{"format": 1, "mode": "release", "from_release": null, "to_release": {"date": "2026-02-26", "build": "17.9", "major": "17", "minor": 9, "manual": "17", "status": "stable", "doc_git": "", "version": "17.9", "eol_date": "2029-11-08", "date_text": "2026-02-26", "supported": true, "manual_url": "/docs/17/release-17-9.html", "source_url": "/docs/release/17.9/", "entry_count": 6, "placeholder": false, "content_hash": "5cc2fa2fa4a262cbefe6dceba9a0f840ac5af5a0b91b8b2255922687c46cefb6", "manual_build": "17.11", "source_as_of": "", "changes_count": 6, "doc_loaded_at": "2026-09-25T02:22:44.760693", "migration_html": "<p>A dump/restore is not required for those running 17.X.</p>\n<p>However, if you are upgrading from a version earlier than 17.6, see <a href=\"/docs/17/release-17-6.html\" title=\"E.6. Release 17.6\">Section E.6</a>.</p>", "compatibility_count": 0, "label": "17.9", "status_label": "Supported", "eol": "2029-11-08", "age_days": 212, "support_days": 1139}, "groups": [{"date": "2026-02-26", "build": "17.9", "major": "17", "minor": 9, "manual": "17", "status": "stable", "doc_git": "", "version": "17.9", "eol_date": "2029-11-08", "date_text": "2026-02-26", "supported": true, "manual_url": "/docs/17/release-17-9.html", "source_url": "/docs/release/17.9/", "entry_count": 6, "placeholder": false, "content_hash": "5cc2fa2fa4a262cbefe6dceba9a0f840ac5af5a0b91b8b2255922687c46cefb6", "manual_build": "17.11", "source_as_of": "", "changes_count": 6, "doc_loaded_at": "2026-09-25T02:22:44.760693", "migration_html": "<p>A dump/restore is not required for those running 17.X.</p>\n<p>However, if you are upgrading from a version earlier than 17.6, see <a href=\"/docs/17/release-17-6.html\" title=\"E.6. Release 17.6\">Section E.6</a>.</p>", "compatibility_count": 0, "label": "17.9", "status_label": "Supported", "eol": "2029-11-08", "age_days": 212, "support_days": 1139, "entries": [{"id": "17.9-80ecbcad5117683e", "cves": [], "html": "<p>Fix failure after replaying a multixid truncation record from WAL that was generated by an older minor version (Heikki Linnakangas) <a href=\"https://postgr.es/c/4a36c89f1\">§</a></p>\n<p>Erroneous logic for coping with the way that previous versions handled multixid wraparound led to replay failure, with messages like <span>“<span>could not access status of transaction</span>”</span>. A typical scenario in which this could occur is a standby server of the latest minor version consuming WAL from a primary server of an older version.</p>", "text": "Fix failure after replaying a multixid truncation record from WAL that was generated by an older minor version (Heikki Linnakangas) § Erroneous logic for coping with the way that previous versions handled multixid wraparound led to replay failure, with messages like “could not access status of transaction”. A typical scenario in which this could occur is a standby server of the latest minor version consuming WAL from a primary server of an older version.", "title": "Fix failure after replaying a multixid truncation record from WAL that was generated by an older minor version", "commits": ["4a36c89f1"], "section": "Changes", "category": "bugfix", "source_url": "/docs/release/17.9/#RELEASE-17-9-CHANGES", "source_hash": "5301788c87a3db984faace17c7bd4a7a012ab0d7cc19a79a859c975b284beed6", "section_path": ["Changes"], "commit_groups": [["23064542f", "4a36c89f1", "547a8aaa7", "817f74600", "899de38d8"]], "identity_text": "Fix failure after replaying a multixid truncation record from WAL that was generated by an older minor version (Heikki Linnakangas) Erroneous logic for coping with the way that previous versions handled multixid wraparound led to replay failure, with messages like could not access status of transaction. A typical scenario in which this could occur is a standby server of the latest minor version consuming WAL from a primary server of an older version.", "commit_aliases": ["23064542f", "4a36c89f1", "547a8aaa7", "817f74600", "899de38d8"], "source_commits": ["4a36c89f1"], "source_entry_id": "17.9/changes/001", "db_id": "269e20cac41b248d80f469e35fb3be04", "patch_ids": ["e8c592597fe0c522a838714ea94d192e"], "statement_hash": "cf611d327c6efbb05b8c3c3eec25baadc4b81f3015eda12031c5dfd70647d75d", "relations": [{"rule": 