DocumentationVersion comparison
POSTGRESQL · VERSION COMPARE
All features, fixes, and compatibility notes in this release, with related records from other versions.
Includes changes after the source version through the target. A major version name means its initial release.
From PostgreSQL 9.0 onward: 17 major branches and 352 release notes. Updated 2026-09-26.
Complete release changes
2020-02-13
12.2 HistoricalSupport ends 2024-11-21
| CVE / issue | Severity | Fixed version |
|---|---|---|
| CVE-2017-7484 Allow the planner to apply potentially-leaky tests to child-table statistics, if the user can read the corresponding column of the table that's actually named in the query | 4.3 | |
| CVE-2020-1720 Add missing permissions checks for ALTER ... DEPENDS ON EXTENSION | 3.1 | 12.2 |
A dump/restore is not required for those running 12.X.
However, if you have any foreign key constraints referencing partitioned tables, see the two entries below about bugs in that feature.
Changes
Add missing permissions checks for ALTER ... DEPENDS ON EXTENSION (Álvaro Herrera) §
Marking an object as dependent on an extension did not have any privilege check whatsoever. This oversight allowed any user to mark routines, triggers, materialized views, or indexes as droppable by anyone able to drop an extension. Require that the calling user own the specified object (and hence have privilege to drop it). (CVE-2020-1720)
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix TRUNCATE ... CASCADE to ensure all relevant partitions are truncated (Jehan-Guillaume de Rorthais) §
If a partition of a partitioned table is truncated with the CASCADE option, and the partitioned table has a foreign-key reference from another table, that table must also be truncated. The need to check this was missed if the referencing table was itself partitioned, possibly allowing rows to survive that violate the foreign-key constraint.
Hence, if you have foreign key constraints between partitioned tables, and you have done any partition-level TRUNCATE on the referenced table, you should check to see if any foreign key violations exist. The simplest way is to add a new instance of the foreign key constraint (and, once that succeeds, drop it or the original constraint). That may be prohibitive from a locking standpoint, however, in which case you might prefer to manually query for unmatched rows.
Changes
Fix failure to attach foreign key constraints to sub-partitions (Jehan-Guillaume de Rorthais) §
When adding a partition to a level below the first level of a multi-level partitioned table, foreign key constraints referencing the top partitioned table were not cloned to the new partition, leading to possible constraint violations later. Detaching and re-attaching the new partition is the cheapest way to fix this. However, if there are many partitions to be fixed, adding a new instance of the foreign key constraint might be preferable.
Changes
Fix possible crash during concurrent update on a partitioned table or inheritance tree (Tom Lane) §
Changes
Ensure that row triggers on partitioned tables are correctly cloned to sub-partitions when appropriate (Álvaro Herrera) §
User-defined triggers (but not triggers for foreign key or deferred unique constraints) might be missed when creating or attaching a partition.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix logical replication subscriber code to execute per-column UPDATE triggers when appropriate (Peter Eisentraut) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Avoid failure in logical decoding when a large transaction must be spilled into many separate temporary files (Amit Khandekar) § §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix possible crash or data corruption when a logical replication subscriber processes a row update (Tom Lane, Tomas Vondra) §
This bug caused visible problems only if the subscriber's table contained columns that were not being copied from the publisher and had pass-by-reference data types.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix crash in logical replication subscriber after DDL changes on a subscribed relation (Jehan-Guillaume de Rorthais, Vignesh C) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix failure in logical replication publisher after a database crash and restart (Vignesh C) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Ensure that the effect of pg_replication_slot_advance() on a physical replication slot will persist across restarts (Alexey Kondratov, Michael Paquier) § §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Improve efficiency of logical replication with REPLICA IDENTITY FULL (Konstantin Knizhnik) §
When searching for an existing tuple during an update or delete operation, return the first matching tuple not the last one.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix base backup to handle database OIDs larger than INT32_MAX (Peter Eisentraut) §
Changes
Ensure parallel plans are always shut down at the correct time (Kyotaro Horiguchi) §
This oversight is known to result in “temporary file leak” warnings from multi-batch parallel hash joins.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Prevent premature shutdown of a Gather or GatherMerge plan node that is underneath a Limit node (Amit Kapila) §
This avoids failure if such a plan node needs to be scanned more than once, as for instance if it is on the inside of a nestloop.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Improve efficiency of parallel hash join on CPUs with many cores (Gang Deng, Thomas Munro) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Avoid crash in parallel CREATE INDEX when there are no free dynamic shared memory slots (Thomas Munro) § §
Fall back to a non-parallel index build, instead.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Avoid memory leak when there are no free dynamic shared memory slots (Thomas Munro) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Ignore the CONCURRENTLY option when performing an index creation, drop, or rebuild on a temporary table (Michael Paquier, Heikki Linnakangas, Andres Freund) §
This avoids strange failures if the temporary table has an ON COMMIT action. There is no benefit in using CONCURRENTLY for a temporary table anyway, since other sessions cannot access the table, making the extra processing pointless.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix possible failure when resetting expression indexes on temporary tables that are marked ON COMMIT DELETE ROWS (Tom Lane) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix possible crash in BRIN index operations with box, range and inet data types (Heikki Linnakangas) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix handling of deleted pages in GIN indexes (Alexander Korotkov) § § § §
Avoid possible deadlocks, incorrect updates of a deleted page's state, and failure to traverse through a recently-deleted page.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix possible crash with a SubPlan (sub-SELECT) within a multi-row VALUES list (Tom Lane) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix failure in ALTER TABLE when a column referenced in a GENERATED expression has been added or changed in type earlier in the same ALTER command (Tom Lane) §
Changes
Fix failure to insert default values for “missing” attributes during tuple conversion (Vik Fearing, Andrew Gierth) §
This could result in values incorrectly reading as NULL, when they come from columns that had been added by ALTER TABLE ADD COLUMN with a constant default.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix crash after FileClose() failure (Noah Misch) §
This issue could only be observed with data_sync_retry enabled, since otherwise FileClose() failure would be reported as a PANIC.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix handling of multiple AFTER ROW triggers on a foreign table (Etsuro Fujita) §
Changes
Fix unlikely crash with pass-by-reference aggregate transition states (Andres Freund, Teodor Sigaev) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Improve error reporting in to_date() and to_timestamp() (Tom Lane, Álvaro Herrera) § §
Reports about incorrect month or day names in input strings could truncate the input in the middle of a multi-byte character, leading to an improperly encoded error message that could cause follow-on failures. Truncate at the next whitespace instead.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix off-by-one result for EXTRACT(ISOYEAR FROM for BC dates (Tom Lane) §timestamp)
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Ensure that the <> operator for type char reports indeterminate-collation errors as such, rather than as “cache lookup failed for collation 0” (Tom Lane) §
Changes
Avoid treating TID scans as sequential scans (Tatsuhito Kasahara) § §
A refactoring oversight caused TID scans (selection by CTID) to be counted as sequential scans in the statistics views, and to take whole-table predicate locks as sequential scans do. The latter behavior could cause unnecessary serialization errors in serializable transaction mode.
