Differences

This shows you the differences between the selected revisions of the page.

history 2007-10-26 history 2026-09-25 (current)
Line 1: Line 1:
====== Recent Version History ====== ====== Recent Version History ======
-This is list of changes for each release of WinSCP. See also [[project_history|project history]].+This is a full list of changes for each release of WinSCP. See also [[project_history|Project history]] and [[incompatible_changes|Incompatible changes between versions]].
-===== Not Released Yet =====  +===== [[6.8]] 6.8 (not released yet) ((2026-08-22)) =====
-=== 2007-10-16 === +
-  * Speed limit can be actually set in KiB/s. +
-  * Speed limit can be set for background transfers. +
-  * Transfer settings were removed from transfer options dialog to simplify it. The settings can be changed by selecting transfer settings preset or by invoking custom transfer settings dialog (the same way as for synchronization). +
-  * More than one host key for a host may be accepted. +
-  * It is possible to cancel connection attempts of background transfer. +
-  * Proxy settings to check for updates can be automatically detected from system and IE settings. +
-  * When synchronized browsing is on and entered directory does not exist in an opposite directory, WinSCP offers to create it. +
-  * Added several switches to scripting commands to extend their capabilities with functionality available in GUI already: ''/mirror'' for ''synchronize'', ''/delete'' for ''synchronize'' and ''keepuptodate'' (obsoletes option ''synchdelete''), ''/delete'' to ''get'' and ''put'', ''/timeout'' and ''/privatekey'' to ''open''. +
-  * Added switch ''/hostkey'' to command-line and ''open'' script command to automatically accept host keys with given fingerprint. +
-  * During resumable transfers, the destination file is not removed (if present) until the transfer actually finishes. +
-  * Transfer and session toolbars automatically stretches to right window edge. +
-  * Command line panel is toolbar (can be docked elsewhere). +
-  * Address and command line drop down boxes follow the toolbar style. +
-  * On Explorer-like interface, path on address toolbar is editable. +
-  * //KiB// is used instead of //KB// for kilobyte. +
-  * Estimated time is shown instead of elapsed time in queue list. +
-  * //Open in PuTTY// makes PuTTY use Telnet or SSH session for FTP sessions in WinSCP. +
-  * Host key confirmation dialog has an option to copy the key into clipboard. +
-  * //Server does not use UTF-8// changed to //UTF-8 encoding for filenames// and moved to //Environment// tab, as it is used also by FTP protocol. +
-  * //Timezone offset// moved to //Environment// tab, as it is used also by FTP protocol. +
-  * ''Shift-Del'' deletes to recycle bin, if deletion to recycle bin is disabled, and vice versa. +
-  * Opening bookmarks does not trigger synchronized browsing anymore. +
-  * It is possible to optionally overwrite stored password with new one, if authentication with original stored password fails. +
-  * When saving current session with password, warning is displayed. +
-  * When saving session with password, option is given not to store the password. +
-  * //Edit link// function is available in context menu of remote symbolic links. +
-  * Size of directory change cache is limited. +
-  * Error messages of background transfer are actually presented as errors. +
-  * Initial size of Commander-like window is increased. +
-  * Improved initial placing of Commander-like window. +
-  * Improved ''call'' command description with respect to FTP protocol. +
-  * ''ftp'' protocol added to command-line syntax help. +
-  * Change: Transfer option //Preserve read-only// is off by default.+
-===== 4.0.5 =====  +··* Word wrapping in the internal editor can be toggled from toolbar menu. [[bug>2451]]
-=== 2007-10-24 === +
-··* With FTP protocol, errors when parsing file permissions in directory listing are ignored. +
-  * Reading/writing INI files is faster. +
-  * Hostkey of tunneled session is verified against target session of tunnel. +
-  * When opening session in PuTTY, defaults for session options not set by WinSCP are loaded from //Default settings// of PuTTY. +
-· * Increased maximal length of username. +
-  * Full system error is reported when writing of local file fails. +
-  * Sample custom command //Execute// changed to ''./!'' (from ''!''). +
-  * When parsing directory listing, plus sign after permissions, separated by space, is silently ignored. +
-  * When uploading to symbolic link with SFTP protocol, resuming is disabled to preserve the link. +
-  * Bug fix: Automatic reconnect in scripting was not working. +
-  * Bug fix: When reading of local file failed, while uploading with SFTP protocol, file transfer was interrupted without reporting any error. +
-  * Bug fix: When file transfer failed with FTP protocol, whole batch was interrupted, without an option to retry or skip the file transfer. +
-  * Bug fix: Failure when parsing of directory listing failed with FTP protocol. +
-  * Bug fix: Background color of directory tree icons has not reflected session color. +
-  * Bug fix: Removed dependency on ''netapi32.dll'' (not present on Windows 95/98/ME). +
-  * Bug fix: It was not possible to upload file opened in another application with FTP protocol. +
-  * Bug fix: Missing GSSAPI was incorrectly reported, even when SSPI with GSSAPI support was present. +
-  * Bug fix: Workaround for occasional bug when opening some dialogs.+
-===== 4.0.4 ===== +===== [[6.6.4]] 6.6.4 (not released yet) ((2026-09-25)) ===== 
-=== 2007-09-02 === +· 
-  * Fallback to simple FTP ''LIST'' command, when ''LIST -a'' fails. +  * XML parser upgraded to Expat 2.8.5. 