2, "type": "equivalent", "target": "54acee06ad9ee6f00cba048e48dfdadc", "evidence": {"same_day": true, "patch_ids": ["e8c592597fe0c522a838714ea94d192e"], "statement_hash": "cf611d327c6efbb05b8c3c3eec25baadc4b81f3015eda12031c5dfd70647d75d"}}, {"rule": 2, "type": "equivalent", "target": "6d7df9238b789e2555fe1290d455a61a", "evidence": {"same_day": true, "patch_ids": ["e8c592597fe0c522a838714ea94d192e"], "statement_hash": "cf611d327c6efbb05b8c3c3eec25baadc4b81f3015eda12031c5dfd70647d75d"}}, {"rule": 2, "type": "equivalent", "target": "ac9d069b97f39c99f4c9540523c6dd01", "evidence": {"same_day": true, "patch_ids": ["e8c592597fe0c522a838714ea94d192e"], "statement_hash": "cf611d327c6efbb05b8c3c3eec25baadc4b81f3015eda12031c5dfd70647d75d"}}, {"rule": 2, "type": "equivalent", "target": "bb4c9dfad3173d99906963ab569e5990", "evidence": {"same_day": true, "patch_ids": ["e8c592597fe0c522a838714ea94d192e"], "statement_hash": "cf611d327c6efbb05b8c3c3eec25baadc4b81f3015eda12031c5dfd70647d75d"}}], "version": "17.9", "category_label": "Bug fixes", "also_in": [], "variants": [], "related_changes": [{"db_id": "6d7df9238b789e2555fe1290d455a61a", "kind": "equivalent", "version": "18.3", "label": "18.3", "title": "Fix failure after replaying a multixid truncation record from WAL that was generated by an older minor version", "evidence": {"same_day": true, "patch_ids": ["e8c592597fe0c522a838714ea94d192e"], "statement_hash": "cf611d327c6efbb05b8c3c3eec25baadc4b81f3015eda12031c5dfd70647d75d"}, "url": "/docs/compare/?release=18.3#18.3-ad611cd1e209983f", "source_url": "/docs/release/18.3/#RELEASE-18-3-CHANGES"}, {"db_id": "54acee06ad9ee6f00cba048e48dfdadc", "kind": "equivalent", "version": "16.13", "label": "16.13", "title": "Fix failure after replaying a multixid truncation record from WAL that was generated by an older minor version", "evidence": {"same_day": true, "patch_ids": ["e8c592597fe0c522a838714ea94d192e"], "statement_hash": "cf611d327c6efbb05b8c3c3eec25baadc4b81f3015eda12031c5dfd70647d75d"}, "url": "/docs/compare/?release=16.13#16.13-2ec40dc78a340503", "source_url": "/docs/release/16.13/#RELEASE-16-13-CHANGES"}, {"db_id": "ac9d069b97f39c99f4c9540523c6dd01", "kind": "equivalent", "version": "15.17", "label": "15.17", "title": "Fix failure after replaying a multixid truncation record from WAL that was generated by an older minor version", "evidence": {"same_day": true, "patch_ids": ["e8c592597fe0c522a838714ea94d192e"], "statement_hash": "cf611d327c6efbb05b8c3c3eec25baadc4b81f3015eda12031c5dfd70647d75d"}, "url": "/docs/compare/?release=15.17#15.17-b825392cb651a3f2", "source_url": "/docs/release/15.17/#id-1.11.6.8.5"}, {"db_id": "bb4c9dfad3173d99906963ab569e5990", "kind": "equivalent", "version": "14.22", "label": "14.22", "title": "Fix failure after replaying a multixid truncation record from WAL that was generated by an older minor version", "evidence": {"same_day": true, "patch_ids": ["e8c592597fe0c522a838714ea94d192e"], "statement_hash": "cf611d327c6efbb05b8c3c3eec25baadc4b81f3015eda12031c5dfd70647d75d"}, "url": "/docs/compare/?release=14.22#14.22-006d7b5e05d070c9", "source_url": "/docs/release/14.22/#id-1.11.6.8.6"}]}, {"id": "17.9-24d7e69f6ec0ae9a", "cves": ["CVE-2026-2006"], "html": "<p>Avoid incorrect complaint of invalid encoding when <code>substring()</code> is applied to <span>“<span>toasted</span>”</span> data (Noah Misch) <a href=\"https://postgr.es/c/5d5232bc3\">§</a> <a href=\"https://postgr.es/c/50d361f62\">§</a> <a href=\"https://postgr.es/c/8e73530f1\">§</a></p>\n<p>The fix for CVE-2026-2006 was too aggressive and could raise an error about an incomplete character in cases that are actually valid.