↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

DocumentationVersion comparison

POSTGRESQL · VERSION COMPARE

PostgreSQL 9.0.1 release changes

All features, fixes, and compatibility notes in this release, with related records from other versions.

All changes in this release
All changes in this release

Includes changes after the source version through the target. A major version name means its initial release.

From PostgreSQL 9.0 onward: 17 major branches and 352 release notes. Updated 2026-09-26.

Complete release changes

9.0.1

2010-10-04

Export JSON
10changesFeatures, fixes, improvements
1releaseGrouped by release
1CVEVulnerability IDs mentioned in these notes

9.0.1 HistoricalSupport ends 2015-10-08

Security records mentioned in this release 1 CVE
CVEs mentioned in these notes, including possible follow-up fixes for earlier vulnerabilities
CVE / issueSeverityFixed version
CVE-2010-3433

Use a separate interpreter for each calling SQL userid in PL/Perl and PL/Tcl

—9.0.1

PostgreSQL 9.0.1

Migration and compatibility

A dump/restore is not required for those running 9.0.X.

SecurityUse a separate interpreter for each calling SQL userid in PL/Perl and PL/Tcl

Changes

Use a separate interpreter for each calling SQL userid in PL/Perl and PL/Tcl (Tom Lane)

This change prevents security problems that can be caused by subverting Perl or Tcl code that will be executed later in the same session under another SQL user identity (for example, within a SECURITY DEFINER function). Most scripting languages offer numerous ways that that might be done, such as redefining standard functions or operators called by the target function. Without this change, any SQL user with Perl or Tcl language usage rights can do essentially anything with the SQL privileges of the target function's owner.

The cost of this change is that intentional communication among Perl and Tcl functions becomes more difficult. To provide an escape hatch, PL/PerlU and PL/TclU functions continue to use only one interpreter per session. This is not considered a security issue since all such functions execute at the trust level of a database superuser already.

It is likely that third-party procedural languages that claim to offer trusted execution have similar security issues. We advise contacting the authors of any PL you are depending on for security-critical purposes.

Our thanks to Tim Bunce for pointing out this issue (CVE-2010-3433).

Bug fixesImprove pg_get_expr() security fix so that the function can still be used on the output of a sub-select

Changes

Improve pg_get_expr() security fix so that the function can still be used on the output of a sub-select (Tom Lane)

Bug fixesFix incorrect placement of placeholder evaluation

Changes

Fix incorrect placement of placeholder evaluation (Tom Lane)

This bug could result in query outputs being non-null when they should be null, in cases where the inner side of an outer join is a sub-select with non-strict expressions in its output list.

Bug fixesFix join removal's handling of placeholder expressions

Changes

Fix join removal's handling of placeholder expressions (Tom Lane)

Bug fixesFix possible duplicate scans of UNION ALL member relations

Changes

Fix possible duplicate scans of UNION ALL member relations (Tom Lane)

ImprovementsPrevent infinite loop in ProcessIncomingNotify() after unlistening

Changes

Prevent infinite loop in ProcessIncomingNotify() after unlistening (Jeff Davis)

Bug fixesPrevent show_session_authorization() from crashing within autovacuum processes

Changes

Prevent show_session_authorization() from crashing within autovacuum processes (Tom Lane)

ImprovementsRe-allow input of Julian dates prior to 0001-01-01 AD

Changes

Re-allow input of Julian dates prior to 0001-01-01 AD (Tom Lane)

Input such as 'J100000'::date worked before 8.4, but was unintentionally broken by added error-checking.

ImprovementsMake psql recognize DISCARD ALL as a command that should not be encased in a transaction block in autocommit-off mode

Changes

Make psql recognize DISCARD ALL as a command that should not be encased in a transaction block in autocommit-off mode (Itagaki Takahiro)

ImprovementsUpdate build infrastructure and documentation to reflect the source code repository's move from CVS to Git

Changes

Update build infrastructure and documentation to reflect the source code repository's move from CVS to Git (Magnus Hagander and others)

How is this comparison generated?

The comparison follows PostgreSQL release notes from just after the source through the target version. For a major upgrade, maintenance releases from each older branch are included only up to the next major release date, and never after the target date. A major version such as 18 means its initial release, 18.0. Previews and development snapshots are labeled separately.

Entries come from the original English manuals. Release coverage and commit evidence are verified against upstream sources. Every entry retains its complete explanation and source link. Categories aid browsing; read the full notes for impact, conditions, and migration steps.

Fixes can be backported to several branches. Confirmed duplicates are merged conservatively, with every branch explanation retained. A note describing several independent fixes is excluded only when all are already present in the source. Major-release features remain distinct from related maintenance patches unless their complete original descriptions match. Uncertain matches are retained. This is a release-note history, not an exhaustive comparison of compiled binaries.

CVE results are calculated independently from the PostgreSQL security registry and vulnerability records. A CVE counts as gained protection only when the source is affected and the target is fixed or unaffected. Remaining vulnerabilities are listed separately. Security entries and distinct CVEs are counted separately.

Interaction inspired by pgversions.com and pgversionreport. Content comes from PostgreSQL release notes. See the release notes archive.