-  * Workaround for bug in Windows Vista preventing selection of files with keyboard. +· * Increased length limit of proxy host name for updates preferences. [[bug>2456]] 
-  * Offline network drives are not scanned on startup to prevent long delays before a main window is shown. +  * Optionally default to keeping Login dialog open after opening session in PuTTY. [[bug>2459]] 
-  * Improved security when handling URL's (from web browser). +  * Improving placement of widows, particularly those opened, while the main window is not visible (notably during command-line operations). 
-  * Bug fix: When connection was broken during automatic transfers, program stalled for few seconds. +  * Removed no longer working OneDrive code. 
-  * Bug fix: Instability the connection was dropped while keep remote directory up to date function was running. +  * Updated to JCL library 2.9 commit 10b92737. 
-  * Bug fix: Malformed prompt for username in scripting. +  * Bug fix: When selecting a site to perform a command-line operation with, it was possible to select a workspace or a folder, resulting in unexpected behaviour or failure. [[bug>2457]] 
-  * Bug fix: Second opened session with enabled SSH tunnel (with automatic selection of tunnel port) actually used the existing tunnel of the first session. +  * Bug fix: After opening session in PuTTY, WinSCP process is never closed. [[bug>2458]] 
-  * Bug fix: Memory leak when SSH connection is refused. +  * Bug fix: Invalid language code for Serbian was used for Microsoft Store package. [[bug>2460]] 
-  * Bug fix: When username is not specified on login dialog, password typing is revealed on authentication dialog.+  * Bug fix: Fix crashes or unexpected behaviour when user saves a site and a workspace with the same name. [[bug>2462]]
 +===== [[6.6.3]] 6.6.3 RC ((2026-09-03)) =====
-===== 4.0.3 ===== +··* Translations completed: Belarusian, Brazilian Portuguese, Catalan, Croatian, Czech, Danish, Dutch, Finnish, French, German, Hungarian, Italian, Japanese, Korean, Lithuanian, Macedonian, Polish, Portuguese, Romanian, Russian, Serbian, Simplified Chinese, Slovak, Slovenian, Spanish, Swedish, Tamil, Traditional Chinese and Turkish. 
-=== 2007-07-12 === +··* Some parts of GUI (panel headers, scrollbars, buttons, checkboxes) show dark in dark theme even when system-wide app theme is light. 
-  * Mask ''*.php*'' in default text file mask is replaced with ''*.php'' and ''*.php3''. +  * SSH core and private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.85]]. \\ It brings the following change: 
-  * Subdirectories of current directory are not scanned for purpose of displaying in tree view when the tree view is hidden. +····* Security issue: fixed a remotely triggerable use-after-free in Pageant. [[pbug>;pageant-deferred-decryption-uaf]] 
-  * Bug fix: Once any transfer is done while keep remote directory up to date is running, its dialog cannot be minimized anymore. +   * Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. [[pbug>;etm-large-packet-overflow]] 
-  * Bug fix: Failure when automatically reconnecting the session from script with ''option batch continue''.+····* Security issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. [[pbug>argon2-parameter-checks]] 
 +    * Denial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. [[pbug>maxpkt-0-tight-loop]] 
 +··* Bundled SSH private key tools (PuTTYgen and Pageant) are 64-bit. 