</p>", "text": "Avoid incorrect complaint of invalid encoding when substring() is applied to “toasted” data (Noah Misch) § § § The fix for CVE-2026-2006 was too aggressive and could raise an error about an incomplete character in cases that are actually valid.", "title": "Avoid incorrect complaint of invalid encoding when substring() is applied to “toasted” data", "commits": ["50d361f62", "5d5232bc3", "8e73530f1"], "section": "Changes", "category": "security", "source_url": "/docs/release/17.9/#RELEASE-17-9-CHANGES", "source_hash": "f66079943109d09ab5df6de739fc355e5c2d722d3c278d0cc7fdcdd0da281fcd", "section_path": ["Changes"], "commit_groups": [["14b1fd617", "5d5232bc3", "6e045e1a6", "9f4fd119b", "a20eb248c", "bdfb37228"], ["2280ab354", "50d361f62", "8cef93d8a", "a0769e74d", "d04b34d68", "ec86152e0"], ["4174e41b9", "44fc85bbf", "45eb47230", "4644f8b23", "5b305ebcc", "8e73530f1"]], "identity_text": "Avoid incorrect complaint of invalid encoding when substring() is applied to toasted data (Noah Misch) The fix for CVE-2026-2006 was too aggressive and could raise an error about an incomplete character in cases that are actually valid.", "commit_aliases": ["14b1fd617", "2280ab354", "4174e41b9", "44fc85bbf", "45eb47230", "4644f8b23", "50d361f62", "5b305ebcc", "5d5232bc3", "6e045e1a6", "8cef93d8a", "8e73530f1", "9f4fd119b", "a0769e74d", "a20eb248c", "bdfb37228", "d04b34d68", "ec86152e0"], "source_commits": ["50d361f62", "5d5232bc3", "8e73530f1"], "source_entry_id": "17.9/changes/002", "db_id": "91516991913d971894a1428891e4772e", "patch_ids": ["924bc2a7b62c922890c6948fec9b1504", "b621552d0483c3fe9118c60e77f297ab", "fe6380c6909ab3efff6be8983b7f18a1"], "statement_hash": "b34aae4222592f29a7ecee54df249e73bebb9346d81b2e5c859347ba8c1ea747", "relations": [{"rule": 2, "type": "equivalent", "target": "2913b28e99dd666bc31951814a799735", "evidence": {"same_day": true, "patch_ids": ["924bc2a7b62c922890c6948fec9b1504", "b621552d0483c3fe9118c60e77f297ab", "fe6380c6909ab3efff6be8983b7f18a1"], "statement_hash": "b34aae4222592f29a7ecee54df249e73bebb9346d81b2e5c859347ba8c1ea747"}}, {"rule": 2, "type": "equivalent", "target": "9b63cad6030353d772f1330dfd687e9f", "evidence": {"same_day": true, "patch_ids": ["924bc2a7b62c922890c6948fec9b1504", "b621552d0483c3fe9118c60e77f297ab", "fe6380c6909ab3efff6be8983b7f18a1"], "statement_hash": "b34aae4222592f29a7ecee54df249e73bebb9346d81b2e5c859347ba8c1ea747"}}, {"rule": 2, "type": "equivalent", "target": "da9fc04e8b825c72955bd70be9fd53ee", "evidence": {"same_day": true, "patch_ids": ["924bc2a7b62c922890c6948fec9b1504", "b621552d0483c3fe9118c60e77f297ab", "fe6380c6909ab3efff6be8983b7f18a1"], "statement_hash": "b34aae4222592f29a7ecee54df249e73bebb9346d81b2e5c859347ba8c1ea747"}}, {"rule": 2, "type": "equivalent", "target": "fe28a154c085da9085a635db8d9d4460", "evidence": {"same_day": true, "patch_ids": ["924bc2a7b62c922890c6948fec9b1504", "b621552d0483c3fe9118c60e77f297ab", "fe6380c6909ab3efff6be8983b7f18a1"], "statement_hash": "b34aae4222592f29a7ecee54df249e73bebb9346d81b2e5c859347ba8c1ea747"}}], "version": "17.9", "category_label": "Security", "also_in": [], "variants": [], "related_changes": [{"db_id": "9b63cad6030353d772f1330dfd687e9f", "kind": "equivalent", "version": "18.3", "label": "18.3", "title": "Avoid incorrect complaint of invalid encoding when substring() is applied to “toasted” data", "evidence": {"same_day": true, "patch_ids": ["924bc2a7b62c922890c6948fec9b1504", "b621552d0483c3fe9118c60e77f297ab", "fe6380c6909ab3efff6be8983b7f18a1"], "statement_hash": "b34aae4222592f29a7ecee54df249e73bebb9346d81b2e5c859347ba8c1ea747"}, "url": "/docs/compare/?release=18.3#18.3-77113f5b52409590", "source_url": "/docs/release/18.3/#RELEASE-18-3-CHANGES"}, {"db_id": "fe28a154c085da9085a635db8d9d4460", "kind": "equivalent", "version": "16.13", "label": "16.13", "title": "Avoid incorrect complaint of invalid encoding when substring() is applied to “toasted” data", "evidence": {"same_day": true, "patch_ids": ["924bc2a7b62c922890c6948fec9b1504", "b621552d0483c3fe9118c60e77f297ab", "fe6380c6909ab3efff6be8983b7f18a1"], "statement_hash": "b34aae4222592f29a7ecee54df249e73bebb9346d81b2e5c859347ba8c1ea747"}, "url": "/docs/compare/?release=16.13#16.13-46657f359d7a6c06", "source_url": "/docs/release/16.13/#RELEASE-16-13-CHANGES"}, {"db_id": "2913b28e99dd666bc31951814a799735", "kind": "equivalent", "version": "15.17", "label": "15.17", "title": "Avoid incorrect complaint of invalid encoding when substring() is applied to “toasted” data", "evidence": {"same_day": true, "patch_ids": ["924bc2a7b62c922890c6948fec9b1504", "b621552d0483c3fe9118c60e77f297ab", "fe6380c6909ab3efff6be8983b7f18a1"], "statement_hash": "b34aae4222592f29a7ecee54df249e73bebb9346d81b2e5c859347ba8c1ea747"}, "url": "/docs/compare/?release=15.17#15.17-ed7a109835c41923", "source_url": "/docs/release/15.17/#id-1.11.6.8.5"}, {"db_id": "da9fc04e8b825c72955bd70be9fd53ee", "kind": "equivalent", "version": "14.22", "label": "14.22", "title": "Avoid incorrect complaint of invalid encoding when substring() is applied to “toasted” data", "evidence": {"same_day": true, "patch_ids": ["924bc2a7b62c922890c6948fec9b1504", "b621552d0483c3fe9118c60e77f297ab", "fe6380c6909ab3efff6be8983b7f18a1"], "statement_hash": "b34aae4222592f29a7ecee54df249e73bebb9346d81b2e5c859347ba8c1ea747"}, "url": "/docs/compare/?release=14.22#14.22-0e619c964c972dcb", "source_url": "/docs/release/14.22/#id-1.11.6.8.6"}]}, {"id": "17.9-1441e21296f1914d", "cves": [], "html": "<p>Fix computation of the set of potentially-nulling outer joins for the output of a <code>LATERAL UNION ALL</code> subquery (Richard Guo) <a href=\"https://postgr.es/c/bcaf1b510\">§</a></p>\n<p>This error could lead to skipping <code>NOT NULL</code> tests in the mistaken belief that they were unnecessary, resulting in wrong query output.</p>", "text": "Fix computation of the set of potentially-nulling outer joins for the output of a LATERAL UNION ALL subquery (Richard Guo) § This error could lead to skipping NOT NULL tests in the mistaken belief that they were unnecessary, resulting in wrong query output.", "title": "Fix computation of the set of potentially-nulling outer joins for the output of a LATERAL UNION ALL subquery", "commits": ["bcaf1b510"], "section": "Changes", "category": "bugfix", "source_url": "/docs/release/17.9/#RELEASE-17-9-CHANGES", "source_hash": "5cd79d75b4b3e8ca8739b04400f4e0d8a4247d958906bb453cdbcdcbc484ff44", "section_path": ["Changes"], "commit_groups": [["691977d37", "bcaf1b510", "ec20a4552", "ed57c207c"]], "identity_text": "Fix computation of the set of potentially-nulling outer joins for the output of a LATERAL UNION ALL subquery (Richard Guo) This error could lead to skipping NOT NULL tests in the mistaken belief that they were unnecessary, resulting in wrong query output.", "commit_aliases": ["691977d37", "bcaf1b510", "ec20a4552", "ed57c207c"], "source_commits": ["bcaf1b510"], "source_entry_id": "17.9/changes/003", "db_id": "b67986c165e36a1a03e1f26aa1714455", "patch_ids": ["39b9ce1d361dcaf187c274f11f3f2877"], "statement_hash": "ba69358a1b83d31e612c77f1471616df5093300bce97f33f1049bcfb8058f683", "relations": [{"rule": 2, "type": "equivalent", "target": "18fdbd910c49cc504248c6225d989414", "evidence": {"same_day": true, "patch_ids": ["39b9ce1d361dcaf187c274f11f3f2877"], "statement_hash": "ba69358a1b83d31e612c77f1471616df5093300bce97f33f1049bcfb8058f683"}}, {"rule": 2, "type": "equivalent", "target": "b8d8d19411ef9eb6905835bde4b0a556", "evidence": {"same_day": true, "patch_ids": ["39b9ce1d361dcaf187c274f11f3f2877"], "statement_hash": "ba69358a1b83d31e612c77f1471616df5093300bce97f33f1049bcfb8058f683"}}], "version": "17.9", "category_label": "Bug fixes", "also_in": [], "variants": [], "related_changes": [{"db_id": "18fdbd910c49cc504248c6225d989414", "kind": "equivalent", "version": "18.3", "label": "18.3", "title": "Fix computation of the set of potentially-nulling outer joins for the output of a LATERAL UNION ALL subquery", "evidence": {"same_day": true, "patch_ids": ["39b9ce1d361dcaf187c274f11f3f2877"], "statement_hash": "ba69358a1b83d31e612c77f1471616df5093300bce97f33f1049bcfb8058f683"}, "url": "/docs/compare/?release=18.3#18.3-cd0444df0515373f", "source_url": "/docs/release/18.3/#RELEASE-18-3-CHANGES"}, {"db_id": "b8d8d19411ef9eb6905835bde4b0a556", "kind": "equivalent", "version": "16.13", "label": "16.13", "title": "Fix computation of the set of potentially-nulling outer joins for the output of a LATERAL UNION ALL subquery", "evidence": {"same_day": true, "patch_ids": ["39b9ce1d361dcaf187c274f11f3f2877"], "statement_hash": "ba69358a1b83d31e612c77f1471616df5093300bce97f33f1049bcfb8058f683"}, "url": "/docs/compare/?release=16.13#16.13-8d356903eb4a95b4", "source_url": "/docs/release/16.13/#RELEASE-16-13-CHANGES"}]}, {"id": "17.9-49611ef76ca99838", "cves": [], "html": "<p>Fix <code>pg_stat_get_backend_wait_event()</code> and <code>pg_stat_get_backend_wait_event_type()</code> to report values for auxiliary processes (Heikki Linnakangas) <a href=\"https://postgr.es/c/842473337\">§</a></p>\n<p>Previously these functions returned NULL for auxiliary processes, but that's inconsistent with the <code>pg_stat_activity</code> view.