  * "Edit" commands now open all selected files, not only focused one, if editing of multiple files is allowed. +
-  * Edited remote file can be uploaded, even if the session was reconnected meanwhile. +
-  * Transfer setting dialog has option //Do not show this dialog box again//, when transfer is invoked using drag&drop to disable future drag&drop transfer confirmation. +
-  * Optional "Office 2003" theme and few minor changes to toolbars. +
-  * Size of the console window is preserved. +
-  * When changing file properties, ''chgrp'' and ''chown'' are called before ''chmod'', because they change file permissions (SCP-only). +
-  * If the session is closed due to option //Disconnect when operation finishes//, associated background transfers are terminated immediately, not only after the user acknowledges the closure. +
-  * It is now possible to edit two files with the same path/name located on different servers. +
-  * Logging to file can be enabled using new ''/log'' command-line option. +
-  * Log file name can contain following patterns: ''&Y'' (year), ''&M'' (month), ''&D'' (day), ''&T'' (time), ''&H'' (hostname), ''&S'' (session name). +
-  * Improved cleaning of directory change cache on symbolic link deletion. +
-  * SFTP extension "versions", specifying list of supported protocol versions, is decoded and logged. +
-  * SFTP extension "supported" is ignored, when extension "supported2" is also sent by the server. +
-  * Custom transfer settings dialog disables settings unusable in current context (synchronization mode, server capabilities, etc.). +
-  * Transfer setting preset info tip does not show settings unusable in current context (server capabilities, etc.). +
-  * Setup does not overwrite update period, if updates were already enabled. +
-  * Transfer setting options "Permissions" and "Preserve read-only" are disabled when the server does not support permissions. +
-  * On Windows XP, native column sorting icons are used. +
-  * Licence of PuTTY updated. +
-  * Command //Copy URL to Clipboard// now URL-encodes some characters (space particularly). +
-  * WinSCP can handle URL with URL-encoded characters in session name. +
-  * URL handler registered by WinSCP now encloses the URL into quotes to allow handling of URL's with space. +
-  * WinSCP can load plain text password from configuration (new attribute ''PasswordPlain''). If possible, it automatically converts the password to encrypted form. +
-  * File mask ''*.*'' is treated exceptionally, matching all files, even those without dot. +
-  * Internal editor window is activated before associated message box pops up (e.g. save confirmation). +
-  * //Preferences// command added to context menu of internal editor. +
-  * Navigation tree on login and preferences dialogs widened to allow longer translations. +
-  * When sorting files in file panel, filename is always secondary criteria. +
-  * INI file name on Properties dialog changes with name of executable. +
-  * Option ''/script='' without value is ignored. +
-  * //Server response timeout// can be set up to 6000 seconds. +
-  * Popup hints close on mouse click. +
-  * Bug fix: Fixed resolving symbolic links in sub-directories. +
-  * Bug fix: After directory refresh, WinSCP sometime incorrectly behaved as if the user were dragging the selected file. +
-  * Bug fix: SCP fallback for SSH-1 was not working. +
-  * Bug fix: Uploads of files into previously non-existing directory could not be resumed (SFTP-only). +
-  * Bug fix: Selection could not be restored after changing file properties. +
-  * Bug fix: WinSCP hung on start-up occasionally (for example when the main window was closed maximised on different screen resolution the last time). +
-  * Bug fix: Failure when changing file properties on SFTP server supporting UTF-8. +
-  * Bug fix: Incorrectly formatted message "Unknown principal". +
-  * Bug fix: Hint on status bar for transfer setting preset selector incorrectly showed preset configuration. +
-  * Bug fix: Custom transfer settings dialog invoked from context menu on synchronization dialog did incorrectly allowed changing all settings, even when time-stamp-only synchronization was selected. +