 +  * On Windows 11, using system dark tab theme, that uses different shades for active and disabled/disconnected tabs. [[bug>2452]] 
 +  * TLS/SSL core upgraded to OpenSSL 3.5.8. 
 +  * XML parser upgraded to Expat 2.8.4. 
 +  * Source code package build script supports 64-bit target. 
 +  * Installer upgraded to Inno Setup 6.7.3. 
 +  * 64-bit build is identified in version information. 
 + * Resolving version of pwsh installed with MSIX. 
 +  * Thirdparty information from the About dialog can be copied to the clipboard even when the browser control malfunctions. 
 +  * Bug fix: No error is shown when connection fails. 
 +  * Bug fix: ''x-name'' URL parameter was incorrectly decoded. 
 +  * Bug fix: Incorrect number validation. 
 +  * Bug fix: Some controls (notably list view headers) do not correctly apply dark mode in 64-bit build. [[bug>2453]] 
 +  * Bug fix: 64-bit build did not identify its system to be 64-bit, what among other prevented it from identifying 64-bit COM registrations. 
 +  * Bug fix: Some strings use incorrect translation in 64-bit version. [[bug>2455]]
-===== [[4.0.2]] 4.0.2 beta ===== +===== [[6.6.2]] 6.6.2 RC ((2026-06-17)) =====
-=== 2007-05-29 === +
-··* Bug fix: Popup menus invoked from buttons were not working.+
-===== [[4.0.1]] 4.0.1 beta ===== +··* Experimental 64-bit version of WinSCP. [[bug>618]] 
-=== 2007-05-28 === +· * Optionally not showing error message when connection is lost while idle. [[bug>2360]] 
-  * FTP core upgraded to [[http://filezilla-project.org/|FileZilla 2.2.32]]. The upgrade solves some vulnerabilities. +  * SSH core and SSH private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.84]]. \\ It brings the following changes: 
- ·* When //Session// sheet is automatically selected on Login dialog (creation of new session, etc.), the //Host name// box is focused. + ···* Security issue: fixed a remotely triggerable double-free in RSA key exchange. [[pbug>rsakex-double-free]] 
- ·* Username of the main session is reused for background transfers. + ···* Minor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. [[pbug>ecdsa-remotely-triggerable-assertion]] 
- ·* Different set of keepalive settings is used for FTP. FTP now has keepalives enabled by default. + ···* Bug fix: spurious //"Network error: Socket is not connected"// when authenticating to some HTTP proxies. [[pbug>http-proxy-auth-wsaenotconn]] 
-  * For convenience, file mask "*." matches files without an extension (even if the name does not include the dot at all). +  * TLS/SSL core upgraded to OpenSSL 3.5.7. 
-  * When window is minimized during transfer that is part of synchronization, it stays minimized till the end of synchronization. +  * XML parser upgraded to Expat 2.8.1. 
-  * After failure to open session requested from command line, login window is not shown. +  * Restored faster C TLS/SSL AES implementation. 
-  * Command //Open in PuTTY// uses tunnel for current session. +  * Configurable warning when opening large file in an internal editor. [[bug>2437]] 
-  * Global configuration that can be set on login dialog (user interface style, logging) is saved when session it saved. +  * Informing that when preserving directory timestamps is enabled, using multiple connections for transfer is not possible. [[bug>2439]] 
-  * ''Alt+F6'' now edits the link (if applicable). +  * Warning when pasting a session URL with unsafe settings. 
-  * Bug fix: Checksum calculation with SFTP protocol was not working at all. +  * When opening session in PuTTY to a host for which WinSCP has multiple host keys cached, using the last key or the key that PuTTY has cached. [[bug>2440]] 
-  * Bug fix: For remote directories with names like "C:", the icons of local drives were used. +  * Always (re)registering drag&drop shell extension during installation, even when the extension is not replaced. 
-  * Bug fix: Proxy setting were ignored when setting up SSH tunnel. +  * Allowed Console interface tool to have ''.exe'' extension to avoid false positive detections by some antiviruses. [[bug>2434]] 
-  * Bug fix: Password for proxy was ignored with FTP. +  * Using //"username"// and //"hostname"// as one word. 