</p>", "text": "Fix pg_stat_get_backend_wait_event() and pg_stat_get_backend_wait_event_type() to report values for auxiliary processes (Heikki Linnakangas) § Previously these functions returned NULL for auxiliary processes, but that's inconsistent with the pg_stat_activity view.", "title": "Fix pg_stat_get_backend_wait_event() and pg_stat_get_backend_wait_event_type() to report values for auxiliary processes", "commits": ["842473337"], "section": "Changes", "category": "bugfix", "source_url": "/docs/release/17.9/#RELEASE-17-9-CHANGES", "source_hash": "cb2b133dfef84606d3230484f61c93b4a79ab1ba9bced571f5d852562b647706", "section_path": ["Changes"], "commit_groups": [["2332911ae", "53463b4b2", "78a5e3074", "82b495cdd", "842473337", "ebc53ca7b"]], "identity_text": "Fix pg_stat_get_backend_wait_event() and pg_stat_get_backend_wait_event_type() to report values for auxiliary processes (Heikki Linnakangas) Previously these functions returned NULL for auxiliary processes, but that's inconsistent with the pg_stat_activity view.", "commit_aliases": ["2332911ae", "53463b4b2", "78a5e3074", "82b495cdd", "842473337", "ebc53ca7b"], "source_commits": ["842473337"], "source_entry_id": "17.9/changes/004", "db_id": "ca6d569bfd12f83cd8b663f7b1b14c38", "patch_ids": ["54586dcff5ba8f38c9bad3069e4ffc52"], "statement_hash": "f5b50524b8ec05ef6a3e7bcc10dc01af6ebe577734eff3be2cb39b4262840b90", "relations": [{"rule": 2, "type": "equivalent", "target": "0fa32f0f7fbb9d8c7a7a1cfeaa993230", "evidence": {"same_day": true, "patch_ids": ["54586dcff5ba8f38c9bad3069e4ffc52"], "statement_hash": "f5b50524b8ec05ef6a3e7bcc10dc01af6ebe577734eff3be2cb39b4262840b90"}}, {"rule": 2, "type": "equivalent", "target": "51c535e1e5383ba40f60f95b951f7542", "evidence": {"same_day": true, "patch_ids": ["54586dcff5ba8f38c9bad3069e4ffc52"], "statement_hash": "f5b50524b8ec05ef6a3e7bcc10dc01af6ebe577734eff3be2cb39b4262840b90"}}, {"rule": 2, "type": "equivalent", "target": "b1227a7b977e0fdde28e2260fd4055ca", "evidence": {"same_day": true, "patch_ids": ["54586dcff5ba8f38c9bad3069e4ffc52"], "statement_hash": "f5b50524b8ec05ef6a3e7bcc10dc01af6ebe577734eff3be2cb39b4262840b90"}}, {"rule": 2, "type": "equivalent", "target": "d389f553498aab12a33e8658e42c2ebd", "evidence": {"same_day": true, "patch_ids": ["54586dcff5ba8f38c9bad3069e4ffc52"], "statement_hash": "f5b50524b8ec05ef6a3e7bcc10dc01af6ebe577734eff3be2cb39b4262840b90"}}], "version": "17.9", "category_label": "Bug fixes", "also_in": [], "variants": [], "related_changes": [{"db_id": "51c535e1e5383ba40f60f95b951f7542", "kind": "equivalent", "version": "18.3", "label": "18.3", "title": "Fix pg_stat_get_backend_wait_event() and pg_stat_get_backend_wait_event_type() to report values for auxiliary processes", "evidence": {"same_day": true, "patch_ids": ["54586dcff5ba8f38c9bad3069e4ffc52"], "statement_hash": "f5b50524b8ec05ef6a3e7bcc10dc01af6ebe577734eff3be2cb39b4262840b90"}, "url": "/docs/compare/?release=18.3#18.3-a63ceb8e607a4b1d", "source_url": "/docs/release/18.3/#RELEASE-18-3-CHANGES"}, {"db_id": "0fa32f0f7fbb9d8c7a7a1cfeaa993230", "kind": "equivalent", "version": "16.13", "label": "16.13", "title": "Fix pg_stat_get_backend_wait_event() and pg_stat_get_backend_wait_event_type() to report values for auxiliary processes", "evidence": {"same_day": true, "patch_ids": ["54586dcff5ba8f38c9bad3069e4ffc52"], "statement_hash": "f5b50524b8ec05ef6a3e7bcc10dc01af6ebe577734eff3be2cb39b4262840b90"}, "url": "/docs/compare/?release=16.13#16.13-ba7ab6fc9d199173", "source_url": "/docs/release/16.13/#RELEASE-16-13-CHANGES"}, {"db_id": "d389f553498aab12a33e8658e42c2ebd", "kind": "equivalent", "version": "15.17", "label": "15.17", "title": "Fix