-  * Bug fix: When the SFTP server does not support permissions, random permissions were used for the files. +
-  * Bug fix: Crash when re-key occurred on idle background session and the host key was not cached. +
-  * Bug fix: Failure when downloading file from different directory than the current one (SCP only). +
-  * Bug fix: Username was stored incorrectly when exporting session to PuTTY. +
-  * Bug fix: On the first start-up on fresh installation, default editor settings were not preset. +
-  * Bug fix: When output of the console is was redirected to file, list of transferred files contained only the last file. +
-  * Bug fix: Editors list was lost when changing configuration storage. +
-  * Bug fix: //Mouse only// option of //Explorer style selection// was not preserved. +
-  * Bug fix: When password storing is restricted, warning that password is being stored is no longer shown.+
-by h@cker tarafından hacklenmiştir+  * Experimental 64-bit version of WinSCP. [[bug>618]] 
 +  * Optionally not showing error message when connection is lost while idle. [[bug>2360]] 
 +  * SSH core and SSH private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.84]]. \\ It brings the following changes: 
 +    * Security issue: fixed a remotely triggerable double-free in RSA key exchange. [[pbug>rsakex-double-free]] 
 +    * Minor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. [[pbug>ecdsa-remotely-triggerable-assertion]] 
 +    * Bug fix: spurious //"Network error: Socket is not connected"// when authenticating to some HTTP proxies. [[pbug>http-proxy-auth-wsaenotconn]] 
 +  * TLS/SSL core upgraded to OpenSSL 3.5.7. 
 +  * XML parser upgraded to Expat 2.8.1. 
 +  * Restored faster C TLS/SSL AES implementation. 
 +  * Configurable warning when opening large file in an internal editor. [[bug>2437]] 
 +  * Informing that when preserving directory timestamps is enabled, using multiple connections for transfer is not possible. [[bug>2439]] 
 +  * Warning when pasting a session URL with unsafe settings. 
 +  * When opening session in PuTTY to a host for which WinSCP has multiple host keys cached, using the last key or the key that PuTTY has cached. [[bug>2440]] 
 +  * Always (re)registering drag&drop shell extension during installation, even when the extension is not replaced. 
 +  * Allowed Console interface tool to have ''.exe'' extension to avoid false positive detections by some antiviruses. [[bug>2434]] 
 +  * Using //"username"// and //"hostname"// as one word. 
 +  * Reading all system settings from 64-bit registry. 
 +  * Allow assigning ''null'' to ''Session.SessionLogPath''. [[bug>2438]] 
 +  * Avoiding using ''SSH_FXF_EXCL'' together with ''SSH_FXF_TRUNC'' SFTP file opening flags. [[bug>2444]] 
 +  * Optimized file system monitoring when looking for dummy directory during drag&drop downloads. [[bug>2445]] 
 +  * Change: Not allowing WebDAV redirects to other hosts by default. [[bug>2447]] 
 +  * Change: Not allowing WebDAV redirects to an unencrypted URL by default. [[bug>2448]] 
 +  * Updated to JCL library 2.9 commit c669fd12. 
 +  * Bug fix: Failure when trying to connect via HTTP proxy to FTP host with excessively long login details. [[bug>2435]] 
 +  * Bug fix: Buffer overflow in Console interface tool. [[bug>2436]] 
 +  * Bug fix: Failure setting ''Session.DebugLogPath'' when running in impersonated context. [[bug>2441]] 
 +  * Bug fix: Message boxes from secondary windows (like the internal editor) caused application to move to the background when when the main window was minimized. [[bug>2443]] 
 +  * Bug fix: Heap over-read via crafted encrypted filename. [[bug>2449]] 
 +  * Bug fix: Slashes in filenames can cause path traversal when invalid filename characters replacement is disabled. [[bug>2450]] 
 + 
 +===== [[6.6.1]] 6.6.1 beta ((2026-04-01)) ===== 
 + 
 +  * Support for OpenSSH ssh-agent. [[bug>1682]] 
 +  * Optionally connecting all workspace/folder sessions immediately. [[bug>1026]] 
 +  * Preserving panel scroll position after rename. [[bug>2425]] 
 +  * ''Ctrl+C'' works in list views on 'Server and protocol information' dialog. 