-  * Bug fix: SFTP uploads occasionally hanged. +  * Reading all system settings from 64-bit registry. 
-  * Bug fix: Prompts (such as password prompts) for background transfers froze the main window. +  * Allow assigning ''null'' to ''Session.SessionLogPath''. [[bug>2438]] 
-  * Bug fix: It was not possible to change path by //Browse// button (such as path to a log file). +  * Avoiding using ''SSH_FXF_EXCL'' together with ''SSH_FXF_TRUNC'' SFTP file opening flags. [[bug>2444]] 
-  * Bug fix: //Yes to All// on overwrite confirmation box was not working (FTP only). +  * Optimized file system monitoring when looking for dummy directory during drag&drop downloads. [[bug>2445]] 
-  * Bug fix: For automatic transfers (uploads from editor, synchronization), the transfer was incorrectly automatically "resumed" when source file was larger than destination one, leaving content of file corrupted (FTP only). The issue may also make uploads from editor impossible in case server does not support (text file) transfer resuming. +  * Change: Not allowing WebDAV redirects to other hosts by default. [[bug>2447]] 
-  * Bug fix: Local files excluded from transfer (upload) were indefinitely locked by WinSCP. +  * Change: Not allowing WebDAV redirects to an unencrypted URL by default. [[bug>2448]] 
-  * Bug fix: Script failed once it needed to ask for password (with SFTP and SCP only). +  * Updated to JCL library 2.9 commit c669fd12. 
-  * Bug fix: //Open session in PUTTY// did not use stored password. +  * Bug fix: Failure when trying to connect via HTTP proxy to FTP host with excessively long login details. [[bug>2435]] 
-  * Bug fix: When switching back to WinSCP internal editor from another application, the main WinSCP window was focused instead. +  * Bug fix: Buffer overflow in Console interface tool. [[bug>2436]] 
-· * Bug fix: When synchronization occurred while the //Keep remote directory up to date// dialog was minimized, it was not possible to restore it.+  * Bug fix: Failure setting ''Session.DebugLogPath'' when running in impersonated context. [[bug>2441]] 
 +  * Bug fix: Message boxes from secondary windows (like the internal editor) caused application to move to the background when when the main window was minimized. [[bug>2443]] 
 +  * Bug fix: Heap over-read via crafted encrypted filename. [[bug>2449]] 
 +  * Bug fix: Slashes in filenames can cause path traversal when invalid filename characters replacement is disabled. [[bug>2450]]
-===== [[4.0]] 4.0 beta ===== +===== [[6.6.1]] 6.6.1 beta ((2026-04-01)) =====
-=== 2007-04-07 ===+
-  * FTP support (based on [[http://filezilla-project.org/|FileZilla project]]). +  * Support for OpenSSH ssh-agent. [[bug>1682]] 
-  * WinSCP can itself setup SSH tunnel to allow indirect connections through proxy SSH host. +  * Optionally connecting all workspace/folder sessions immediately. [[bug>1026]] 
-  * WinSCP executable is now named ''WinSCP.exe'' instead of ''WinSCP3.exe''. The same change applies to default installation path and //Start// menu group (for upgrades, existing ''WinSCP3'' path is preserved). +  * Preserving panel scroll position after rename. [[bug>2425]] 
-  * Added simple "typical installation" option to setup that requires no further interaction from the user (apart from interface selection for fresh installs). +  * ''Ctrl+C'' works in list views on 'Server and protocol information' dialog. 
-  * Optional minimization to taskbar notification area (system tray). +  * Preventing moving or copying a file or folder over ancestor folder with the same name. [[bug>2427]] 
-  * When executed as standalone (not installed) for the very first time, an INI file is used by default, if user has write permissions to directory, where WinSCP is executed from. +  * WebDAV/HTTP core upgraded to neon 0.37.1. 
-  * Taskbar balloons optionally used for notifications when appropriate: +  * XML parser upgraded to Expat 2.7.5. 
