{"format": 1, "mode": "release", "from_release": null, "to_release": {"date": "2025-02-20", "build": "15.12", "major": "15", "minor": 12, "manual": "15", "status": "stable", "doc_git": "", "version": "15.12", "eol_date": "2027-11-11", "date_text": "2025-02-20", "supported": true, "manual_url": "/docs/15/release-15-12.html", "source_url": "/docs/release/15.12/", "entry_count": 1, "placeholder": false, "content_hash": "3340257554cbbecff3a899b201ff4b2fd8f840b7e6861db0e54026d8625568f5", "manual_build": "15.19", "source_as_of": "", "changes_count": 1, "doc_loaded_at": "2026-09-25T02:22:44.760693", "migration_html": "<p>A dump/restore is not required for those running 15.X.</p>\n<p>However, if you are upgrading from a version earlier than 15.9, see <a href=\"/docs/15/release-15-9.html\" title=\"E.11. Release 15.9\">Section E.11</a>.</p>", "compatibility_count": 0, "label": "15.12", "status_label": "Supported", "eol": "2027-11-11", "age_days": 586, "support_days": 408}, "groups": [{"date": "2025-02-20", "build": "15.12", "major": "15", "minor": 12, "manual": "15", "status": "stable", "doc_git": "", "version": "15.12", "eol_date": "2027-11-11", "date_text": "2025-02-20", "supported": true, "manual_url": "/docs/15/release-15-12.html", "source_url": "/docs/release/15.12/", "entry_count": 1, "placeholder": false, "content_hash": "3340257554cbbecff3a899b201ff4b2fd8f840b7e6861db0e54026d8625568f5", "manual_build": "15.19", "source_as_of": "", "changes_count": 1, "doc_loaded_at": "2026-09-25T02:22:44.760693", "migration_html": "<p>A dump/restore is not required for those running 15.X.</p>\n<p>However, if you are upgrading from a version earlier than 15.9, see <a href=\"/docs/15/release-15-9.html\" title=\"E.11. Release 15.9\">Section E.11</a>.</p>", "compatibility_count": 0, "label": "15.12", "status_label": "Supported", "eol": "2027-11-11", "age_days": 586, "support_days": 408, "entries": [{"id": "15.12-43f9b4124d940cad", "cves": ["CVE-2025-1094"], "html": "<p>Improve behavior of <span>libpq</span>'s quoting functions (Andres Freund, Tom Lane) <a href=\"https://postgr.es/c/22ffbbf24\">§</a> <a href=\"https://postgr.es/c/e782a63cc\">§</a> <a href=\"https://postgr.es/c/2226a2e26\">§</a></p>\n<p>The changes made for CVE-2025-1094 had one serious oversight: <code>PQescapeLiteral()</code> and <code>PQescapeIdentifier()</code> failed to honor their string length parameter, instead always reading to the input string's trailing null. This resulted in including unwanted text in the output, if the caller intended to truncate the string via the length parameter. With very bad luck it could cause a crash due to reading off the end of memory.</p>\n<p>In addition, modify all these quoting functions so that when invalid encoding is detected, an invalid sequence is substituted for just the first byte of the presumed character, not all of it. This reduces the risk of problems if a calling application performs additional processing on the quoted string.</p>", "text": "Improve behavior of libpq's quoting functions (Andres Freund, Tom Lane) § § § The changes made for CVE-2025-1094 had one serious oversight: PQescapeLiteral() and PQescapeIdentifier() failed to honor their string length parameter, instead always reading to the input string's trailing null. This resulted in including unwanted text in the output, if the caller intended to truncate the string via the length parameter. With very bad luck it could cause a crash due to reading off the end of memory. In addition, modify all these quoting functions so that when invalid encoding is detected, an invalid sequence is substituted for just the first byte of the presumed character, not all of it. This reduces the risk of problems if a calling application performs additional processing on the quoted string.", "title": "Improve behavior of libpq's quoting functions", "commits": ["2226a2e26", "22ffbbf24", "e782a63cc"], "section": "Changes", "category": "security", "source_url": "/docs/release/15.12/#id-1.11.6.13.5", "source_hash": "a860981aec768960d874cd7a0efea69e5eb7074173cf67a6f6b6cbdfbe5c5495", "section_path": ["Changes"], "commit_groups": [["111f4dd27", "1f7a05324", "22ffbbf24", "985908df1", "a92db3d02", "efdadeb22"], ["2226a2e26", "3977bd298", "644b7d686", "9f052613e", "a7f95859e", "f864a4cdf"], ["3abe6e04c", "991a60a9f", "9f45e6a91", "c08309584", "d6d29b213", "e782a63cc"]], "identity_text": "Improve behavior of libpq's quoting functions (Andres Freund, Tom Lane) The changes made for CVE-2025-1094 had one serious oversight: PQescapeLiteral() and PQescapeIdentifier() failed to honor their string length parameter, instead always reading to the input string's trailing null. This resulted in including unwanted text in the output, if the caller intended to truncate the