 +  * Preventing moving or copying a file or folder over ancestor folder with the same name. [[bug>2427]] 
 +  * WebDAV/HTTP core upgraded to neon 0.37.1. 
 +  * XML parser upgraded to Expat 2.7.5. 
 +  * Bug fix: Some menus were not working on displays to the left or above the primary display. [[bug>2423]] 
 +  * Bug fix: Mouse wheel downwards scrolling did not work on toolbar drop down lists. 
 +  * Bug fix: Once any control of permissions popup box was focused the popup no longer closed when user clicked outside of it. 
 +  * Bug fix: Failure when closing Transfer settings dialog with //X// button while a permissions popup box control is focused. [[bug>2420]] 
 +  * Bug fix: Failure when switching to a session that is being reconnected. 
 +  * Bug fix: Failure when the first bit of an SFTP response is set. [[bug>2422]] 
 +  * Bug fix: Copying to clipboard with ''Ctrl+C'' from 'Server and protocol information' was broken. 
 +  * Bug fix: Protocol additional information scrolling was broken. 
 +  * Bug fix: Master password dialog was missing //Help// button. 
 +  * Bug fix: Checking if edited/opened file was modified externally didn't work for inactive sessions. [[bug>2426]] 
 +  * Bug fix: Wrapped settings values from Raw Site Settings dialog were not preserved. 
 +  * Bug fix: Some files modified by local custom command in SCP session fail to upload back. [[bug>2428]] 
 +  * Bug fix: Whole //Key exchange// page was incorrectly hidden when //"Handles SSH key re-exchange badly"// bug was enabled. 
 +  * Bug fix: Some message boxes leak GDI handle. [[bug>2430]] 
 +  * Bug fix: Login dialog leaks GDI handles. [[bug>2431]] 
 + 
 +===== [[6.6]] 6.6 beta ((2026-02-02)) ===== 
 + 
 +  * Synchronizing two local directories. [[bug>2020]] 
 +  * Compiler upgraded to Clang/bcc32c. [[bug>618]] 
 +  * Inactive sessions can be automatically reconnected. [[bug>2232]] 
 +  * Added dark theme support to: [[bug>1696]] 
 +    * Login dialog. [[bug>2345]] 
 +    * Transfer Options dialog. 
 +    * Message boxes. 
 +    * Queue column headers. [[bug>2356]] 
 +    * Progress window. 
 +    * Authentication Progress window. [[bug>2358]] 
 +    * Bug fix: Scrollbar colors did not always reflect the color theme 
 +  * Using modern directory selection dialog that scales correctly and allows creating new directory. [[bug>2373]] [[bug>2389]] 
 +  * Optimized GUI when working with large subdirectory selection. [[bug>2396]] 
 +  * Change: Default to UTF-8 encoding in internal editor. [[bug>2397]] 
 +  * New DigiCert EV code signing certificate valid until March 2029 is used for signing binaries. 
 +  * TLS/SSL core upgraded to OpenSSL 3.5.5. 
 +  * WebDAV/HTTP core upgraded to neon 0.36.0. 
 +  * XML parser upgraded to Expat 2.7.4. 
 +  * Installer upgraded to Inno Setup 6.7.0 with dark mode support enabled. 
 +  * Increased WinSCP memory limit to 4 GB. [[bug>2412]] 
 +  * Defined and implemented interface for the .NET library. By @mjkent. [[bug>856]] 
 + * Optimized TLS/SSL AES implementation. 
 +  * Restoring ability to restart Explorer to allow upgrade of drag&drop shell extension, when installing for current user, as after-restart replacement is not possible without Administrator privileges. [[bug>2381]] 
 +  * MSI toolset updated to WiX 5. 
 +  * Commands to copy paths to the clipboard on the Synchronization checklist window. 
 +  * Cryptography optimization. 