pg_stat_get_backend_wait_event() and pg_stat_get_backend_wait_event_type() to report values for auxiliary processes", "evidence": {"same_day": true, "patch_ids": ["54586dcff5ba8f38c9bad3069e4ffc52"], "statement_hash": "f5b50524b8ec05ef6a3e7bcc10dc01af6ebe577734eff3be2cb39b4262840b90"}, "url": "/docs/compare/?release=15.17#15.17-004af2947054d2ea", "source_url": "/docs/release/15.17/#id-1.11.6.8.5"}, {"db_id": "b1227a7b977e0fdde28e2260fd4055ca", "kind": "equivalent", "version": "14.22", "label": "14.22", "title": "Fix pg_stat_get_backend_wait_event() and pg_stat_get_backend_wait_event_type() to report values for auxiliary processes", "evidence": {"same_day": true, "patch_ids": ["54586dcff5ba8f38c9bad3069e4ffc52"], "statement_hash": "f5b50524b8ec05ef6a3e7bcc10dc01af6ebe577734eff3be2cb39b4262840b90"}, "url": "/docs/compare/?release=14.22#14.22-380d81041c2b7b37", "source_url": "/docs/release/14.22/#id-1.11.6.8.6"}]}, {"id": "17.9-00f1ed550848c3b5", "cves": [], "html": "<p>Fix casting a composite-type variable to a domain type when returning its value from a PL/pgSQL function (Tom Lane) <a href=\"https://postgr.es/c/dfd850980\">§</a></p>\n<p>If the variable's value is NULL, a <span>“<span>cache lookup failed for type 0</span>”</span> error resulted.</p>", "text": "Fix casting a composite-type variable to a domain type when returning its value from a PL/pgSQL function (Tom Lane) § If the variable's value is NULL, a “cache lookup failed for type 0” error resulted.", "title": "Fix casting a composite-type variable to a domain type when returning its value from a PL/pgSQL function", "commits": ["dfd850980"], "section": "Changes", "category": "bugfix", "source_url": "/docs/release/17.9/#RELEASE-17-9-CHANGES", "source_hash": "8609a1b3bab14b3c4cbecc4cce37cf565bb82d9fbe4e1193bf5243274eacf17c", "section_path": ["Changes"], "commit_groups": [["254b15cbf", "2b93d3820", "9863c9075", "c66f4cff1", "ce4b7e3a1", "dfd850980"]], "identity_text": "Fix casting a composite-type variable to a domain type when returning its value from a PL/pgSQL function (Tom Lane) If the variable's value is NULL, a cache lookup failed for type 0 error resulted.", "commit_aliases": ["254b15cbf", "2b93d3820", "9863c9075", "c66f4cff1", "ce4b7e3a1", "dfd850980"], "source_commits": ["dfd850980"], "source_entry_id": "17.9/changes/005", "db_id": "1f6375c5be0406ebaeab1ddd1281f48a", "patch_ids": ["4682bfcc99694f6b7bf7c07af3082c2e"], "statement_hash": "257a19cad310234769985e6594cf9f32698b7849a63b72427ee23e58e321e7d5", "relations": [{"rule": 2, "type": "equivalent", "target": "08e9766e078b0f98d664963d7351568a", "evidence": {"same_day": true, "patch_ids": ["4682bfcc99694f6b7bf7c07af3082c2e"], "statement_hash": "257a19cad310234769985e6594cf9f32698b7849a63b72427ee23e58e321e7d5"}}, {"rule": 2, "type": "equivalent", "target": "509c9d18c03750ab5a1af4533e9e3f71", "evidence": {"same_day": true, "patch_ids": ["4682bfcc99694f6b7bf7c07af3082c2e"], "statement_hash": "257a19cad310234769985e6594cf9f32698b7849a63b72427ee23e58e321e7d5"}}, {"rule": 2, "type": "equivalent", "target": "b3e55b2d8440115c6283ddb4434aed5d", "evidence": {"same_day": true, "patch_ids": ["4682bfcc99694f6b7bf7c07af3082c2e"], "statement_hash": "257a19cad310234769985e6594cf9f32698b7849a63b72427ee23e58e321e7d5"}}, {"rule": 2, "type": "equivalent", "target": "d7289871637eb477a52d704b8b129dee", "evidence": {"same_day": true, "patch_ids": ["4682bfcc99694f6b7bf7c07af3082c2e"], "statement_hash": "257a19cad310234769985e6594cf9f32698b7849a63b72427ee23e58e321e7d5"}}], "version": "17.9", "category_label": "Bug fixes", "also_in": [], "variants": [], "related_changes": [{"db_id": "d7289871637eb477a52d704b8b129dee", "kind": "equivalent", "version": "18.3", "label": "18.3", "title": "Fix casting a composite-type variable to a domain type when returning its value from a PL/pgSQL function", "evidence": {"same_day": true, "patch_ids": ["4682bfcc99694f6b7bf7c07af3082c2e"], "statement_hash": "257a19cad310234769985e6594cf9f32698b7849a63b72427ee23e58e321e7d5"}, "url": "/docs/compare/?release=18.3#18.3-68534f113dfbb27d", "source_url": "/docs/release/18.3/#RELEASE-18-3-CHANGES"}, {"db_id": "b3e55b2d8440115c6283ddb4434aed5d", "kind": "equivalent", "version": "16.13", "label": "16.13", "title": "Fix