-   * When inactive session is disconnected. +  * Bug fix: Some menus were not working on displays to the left or above the primary display. [[bug>2423]] 
- ···* When background transfer queue is emptied (except for active session, when queue list is visible). +  * Bug fix: Mouse wheel downwards scrolling did not work on toolbar drop down lists. 
- ···* When user interaction is required, while WinSCP is minimized. + ·* Bug fix: Once any control of permissions popup box was focused the popup no longer closed when user clicked outside of it. 
-····* When new release is detected. + ·* Bug fix: Failure when closing Transfer settings dialog with //X// button while a permissions popup box control is focused. [[bug>2420]] 
-  * File checksum can be calculated from Properties dialog (providing the server supports the functionality). +  * Bug fix: Failure when switching to a session that is being reconnected. 
-  * SFTP uploads optimized. +  * Bug fix: Failure when the first bit of an SFTP response is set. [[bug>2422]] 
-  * New option for handling of remote file timestamps: //Preserve remote timestamp//. +  * Bug fix: Copying to clipboard with ''Ctrl+C'' from 'Server and protocol information' was broken. 
-  * New scripting option ''option batch continue''. When set, WinSCP ignores and skips all errors. +  * Bug fix: Protocol additional information scrolling was broken. 
-  * New scripting option ''option echo'' to enable echoing of commands being executed. +  * Bug fix: Master password dialog was missing //Help// button. 
-  * New command to execute the last ad hoc custom command. +··* Bug fix: Checking if edited/opened file was modified externally didn't work for inactive sessions. [[bug>2426]] 
-  * Tabs on Login dialog that have no usable option for current context (e.g. protocol) are hidden. +  * Bug fix: Wrapped settings values from Raw Site Settings dialog were not preserved. 
-  * "Host hasn’t answered for X seconds" message disappears itself once the response finally arrives also in scripting. +  * Bug fix: Some files modified by local custom command in SCP session fail to upload back. [[bug>2428]] 
-  * File edited in an internal editor can be reloaded (refreshed). +  * Bug fix: Whole //Key exchange// page was incorrectly hidden when //"Handles SSH key re-exchange badly"// bug was enabled. 
-  * Support for SSPI authentication. +  * Bug fix: Some message boxes leak GDI handle. [[bug>2430]] 
-  * Support for Kerberos ticket forwarding. +  * Bug fix: Login dialog leaks GDI handles. [[bug>2431]] 
-  * Configuration can be exported to an INI file. + 
-  * New command //Duplicate session//. +===== [[6.6]] 6.6 beta ((2026-02-02)) ===== 
- ·* Mirror mode for synchronization, where files are updated on any timestamp difference (i.e. even newer files are updated). + 
- ·* Custom commands history stores also the command options. +  * Synchronizing two local directories. [[bug>2020]] 
-  * Preview changes for synchronization is enabled by default. +  * Compiler upgraded to Clang/bcc32c. [[bug>618]] 
-  * Quick preset buttons for Windows and Unix systems on //Environment// tab of Login dialog (visible when advanced options are turned off only). +  * Inactive sessions can be automatically reconnected. [[bug>2232]] 
-  * It is no longer required to specify username of login dialog. User is prompted for username once required (and only if required). +  * Added dark theme support to: [[bug>1696]] 
-  * Information shown on status bar were reduced. + ···* Login dialog. [[bug>2345]] 
-  * Environment variables can be used in most configurable paths (like path to random seed file, log file, configuration INI file, PuTTY executable, folder for temporary files, private key file, etc.). The syntax is ''%NAME%''. Part of U3 support. + ···* Transfer Options dialog. 
-  * Script aborts eventually after receiving no answer for prompt (like password prompt), when running in batch mode. +   * Message boxes. 
-  * Whole authentication prompt is shown, even if it spans multiple lines. +   * Queue column headers. [[bug>2356]] 
-  * When ''Shift'' key is hold while //New session// or //Duplicate session// commands are selected, the session is opened in new instance (window) of WinSCP. +    * Progress window. 