 +  * Support long AWS/S3 session tokens. [[bug>2403]] 
 +  * Prevent hang when new device is attached or removed while some mapped network drive is not available. [[bug>2382]] 
 +  * Copy and paste improvements: 
 +    * Consistently renaming local files dropped or pasted back to their source directory to avoid collisions. 
 +    * Bug fix: When copying local files to clipboard from system context menu, "cut" state of previously cut files was not cleared. 
 +  * Not redundantly verifying WebDAV or S3 certificate in Windows Certificate store if it is already marked as trusted in session settings. [[bug>2404]] 
 +  * Provide SNI when opening FTP data connection. [[bug>2410]] 
 +  * Optimized synchronization checklist sorting. 
 +  * Support for Beyond Compare 5 in Compare Files extension. [[bug>2417]] 
 +  * Convert unsupported SSH proxy to SSH tunnel when importing site from PuTTY. [[bug>2408]] 
 +  * FTP directory listing falls back to the other active/passive mode, consistently with file transfers. 
 +  * Consistently calling command to open window with specific directory //Explore//, instead of sometimes //Browse//. 
 +  * Consistently referring to file last modification timestamp column as //Date modified//. 
 +  * With INI file provided on command-line, using the same INI file when starting a new instance. 
 +  * Windows shell local file copy status window is centered on the main window. 
 +  * Made taskbar flashing configurable in GUI. [[bug>2411]] 
 +  * Control labels on transfer settings dialogs do not show keyboard accelerator cue, until ''Alt'' key is pressed. 
 +  * Not using drag images even with directory trees. [[bug>1274]] 
 +  * Allow configuring checksum commands. [[bug>2394]] 
 +  * Updated to JCL library 2.8.1. 
 +  * Updating jump list only when running with GUI. 
 +  * Made space on permissions box for longer translations. [[bug>2398]] 
 +  * Opening //Default Apps// //Settings// page directly to open it in the foreground and avoid flashing //Control Panel// window. 
 +  * Improving order in which Windows Narrator reads window controls. 
 +  * All edit boxes with history consistently do not auto complete and show 16 entries in the drop down. 
 +  * Removed obsolete //Preserve remote timestamp// session settings. 
 +  * Bug fix: Local file with invalid characters replaced could not be explored from the Synchronization checklist window. 
 +  * Bug fix: Files modified by local custom command are not always uploaded to the correct remote directory. [[bug>2370]] 
 +  * Bug fix: List of network drives in drive drop down and directory tree did not always match. 
 +  * Bug fix: Host key prompt did not have the default button. 
 +  * Bug fix: When the local path specified on Open directory/Location profile dialog is not existing, when browsing for a new path, the trailing part of the nonexisting path was appended to the new path. 
 +  * Bug fix: Trying to enter an invalid link in local panel fails silently. 
 +  * Bug fix: After FTP data connection fails to open further use of the session is broken. 
 +  * Bug fix: Pasting cut files from the clipboard into a local panel copies them instead of moving them. [[bug>2400]] 
 +  * Bug fix: Some edits did not save their value to history when submitting with ''Enter''. 
 +  * Bug fix: Too long edit history dropdown can overflow monitor bounds. [[bug>2432]] 
 +  * Bug fix: Message box texts and some control labels are not visible to screen readers. [[bug>2413]] 
 +  * Bug fix: Failure when clicking tab close button while the session is already being closed. [[bug>2416]] 
 + 
 +===== [[6.5.9]] 6.5.9 (not released yet) ((2026-09-10)) ===== 
 + 
 +  * Back-propagated fixes from 6.6.4 release: 
 +    * Bug fix: Invalid language code for Serbian was used for Microsoft Store package. [[bug>2460]] 
 + 
 +===== [[6.5.8]] 6.5.8 ((2026-09-10)) ===== 
 + 
 +  * This is Microsoft Store-only release that fixes packaging problem of 6.5.7. The actual binaries are still 6.5.7. 