casting a composite-type variable to a domain type when returning its value from a PL/pgSQL function", "evidence": {"same_day": true, "patch_ids": ["4682bfcc99694f6b7bf7c07af3082c2e"], "statement_hash": "257a19cad310234769985e6594cf9f32698b7849a63b72427ee23e58e321e7d5"}, "url": "/docs/compare/?release=16.13#16.13-63ccf52c03df56be", "source_url": "/docs/release/16.13/#RELEASE-16-13-CHANGES"}, {"db_id": "509c9d18c03750ab5a1af4533e9e3f71", "kind": "equivalent", "version": "15.17", "label": "15.17", "title": "Fix casting a composite-type variable to a domain type when returning its value from a PL/pgSQL function", "evidence": {"same_day": true, "patch_ids": ["4682bfcc99694f6b7bf7c07af3082c2e"], "statement_hash": "257a19cad310234769985e6594cf9f32698b7849a63b72427ee23e58e321e7d5"}, "url": "/docs/compare/?release=15.17#15.17-f14d3ac393cef450", "source_url": "/docs/release/15.17/#id-1.11.6.8.5"}, {"db_id": "08e9766e078b0f98d664963d7351568a", "kind": "equivalent", "version": "14.22", "label": "14.22", "title": "Fix casting a composite-type variable to a domain type when returning its value from a PL/pgSQL function", "evidence": {"same_day": true, "patch_ids": ["4682bfcc99694f6b7bf7c07af3082c2e"], "statement_hash": "257a19cad310234769985e6594cf9f32698b7849a63b72427ee23e58e321e7d5"}, "url": "/docs/compare/?release=14.22#14.22-3b6651931176e1ab", "source_url": "/docs/release/14.22/#id-1.11.6.8.6"}]}, {"id": "17.9-09236fba7643dbb2", "cves": [], "html": "<p>Fix potential null pointer dereference in <code>contrib/hstore</code>'s binary input function (Michael Paquier) <a href=\"https://postgr.es/c/0dfbe42da\">§</a></p>\n<p><code>hstore</code>'s receive function crashed on input containing duplicate keys. <code>hstore</code> values generated by Postgres would never contain duplicate keys, so this mistake has gone unnoticed. The crash could be provoked by malicious or corrupted data.</p>", "text": "Fix potential null pointer dereference in contrib/hstore's binary input function (Michael Paquier) § hstore's receive function crashed on input containing duplicate keys. hstore values generated by Postgres would never contain duplicate keys, so this mistake has gone unnoticed. The crash could be provoked by malicious or corrupted data.", "title": "Fix potential null pointer dereference in contrib/hstore's binary input function", "commits": ["0dfbe42da"], "section": "Changes", "category": "bugfix", "source_url": "/docs/release/17.9/#RELEASE-17-9-CHANGES", "source_hash": "78a371928fa32bcde5022361352d0f2d26dff8f0de8dc97252d95914825625d4", "section_path": ["Changes"], "commit_groups": [["0dfbe42da", "31d0b917d", "4a0843c53", "63c05e03b", "a6f823e77", "f604cc695"]], "identity_text": "Fix potential null pointer dereference in contrib/hstore's binary input function (Michael Paquier) hstore's receive function crashed on input containing duplicate keys. hstore values generated by Postgres would never contain duplicate keys, so this mistake has gone unnoticed. The crash could be provoked by malicious or corrupted data.", "commit_aliases": ["0dfbe42da", "31d0b917d", "4a0843c53", "63c05e03b", "a6f823e77", "f604cc695"], "source_commits": ["0dfbe42da"], "source_entry_id": "17.9/changes/006", "db_id": "3a65408ffac19ce6c90d333d8d5318cf", "patch_ids": ["05e85f727ef4e88378a37028157d43b6"], "statement_hash": "d3475d54feed07f63eac9d89bc0052bdf62514368b9675dd5fa3bbf2749ab52d", "relations": [{"rule": 2, "type": "equivalent", "target": "302f35b8c992f59981d9c8bbcbf80b74", "evidence": {"same_day": true, "patch_ids": ["05e85f727ef4e88378a37028157d43b6"], "statement_hash": "d3475d54feed07f63eac9d89bc0052bdf62514368b9675dd5fa3bbf2749ab52d"}}, {"rule": 2, "type": "equivalent", "target": "333c171c538037b7ded4bd4a610b1799", "evidence": {"same_day": true, "patch_ids": ["05e85f727ef4e88378a37028157d43b6"], "statement_hash": "d3475d54feed07f63eac9d89bc0052bdf62514368b9675dd5fa3bbf2749ab52d"}}, {"rule": 2, "type": "equivalent", "target": "6c2d1768700fe19270f371e13fa79343", "evidence": {"same_day": true, "patch_ids": ["05e85f727ef4e88378a37028157d43b6"], "statement_hash": "d3475d54feed07f63eac9d89bc0052bdf62514368b9675dd5fa3bbf2749ab52d"}}, {"rule": 