- ·* Button //Load// on //Stored sessions tab// of Login dialog renamed to //Edit//. +   * Authentication Progress window. [[bug>2358]] 
-  * ''F1'' opens help for current tab on Login and Preferences dialogs. + ···* Bug fix: Scrollbar colors did not always reflect the color theme 
-· * What's this button on dialog caption (''?'') opens help directly. +  * Using modern directory selection dialog that scales correctly and allows creating new directory. [[bug>2373]] [[bug>2389]] 
-  * Button //Help// replaced with //Close// on Login dialog. +  * Optimized GUI when working with large subdirectory selection. [[bug>2396]] 
-  * Single log file is used for all connections of one session (background transfer connections, secondary shell connection, tunnel connection). +  * Change: Default to UTF-8 encoding in internal editor. [[bug>2397]] 
-  * During silent uninstall, user is not prompted for cleanup of application data. +  * New DigiCert EV code signing certificate valid until March 2029 is used for signing binaries. 
-  * Workaround for SSH servers based on cryptlib, which reports invalid files types in response to ''SSH_FXP_LSTAT'' request. +  * TLS/SSL core upgraded to OpenSSL 3.5.5. 
-  * Configuration of GSSAPI/SSPI authentication is exported to PuTTY sessions. +  * WebDAV/HTTP core upgraded to neon 0.36.0. 
-  * When changing configuration storage, also caches (change directory cache, accepted SSH host keys, accepted banners) are transferred to the new storage. +  * XML parser upgraded to Expat 2.7.4. 
-  * Context menu of permissions popup and input boxes has clipboard management commands. +  * Installer upgraded to Inno Setup 6.7.0 with dark mode support enabled. 
-  * Menu item captions capitalized according to Windows standard. +  * Increased WinSCP memory limit to 4 GB. [[bug>2412]] 
-  * More internal error messages from PuTTY code are being localized. +··* Defined and implemented interface for the .NET library. By @mjkent. [[bug>856]] 
-  * When saving the edited session under the same name, overwrite confirmation is not requested. +  * Optimized TLS/SSL AES implementation. 
-  * Shell options of //SCP tab// of login dialog redesigned. +  * Restoring ability to restart Explorer to allow upgrade of drag&drop shell extension, when installing for current user, as after-restart replacement is not possible without Administrator privileges. [[bug>2381]] 
-  * Timestamps are saved in numerical format into an INI file for portability among systems with different date/time format. +  * MSI toolset updated to WiX 5. 
-  * Status bar message about preset auto-selection can be clicked to reveal information about the preset. +  * Commands to copy paths to the clipboard on the Synchronization checklist window. 
-  * Preset information dialog has //Configure// button that opens preset preferences. +  * Cryptography optimization. 
-  * Detection of OpenSSH sftp-server is more strict, not to apply on other SFTP servers running under OpenSSH. +··* Support long AWS/S3 session tokens. [[bug>2403]] 
-  * Pattern hint link for log file name added. + * Prevent hang when new device is attached or removed while some mapped network drive is not available. [[bug>2382]] 
-  * For fatal errors (e.g. "lost connection"), original cause of the problem is kept as a top message, as opposite to regular errors, where contextual error message is on top. +  * Copy and paste improvements: 
-  * Buttons //Login// and //Save// on Login dialog swapped. +   * Consistently renaming local files dropped or pasted back to their source directory to avoid collisions. 
-  * When //Handles SSH-2 key re-exchange badly// bug is enabled, the //Key exchange// tab is hidden. + ···* Bug fix: When copying local files to clipboard from system context menu, "cut" state of previously cut files was not cleared. 
-  * Web page shortcuts in //Start// menu are now direct shortcuts instead of shortcuts to ''URL'' file. +  * Not redundantly verifying WebDAV or S3 certificate in Windows Certificate store if it is already marked as trusted in session settings. [[bug>2404]] 
-  * New button //What's new// on information box about updates. +  * Provide SNI when opening FTP data connection. [[bug>2410]] 
-  * Bug fix: Failure when changing languages (particularly with "Data execution protection" enabled). +··* Optimized synchronization checklist sorting. 
-  * Bug fix: Failure, when remote command had character ''%'' in its error output. +  * Support for Beyond Compare 5 in Compare Files extension. [[bug>2417]] 
-  * Bug fix: //Close// button were default even, if path box on //Space available// tab of Server and protocol information dialog had focus. +  * Convert unsupported SSH proxy to SSH tunnel when importing site from PuTTY. [[bug>2408]] 
- ·* Bug fix: Remote home directory of session was set to current working directory, after switching sessions. +··* FTP directory listing falls back to the other active/passive mode, consistently with file transfers. 
