{"format": 1, "mode": "release", "from_release": null, "to_release": {"date": "2025-02-20", "build": "14.17", "major": "14", "minor": 17, "manual": "14", "status": "stable", "doc_git": "", "version": "14.17", "eol_date": "2026-11-12", "date_text": "2025-02-20", "supported": true, "manual_url": "/docs/14/release-14-17.html", "source_url": "/docs/release/14.17/", "entry_count": 2, "placeholder": false, "content_hash": "8c4c80ee47710deba9948dfa8a365065eb542e225638f6b36056c67654af2397", "manual_build": "14.24", "source_as_of": "", "changes_count": 2, "doc_loaded_at": "2026-09-25T02:22:44.760693", "migration_html": "<p>A dump/restore is not required for those running 14.X.</p>\n<p>However, if you are upgrading from a version earlier than 14.14, see <a href=\"/docs/14/release-14-14.html\" title=\"E.11. Release 14.14\">Section E.11</a>.</p>", "compatibility_count": 0, "label": "14.17", "status_label": "Supported", "eol": "2026-11-12", "age_days": 586, "support_days": 44}, "groups": [{"date": "2025-02-20", "build": "14.17", "major": "14", "minor": 17, "manual": "14", "status": "stable", "doc_git": "", "version": "14.17", "eol_date": "2026-11-12", "date_text": "2025-02-20", "supported": true, "manual_url": "/docs/14/release-14-17.html", "source_url": "/docs/release/14.17/", "entry_count": 2, "placeholder": false, "content_hash": "8c4c80ee47710deba9948dfa8a365065eb542e225638f6b36056c67654af2397", "manual_build": "14.24", "source_as_of": "", "changes_count": 2, "doc_loaded_at": "2026-09-25T02:22:44.760693", "migration_html": "<p>A dump/restore is not required for those running 14.X.</p>\n<p>However, if you are upgrading from a version earlier than 14.14, see <a href=\"/docs/14/release-14-14.html\" title=\"E.11. Release 14.14\">Section E.11</a>.</p>", "compatibility_count": 0, "label": "14.17", "status_label": "Supported", "eol": "2026-11-12", "age_days": 586, "support_days": 44, "entries": [{"id": "14.17-5608e94c3b2dd6d1", "cves": ["CVE-2025-1094"], "html": "<p>Improve behavior of <span>libpq</span>'s quoting functions (Andres Freund, Tom Lane) <a href=\"https://postgr.es/c/985908df1\">§</a> <a href=\"https://postgr.es/c/c08309584\">§</a> <a href=\"https://postgr.es/c/f864a4cdf\">§</a></p>\n<p>The changes made for CVE-2025-1094 had one serious oversight: <code>PQescapeLiteral()</code> and <code>PQescapeIdentifier()</code> failed to honor their string length parameter, instead always reading to the input string's trailing null. This resulted in including unwanted text in the output, if the caller intended to truncate the string via the length parameter. With very bad luck it could cause a crash due to reading off the end of memory.</p>\n<p>In addition, modify all these quoting functions so that when invalid encoding is detected, an invalid sequence is substituted for just the first byte of the presumed character, not all of it. This reduces the risk of problems if a calling application performs additional processing on the quoted string.</p>", "text": "Improve behavior of libpq's quoting functions (Andres Freund, Tom Lane) § § § The changes made for CVE-2025-1094 had one serious oversight: PQescapeLiteral() and PQescapeIdentifier() failed to honor their string length parameter, instead always reading to the input string's trailing null. This resulted in including unwanted text in the output, if the caller intended to truncate the string via the length parameter. With very bad luck it could cause a crash due to reading off the end of memory. In addition, modify all these quoting functions so that when invalid encoding is detected, an invalid sequence is substituted for just the first byte of the presumed character, not all of it. This reduces the risk of problems if a calling application performs additional processing on the quoted string.", "title": "Improve behavior of libpq's quoting