 +    * Bug fix: Cannot install from Microsoft Store because of invalid 'sr' language. [[bug>2460]] 
 + 
 +===== [[6.5.7]] 6.5.7 ((2026-09-09)) ===== 
 + 
 +  * Translations completed: Croatian, Finnish, Georgian, Italian and Serbian, and updated: Slovenian. 
 +  * TLS/SSL core upgraded to OpenSSL 3.3.7. 
 +  * SSH private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.85]]. SSH core upgraded to include some fixes. \\ It brings the following change: 
 +    * Security issue: fixed a remotely triggerable use-after-free in Pageant. [[pbug>pageant-deferred-decryption-uaf]] 
 +    * Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. [[pbug>etm-large-packet-overflow]] 
 +    * Security issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. [[pbug>argon2-parameter-checks]] 
 +    * Denial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. [[pbug>maxpkt-0-tight-loop]] 
 +    * Security issue: fixed a remotely triggerable double-free in RSA key exchange. [[pbug>rsakex-double-free]] 
 +    * Minor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. [[pbug>ecdsa-remotely-triggerable-assertion]] 
 +  * Back-propagated fixes from 6.6.2 beta release: 
 +    * Bug fix: Failure setting ''Session.DebugLogPath'' when running in impersonated context. [[bug>2441]] 
 +  * Bug fix: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. CVE-2026-45447 fix from OpenSSL 3.4.6. 
 + 
 +===== [[6.5.6]] 6.5.6 ((2026-03-25)) ===== 
 + 
 +  * Translations completed: Macedonian, and updated: Lithuanian, and Russian. 
 +  * TLS/SSL core upgraded to OpenSSL 3.3.6. 
 +  * Back-propagated improvements from 6.6–6.6.1 beta release: 
 +    * New DigiCert EV code signing certificate valid until March 2029 is used for signing binaries. 
 +    * XML parser upgraded to Expat 2.7.5. 
 +    * Support for Beyond Compare 5 in Compare Files extension. [[bug>2417]] 
 +    * Bug fix: Checking if edited/opened file was modified externally didn't work for inactive sessions. [[bug>2426]] 
 + 
 +===== [[6.5.5]] 6.5.5 ((2025-11-19)) ===== 
 + 
 +  * Translation updated: Vietnamese. 
 +  * Bug fix: Pasting files using local directory tree context menu pastes them to the current directory, instead of the selected one. 
 +  * Bug fix: Failure when opening site imported from PuTTY with unsupported SSH proxy. [[bug>2407]] 
 +  * Bug fix: Incorrect hostname validation when connecting to S3 endpoint with certificate that does not cover root S3 hostname. [[bug>2409]] 
 + 
 +===== [[6.5.4]] 6.5.4 ((2025-10-16)) ===== 
 + 
 +  * Translations updated: Belarusian and Georgian. 
 +  * TLS/SSL core upgraded to OpenSSL 3.3.5. 
 +  * XML parser upgraded to Expat 2.7.3. 
 +  * Added new ''ap-southeast-6'' AWS region. 
 +  * Bug fix: When restored after operation completed while minimized the window is disabled. [[bug>2393]] 
 +  * Bug fix: Command ''md5sums'' is incorrectly used to calculate MD5 checksum instead of ''md5sum''. [[bug>2392]] 
 +  * Bug fix: Incomplete FTP upload when the source stream/stdin reads less than requested. [[bug>2395]] 
 +  * Bug fix: ''Shift''-clicking //OK// button on Synchronization checklist window when synchronization in the background was not possible still closed the window. 
 +  * Bug fix: Failure after reloading file panel when number of files decreases. [[bug>2402]] 
 +  * Bug fix: Failure or silently missing headers when when S3 request headers were too long. 
 + 
 +[[history_old|Older versions]] 
 +~~NOTOC~~ 
 +~~ARCHIVE=history_old~~

Last modified: by 85.97.199.52