- ·* Bug fix: Local home directory were changing while switching sessions, even when changing of local panel state with sessions is disabled. +  * Consistently calling command to open window with specific directory //Explore//, instead of sometimes //Browse//. 
-  * Bug fix: INI file specified by filename-only using ''/ini'' parameter was not looked for in current working directory. +  * Consistently referring to file last modification timestamp column as //Date modified//. 
-  * Bug fix: Ad hoc command executed from file panel context menu was executed for selected files, despite the menu being opened for not-selected file. +  * With INI file provided on command-line, using the same INI file when starting a new instance. 
-  * Bug fix: Infinite loop of error messages when connection was broken while timeout message was being shown. +  * Windows shell local file copy status window is centered on the main window. 
-  * Bug fix: Trailing delimiter text were occasionally left in remote command output. +  * Made taskbar flashing configurable in GUI. [[bug>2411]] 
- ·* Bug fix: Some authentication progress steps were not shown on authentication window for secondary shell sessions. +  * Control labels on transfer settings dialogs do not show keyboard accelerator cue, until ''Alt'' key is pressed. 
- ·* Bug fix: Inactive sessions were not kept alive. +  * Not using drag images even with directory trees. [[bug>1274]] 
-  * Bug fix: Incorrect sizing of internal editor windows opened on non-primary monitor. +  * Allow configuring checksum commands. [[bug>2394]] 
-  * Bug fix: Automatic retry after timeout was not working. +  * Updated to JCL library 2.8.1. 
-  * Bug fix: Stored session may be lost when letter case was changed solely during rename.  +  * Updating jump list only when running with GUI. 
-  * Bug fix: It was not possible to cancel text mode upload with SCP protocol. +  * Made space on permissions box for longer translations. [[bug>2398]] 
-  * Bug fix: Change directory cache may become corrupted when using INI file for configuration. +  * Opening //Default Apps// //Settings// page directly to open it in the foreground and avoid flashing //Control Panel// window. 
-  * Bug fix: Drag&drop download was not working, if relative path was used for temporary folder. Part of U3 support. +  * Improving order in which Windows Narrator reads window controls. 
-  * Bug fix: After startup, button on taskbar was not "pressed", even if WinSCP login dialog had focus. +  * All edit boxes with history consistently do not auto complete and show 16 entries in the drop down. 
-  * Bug fix: Failure when closing console window. +  * Removed obsolete //Preserve remote timestamp// session settings. 
-  * Bug fix: When moving files from remote directory tree, the tree was not updated after operation, leaving icon for no-longer-existing directory. +  * Bug fix: Local file with invalid characters replaced could not be explored from the Synchronization checklist window. 
-  * Bug fix: Octal display of file permissions was not filled if no permissions were set for a file. +· * Bug fix: Files modified by local custom command are not always uploaded to the correct remote directory. [[bug>2370]] 
-  * Bug fix: Failure to change attributes of local files was not reported sometime.+  * Bug fix: List of network drives in drive drop down and directory tree did not always match. 
 +  * Bug fix: Host key prompt did not have the default button. 
 +  * Bug fix: When the local path specified on Open directory/Location profile dialog is not existing, when browsing for a new path, the trailing part of the nonexisting path was appended to the new path. 
 +  * Bug fix: Trying to enter an invalid link in local panel fails silently. 
 +  * Bug fix: After FTP data connection fails to open further use of the session is broken. 
 +  * Bug fix: Pasting cut files from the clipboard into a local panel copies them instead of moving them. [[bug>2400]] 
 +  * Bug fix: Some edits did not save their value to history when submitting with ''Enter''. 
 +  * Bug fix: Too long edit history dropdown can overflow monitor bounds. [[bug>2432]] 
 +  * Bug fix: Message box texts and some control labels are not visible to screen readers. [[bug>2413]] 
 +  * Bug fix: Failure when clicking tab close button while the session is already being closed. [[bug>2416]] 
 + 
 +===== [[6.5.9]] 6.5.9 (not released yet) ((2026-09-10)) ===== 
 + 
 +  * Back-propagated fixes from 6.6.4 release: 
 + ···* Bug fix: Invalid language code for Serbian was used for Microsoft Store package. [[bug>2460]] 
 + 
 +===== [[6.5.8]] 6.5.8 ((2026-09-10)) ===== 
 + 
 +  * This is Microsoft Store-only release that fixes packaging problem of 6.5.7. The actual binaries are still 6.5.7. 