functions", "commits": ["985908df1", "c08309584", "f864a4cdf"], "section": "Changes", "category": "security", "source_url": "/docs/release/14.17/#id-1.11.6.13.5", "source_hash": "32570819e2fd6738378a333fb55e614f6e8140c862bc93136287b2a6318bd45d", "section_path": ["Changes"], "commit_groups": [["111f4dd27", "1f7a05324", "22ffbbf24", "985908df1", "a92db3d02", "efdadeb22"], ["2226a2e26", "3977bd298", "644b7d686", "9f052613e", "a7f95859e", "f864a4cdf"], ["3abe6e04c", "991a60a9f", "9f45e6a91", "c08309584", "d6d29b213", "e782a63cc"]], "identity_text": "Improve behavior of libpq's quoting functions (Andres Freund, Tom Lane) The changes made for CVE-2025-1094 had one serious oversight: PQescapeLiteral() and PQescapeIdentifier() failed to honor their string length parameter, instead always reading to the input string's trailing null. This resulted in including unwanted text in the output, if the caller intended to truncate the string via the length parameter. With very bad luck it could cause a crash due to reading off the end of memory. In addition, modify all these quoting functions so that when invalid encoding is detected, an invalid sequence is substituted for just the first byte of the presumed character, not all of it. This reduces the risk of problems if a calling application performs additional processing on the quoted string.", "commit_aliases": ["111f4dd27", "1f7a05324", "2226a2e26", "22ffbbf24", "3977bd298", "3abe6e04c", "644b7d686", "985908df1", "991a60a9f", "9f052613e", "9f45e6a91", "a7f95859e", "a92db3d02", "c08309584", "d6d29b213", "e782a63cc", "efdadeb22", "f864a4cdf"], "source_commits": ["985908df1", "c08309584", "f864a4cdf"], "source_entry_id": "14.17/changes/001", "db_id": "93606c971fb27b15f66a071ba02ed94f", "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e", "relations": [{"rule": 2, "type": "equivalent", "target": "10e97b40c924a8c01435396c5cec5c41", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}}, {"rule": 2, "type": "equivalent", "target": "4646f216ed794505b943757978907404", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}}, {"rule": 2, "type": "equivalent", "target": "9f693cbaa1b27909dc5ea6b2372ebffc", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}}, {"rule": 2, "type": "equivalent", "target": "c7960ab441796e11f499e5bba716166e", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}}], "version": "14.17", "category_label": "Security", "also_in": [], "variants": [], "related_changes": [{"db_id": "c7960ab441796e11f499e5bba716166e", "kind": "equivalent", "version": "17.4", "label": "17.4", "title": "Improve behavior of libpq's quoting functions", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}, "url": "/docs/compare/?release=17.4#17.4-d477ecad89a3b81e", "source_url": "/docs/release/17.4/#RELEASE-17-4-CHANGES"}, {"db_id": "10e97b40c924a8c01435396c5cec5c41", "kind": "equivalent", "version": "16.8", "label": "16.8", "title": "Improve behavior of libpq's quoting functions", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}, "url": "/docs/compare/?release=16.8#16.8-37cc8c2afc9a961e", "source_url": "/docs/release/16.8/#RELEASE-16-8-CHANGES"}, {"db_id": "4646f216ed794505b943757978907404", "kind": "equivalent", "version": "15.12", "label": "15.12", "title": "Improve behavior of libpq's quoting functions", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}, "url": "/docs/compare/?release=15.12#15.12-43f9b4124d940cad", "source_url": "/docs/release/15.12/#id-1.11.6.13.5"}, {"db_id": "9f693cbaa1b27909dc5ea6b2372ebffc", "kind": "equivalent", "version": "13.20", "label": "13.20", "title": "Improve behavior of libpq's quoting functions", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}, "url": "/docs/compare/?release=13.20#13.20-27312e34c6df83be", "source_url": "/docs/release/13.20/#id-1.11.6.9.6"}]}, {"id": "14.17-65de86b1400213de", "cves": [], "html": "<p>Fix crash involving triggers on partitioned tables that make use of transition tables (Kyotaro Horiguchi) <a href=\"https://postgr.es/c/8e58f8024\">§</a></p>\n<p>If there are both <code>AFTER UPDATE</code> and <code>AFTER DELETE</code> triggers, the need for transition tables was determined incorrectly, leading to a crash during cross-partition updates.