string via the length parameter. With very bad luck it could cause a crash due to reading off the end of memory. In addition, modify all these quoting functions so that when invalid encoding is detected, an invalid sequence is substituted for just the first byte of the presumed character, not all of it. This reduces the risk of problems if a calling application performs additional processing on the quoted string.", "commit_aliases": ["111f4dd27", "1f7a05324", "2226a2e26", "22ffbbf24", "3977bd298", "3abe6e04c", "644b7d686", "985908df1", "991a60a9f", "9f052613e", "9f45e6a91", "a7f95859e", "a92db3d02", "c08309584", "d6d29b213", "e782a63cc", "efdadeb22", "f864a4cdf"], "source_commits": ["2226a2e26", "22ffbbf24", "e782a63cc"], "source_entry_id": "15.12/changes/001", "db_id": "4646f216ed794505b943757978907404", "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e", "relations": [{"rule": 2, "type": "equivalent", "target": "10e97b40c924a8c01435396c5cec5c41", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}}, {"rule": 2, "type": "equivalent", "target": "93606c971fb27b15f66a071ba02ed94f", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}}, {"rule": 2, "type": "equivalent", "target": "9f693cbaa1b27909dc5ea6b2372ebffc", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}}, {"rule": 2, "type": "equivalent", "target": "c7960ab441796e11f499e5bba716166e", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}}], "version": "15.12", "category_label": "Security", "also_in": [], "variants": [], "related_changes": [{"db_id": "c7960ab441796e11f499e5bba716166e", "kind": "equivalent", "version": "17.4", "label": "17.4", "title": "Improve behavior of libpq's quoting functions", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}, "url": "/docs/compare/?release=17.4#17.4-d477ecad89a3b81e", "source_url": "/docs/release/17.4/#RELEASE-17-4-CHANGES"}, {"db_id": "10e97b40c924a8c01435396c5cec5c41", "kind": "equivalent", "version": "16.8", "label": "16.8", "title": "Improve behavior of libpq's quoting functions", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}, "url": "/docs/compare/?release=16.8#16.8-37cc8c2afc9a961e", "source_url": "/docs/release/16.8/#RELEASE-16-8-CHANGES"}, {"db_id": "93606c971fb27b15f66a071ba02ed94f", "kind": "equivalent", "version": "14.17", "label": "14.17", "title": "Improve behavior of libpq's quoting functions", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}, "url": "/docs/compare/?release=14.17#14.17-5608e94c3b2dd6d1", "source_url": "/docs/release/14.17/#id-1.11.6.13.5"}, {"db_id": "9f693cbaa1b27909dc5ea6b2372ebffc", "kind": "equivalent", "version": "13.20", "label": "13.20", "title": "Improve behavior of libpq's quoting functions", "evidence": {"same_day": true, "patch_ids": ["0e981f968b952d9cf7d0d6a3a22cc247", "6f7805d8e67721bf35bd17443b6b5f5d", "b0ea6cce1c2d6113f422ff8aee23ccfc"], "statement_hash": "82ceafbe009cc55c8bbb783c79cd0468287302477d70ae849a35027e0bec658e"}, "url": "/docs/compare/?release=13.20#13.20-27312e34c6df83be", "source_url": "/docs/release/13.20/#id-1.11.6.9.6"}]}]}], "stats": [{"key": "all", "label": "All changes", "count": 1}, {"key": "feature", "label": "Features", "count": 0}, {"key": "bugfix", "label": "Bug fixes", "count": 0}, {"key": "security", "label": "Security", "count": 1}, {"key": "performance", "label": "Performance", "count": 0}, {"key": "compatibility", "label": "Compatibility", "count": 0}, {"key": "improvement", "label": "Improvements", "count": 0}], "total": 1, "release_count": 1, "cross_major": false, "cve_count": 1, "cves": [{"id": "CVE-2025-1094", "url": "https://www.postgresql.org/support/security/CVE-2025-1094/", "fixed": {"13": "13.19", "14": "14.16", "15": "15.11", "16": "16.7", "17": "17.3"}, "score": 8.1, "title": "Improve behavior of libpq's quoting functions", "vector": "AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H", "cna_url": "https://cveawg.mitre.org/api/cve/CVE-2025-1094", "affected": {"13": "13", "14": "14", "15": "15", "16": "16", "17": "17"}, "component": "core server", "published": {"13": "2025-02-13", "14": "2025-02-13", "15": "2025-02-13", "16": "2025-02-13", "17": "2025-02-13"}, "introduced": {}, "cvss_version": "3.0", "description_en": "Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.", "affected_ranges": [{"from": "0", "until": "13.19"}, {"from": "14", "until": "14.16"}, {"from": "15", "until": "15.11"}, {"from": "16", "until": "16.7"}, {"from": "17", "until": "17.3"}], "first_published": "2025-02-13", "fixed_version": "15.11"}], "cve_available": true, "remaining_cves": [], "security_regressions": [], "warnings": [], "candidate_count": 1, "already_in_source_count": 0, "duplicate_count": 0, "excluded_count": 0, "exclusions": [], "source_as_of": "2026-09-26", "security_as_of": "2026-09-26"}