 +   * Bug fix: Cannot install from Microsoft Store because of invalid 'sr' language. [[bug>;2460]] 
 + 
 +===== [[6.5.7]] 6.5.7 ((2026-09-09)) ===== 
 + 
 +  * Translations completed: Croatian, Finnish, Georgian, Italian and Serbian, and updated: Slovenian. 
 +· * TLS/SSL core upgraded to OpenSSL 3.3.7. 
 +  * SSH private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.85]]. SSH core upgraded to include some fixes. \\ It brings the following change: 
 +····* Security issue: fixed a remotely triggerable use-after-free in Pageant. [[pbug>pageant-deferred-decryption-uaf]] 
 +   * Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. [[pbug>etm-large-packet-overflow]] 
 +   * Security issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. [[pbug>argon2-parameter-checks]] 
 + ···* Denial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. [[pbug>maxpkt-0-tight-loop]] 
 + ···* Security issue: fixed a remotely triggerable double-free in RSA key exchange. [[pbug>rsakex-double-free]] 
 +   * Minor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. [[pbug>ecdsa-remotely-triggerable-assertion]] 
 +  * Back-propagated fixes from 6.6.2 beta release: 
 +   * Bug fix: Failure setting ''Session.DebugLogPath'' when running in impersonated context. [[bug>2441]] 
 +  * Bug fix: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. CVE-2026-45447 fix from OpenSSL 3.4.6. 
 + 
 +===== [[6.5.6]] 6.5.6 ((2026-03-25)) ===== 
 + 
 +  * Translations completed: Macedonian, and updated: Lithuanian, and Russian. 
 +  * TLS/SSL core upgraded to OpenSSL 3.3.6. 
 +  * Back-propagated improvements from 6.6–6.6.1 beta release: 
 +   * New DigiCert EV code signing certificate valid until March 2029 is used for signing binaries. 
 + ···* XML parser upgraded to Expat 2.7.5. 
 +   * Support for Beyond Compare 5 in Compare Files extension. [[bug>2417]] 
 + ···* Bug fix: Checking if edited/opened file was modified externally didn't work for inactive sessions. [[bug>2426]] 
 + 
 +===== [[6.5.5]] 6.5.5 ((2025-11-19)) ===== 
 + 
 +  * Translation updated: Vietnamese. 
 +  * Bug fix: Pasting files using local directory tree context menu pastes them to the current directory, instead of the selected one. 
 +  * Bug fix: Failure when opening site imported from PuTTY with unsupported SSH proxy. [[bug>2407]] 
 +  * Bug fix: Incorrect hostname validation when connecting to S3 endpoint with certificate that does not cover root S3 hostname. [[bug>2409]] 
 + 
 +===== [[6.5.4]] 6.5.4 ((2025-10-16)) ===== 
 + 
 +  * Translations updated: Belarusian and Georgian. 
 +  * TLS/SSL core upgraded to OpenSSL 3.3.5. 
 +  * XML parser upgraded to Expat 2.7.3. 
 +· * Added new ''ap-southeast-6'' AWS region. 
 +  * Bug fix: When restored after operation completed while minimized the window is disabled. [[bug>2393]] 
 +  * Bug fix: Command ''md5sums'' is incorrectly used to calculate MD5 checksum instead of ''md5sum''. [[bug>2392]] 
 +  * Bug fix: Incomplete FTP upload when the source stream/stdin reads less than requested. [[bug>2395]] 
 +  * Bug fix: ''Shift''-clicking //OK// button on Synchronization checklist window when synchronization in the background was not possible still closed the window. 
 +  * Bug fix: Failure after reloading file panel when number of files decreases. [[bug>2402]] 
 +  * Bug fix: Failure or silently missing headers when when S3 request headers were too long.
[[history_old|Older versions]] [[history_old|Older versions]]
~~NOTOC~~ ~~NOTOC~~
 +~~ARCHIVE=history_old~~

Last modified: by martin