</p>", "text": "Fix crash involving triggers on partitioned tables that make use of transition tables (Kyotaro Horiguchi) § If there are both AFTER UPDATE and AFTER DELETE triggers, the need for transition tables was determined incorrectly, leading to a crash during cross-partition updates.", "title": "Fix crash involving triggers on partitioned tables that make use of transition tables", "commits": ["8e58f8024"], "section": "Changes", "category": "bugfix", "source_url": "/docs/release/14.17/#id-1.11.6.13.5", "source_hash": "50657316133c56037d228fd8d7823d9c119531d2c6565cda4aa5fc549bac68db", "section_path": ["Changes"], "commit_groups": [["139beb035", "520905824", "6342d49d8", "773c51dd3", "8e58f8024", "a37c83d1e"]], "identity_text": "Fix crash involving triggers on partitioned tables that make use of transition tables (Kyotaro Horiguchi) If there are both AFTER UPDATE and AFTER DELETE triggers, the need for transition tables was determined incorrectly, leading to a crash during cross-partition updates.", "commit_aliases": ["139beb035", "520905824", "6342d49d8", "773c51dd3", "8e58f8024", "a37c83d1e"], "source_commits": ["8e58f8024"], "source_entry_id": "14.17/changes/002", "db_id": "270b28b4fd5b1a64db6fd2c6e7d0616b", "patch_ids": ["5d8e70787e916c17a06f92431d233158"], "statement_hash": "a2faa042f0235ab875abe5bafd2b3e16d356c92bdc679749202096ff8fc0ab9b", "relations": [{"rule": 2, "type": "equivalent", "target": "e2e87a9b031a55579df9825603d85daf", "evidence": {"same_day": true, "patch_ids": ["5d8e70787e916c17a06f92431d233158"], "statement_hash": "a2faa042f0235ab875abe5bafd2b3e16d356c92bdc679749202096ff8fc0ab9b"}}], "version": "14.17", "category_label": "Bug fixes", "also_in": [], "variants": [], "related_changes": [{"db_id": "e2e87a9b031a55579df9825603d85daf", "kind": "equivalent", "version": "13.20", "label": "13.20", "title": "Fix crash involving triggers on partitioned tables that make use of transition tables", "evidence": {"same_day": true, "patch_ids": ["5d8e70787e916c17a06f92431d233158"], "statement_hash": "a2faa042f0235ab875abe5bafd2b3e16d356c92bdc679749202096ff8fc0ab9b"}, "url": "/docs/compare/?release=13.20#13.20-79f82e3a043f6ecd", "source_url": "/docs/release/13.20/#id-1.11.6.9.6"}]}]}], "stats": [{"key": "all", "label": "All changes", "count": 2}, {"key": "feature", "label": "Features", "count": 0}, {"key": "bugfix", "label": "Bug fixes", "count": 1}, {"key": "security", "label": "Security", "count": 1}, {"key": "performance", "label": "Performance", "count": 0}, {"key": "compatibility", "label": "Compatibility", "count": 0}, {"key": "improvement", "label": "Improvements", "count": 0}], "total": 2, "release_count": 1, "cross_major": false, "cve_count": 1, "cves": [{"id": "CVE-2025-1094", "url": "https://www.postgresql.org/support/security/CVE-2025-1094/", "fixed": {"13": "13.19", "14": "14.16", "15": "15.11", "16": "16.7", "17": "17.3"}, "score": 8.1, "title": "Improve behavior of libpq's quoting functions", "vector": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "cna_url": "https://cveawg.mitre.org/api/cve/CVE-2025-1094", "affected": {"13": "13", "14": "14", "15": "15", "16": "16", "17": "17"}, "component": "core server", "published": {"13": "2025-02-13", "14": "2025-02-13", "15": "2025-02-13", "16": "2025-02-13", "17": "2025-02-13"}, "introduced": {}, "cvss_version": "3.0", "description_en": "Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.", "affected_ranges": [{"from": "0", "until": "13.19"}, {"from": "14", "until": "14.16"}, {"from": "15", "until": "15.11"}, {"from": "16", "until": "16.7"}, {"from": "17", "until": "17.3"}], "first_published": "2025-02-13", "fixed_version": "14.16"}], "cve_available": true, "remaining_cves": [], "security_regressions": [], "warnings": [], "candidate_count": 2, "already_in_source_count": 0, "duplicate_count": 0, "excluded_count": 0, "exclusions": [], "source_as_of": "2026-09-26", "security_as_of": "2026-09-26"}