2, "type": "equivalent", "target": "88acf3ddcff5993038ed18e0a7157844", "evidence": {"same_day": true, "patch_ids": ["05e85f727ef4e88378a37028157d43b6"], "statement_hash": "d3475d54feed07f63eac9d89bc0052bdf62514368b9675dd5fa3bbf2749ab52d"}}], "version": "17.9", "category_label": "Bug fixes", "also_in": [], "variants": [], "related_changes": [{"db_id": "302f35b8c992f59981d9c8bbcbf80b74", "kind": "equivalent", "version": "18.3", "label": "18.3", "title": "Fix potential null pointer dereference in contrib/hstore's binary input function", "evidence": {"same_day": true, "patch_ids": ["05e85f727ef4e88378a37028157d43b6"], "statement_hash": "d3475d54feed07f63eac9d89bc0052bdf62514368b9675dd5fa3bbf2749ab52d"}, "url": "/docs/compare/?release=18.3#18.3-72cba4c8d34e077e", "source_url": "/docs/release/18.3/#RELEASE-18-3-CHANGES"}, {"db_id": "6c2d1768700fe19270f371e13fa79343", "kind": "equivalent", "version": "16.13", "label": "16.13", "title": "Fix potential null pointer dereference in contrib/hstore's binary input function", "evidence": {"same_day": true, "patch_ids": ["05e85f727ef4e88378a37028157d43b6"], "statement_hash": "d3475d54feed07f63eac9d89bc0052bdf62514368b9675dd5fa3bbf2749ab52d"}, "url": "/docs/compare/?release=16.13#16.13-cbdd4e244cbf6bcb", "source_url": "/docs/release/16.13/#RELEASE-16-13-CHANGES"}, {"db_id": "88acf3ddcff5993038ed18e0a7157844", "kind": "equivalent", "version": "15.17", "label": "15.17", "title": "Fix potential null pointer dereference in contrib/hstore's binary input function", "evidence": {"same_day": true, "patch_ids": ["05e85f727ef4e88378a37028157d43b6"], "statement_hash": "d3475d54feed07f63eac9d89bc0052bdf62514368b9675dd5fa3bbf2749ab52d"}, "url": "/docs/compare/?release=15.17#15.17-cf5bd5f4632c2dc1", "source_url": "/docs/release/15.17/#id-1.11.6.8.5"}, {"db_id": "333c171c538037b7ded4bd4a610b1799", "kind": "equivalent", "version": "14.22", "label": "14.22", "title": "Fix potential null pointer dereference in contrib/hstore's binary input function", "evidence": {"same_day": true, "patch_ids": ["05e85f727ef4e88378a37028157d43b6"], "statement_hash": "d3475d54feed07f63eac9d89bc0052bdf62514368b9675dd5fa3bbf2749ab52d"}, "url": "/docs/compare/?release=14.22#14.22-e6357c39af22cdb6", "source_url": "/docs/release/14.22/#id-1.11.6.8.6"}]}]}], "stats": [{"key": "all", "label": "All changes", "count": 6}, {"key": "feature", "label": "Features", "count": 0}, {"key": "bugfix", "label": "Bug fixes", "count": 5}, {"key": "security", "label": "Security", "count": 1}, {"key": "performance", "label": "Performance", "count": 0}, {"key": "compatibility", "label": "Compatibility", "count": 0}, {"key": "improvement", "label": "Improvements", "count": 0}], "total": 6, "release_count": 1, "cross_major": false, "cve_count": 1, "cves": [{"id": "CVE-2026-2006", "url": "https://www.postgresql.org/support/security/CVE-2026-2006/", "fixed": {"14": "14.21", "15": "15.16", "16": "16.12", "17": "17.8", "18": "18.2"}, "score": 8.8, "title": "Avoid incorrect complaint of invalid encoding when substring() is applied to “toasted” data", "vector": "AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cna_url": "https://cveawg.mitre.org/api/cve/CVE-2026-2006", "affected": {"14": "14", "15": "15", "16": "16", "17": "17", "18": "18"}, "component": "core server", "published": {"14": "2026-02-12", "15": "2026-02-12", "16": "2026-02-12", "17": "2026-02-12", "18": "2026-02-12"}, "introduced": {}, "cvss_version": "3.0", "description_en": "Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.", "affected_ranges": [{"from": "0", "until": "14.21"}, {"from": "15", "until": "15.16"}, {"from": "16", "until": "16.12"}, {"from": "17", "until": "17.8"}, {"from": "18", "until": "18.2"}], "first_published": "2026-02-12", "fixed_version": "17.8"}], "cve_available": true, "remaining_cves": [], "security_regressions": [], "warnings": [], "candidate_count": 6, "already_in_source_count": 0, "duplicate_count": 0, "excluded_count": 0, "exclusions": [], "source_as_of": "2026-09-26", "security_as_of": "2026-09-26"}