Changes
Avoid stack overflow in information_schema views when a self-referential view exists in the system catalogs (Tom Lane) §
A self-referential view can't work; it will always result in infinite recursion. We handled that situation correctly when trying to execute the view, but not when inquiring whether it is automatically updatable.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Ensure that walsender processes always show NULL for transaction start time in pg_stat_activity (Álvaro Herrera) § §
Previously, the xact_start column would sometimes show the process start time.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Improve performance of hash joins with very large inner relations (Thomas Munro) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Reduce spinlock contention when there are many active walsender processes (Pierre Ducroquet) §
Changes
Fix placement of “Subplans Removed” field in EXPLAIN output (Daniel Gustafsson, Tom Lane) §
In non-text output formats, this field was emitted inside the “Plans” sub-group, resulting in syntactically invalid output. Attach it to the parent Append or MergeAppend plan node as intended. This causes the field to change position in text output format too: if there are any InitPlans attached to the same plan node, “Subplans Removed” will now appear before those.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix EXPLAIN's SETTINGS option to print as empty in non-text output formats (Tom Lane) §
In the non-text output formats, fields are supposed to appear when requested, even if they have empty or zero values.
Changes
Allow the planner to apply potentially-leaky tests to child-table statistics, if the user can read the corresponding column of the table that's actually named in the query (Dilip Kumar, Amit Langote) §
This change fixes a performance problem for partitioned tables that was created by the fix for CVE-2017-7484. That security fix disallowed applying leaky operators to statistics for columns that the current user doesn't have permission to read directly. However, it's somewhat common to grant permissions only on the parent partitioned table and not bother to do so on individual partitions. In such cases, the user can read the column via the parent, so there's no point in this security restriction; it only results in poorer planner estimates than necessary.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix planner errors induced by overly-aggressive collapsing of joins to single-row subqueries (Tom Lane) §
This mistake led to errors such as “failed to construct the join relation”.
Changes
Fix “no = operator for opfamily NNNN” planner error when trying to match a LIKE or regex pattern-match operator to a binary-compatible index opclass (Tom Lane) §
Changes
Fix edge-case crashes and misestimations in selectivity calculations for the <@ and @> range operators (Michael Paquier, Andrey Borodin, Tom Lane) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Ignore system columns when applying most-common-value extended statistics (Tomas Vondra) §
This prevents “negative bitmapset member not allowed” planner errors for affected queries.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix BRIN index logic to support hypothetical BRIN indexes (Julien Rouhaud, Heikki Linnakangas) §
Previously, if an “index adviser” extension tried to get the planner to produce a plan involving a hypothetical BRIN index, that would fail, because the BRIN cost estimation code would always try to physically access the index's metapage. Now it checks to see if the index is only hypothetical, and uses default assumptions about the index parameters if so.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Improve error reporting for attempts to use automatic updating of views with conditional INSTEAD rules (Dean Rasheed) §
This has never been supported, but previously the error was thrown only at execution time, so that it could be masked by planner errors.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Prevent a composite type from being included in itself indirectly via a range type (Tom Lane, Julien Rouhaud) § §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Disallow partition key expressions that return pseudo-types, such as record (Tom Lane) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix error reporting for index expressions of prohibited types (Amit Langote) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix dumping of views that contain only a VALUES list to handle cases where a view output column has been renamed (Tom Lane) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Ensure that data types and collations used in XMLTABLE constructs are accounted for when computing dependencies of a view or rule (Tom Lane) §
Previously it was possible to break a view using XMLTABLE by dropping a type, if the type was not otherwise referenced in the view. This fix does not correct the dependencies already recorded for existing views, only for newly-created ones.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Prevent unwanted downcasing and truncation of RADIUS authentication parameters (Marcos David) §
The pg_hba.conf parser mistakenly treated these fields as SQL identifiers, which in general they aren't.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Transmit incoming NOTIFY messages to the client before sending ReadyForQuery, rather than after (Tom Lane) §
This change ensures that, with libpq and other client libraries that act similarly to it, any notifications received during a transaction will be available by the time the client thinks the transaction is complete. This probably makes no difference in practical applications (which would need to cope with asynchronous notifications in any case); but it makes it easier to build test cases with reproducible behavior.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix bugs in handling of non-blocking I/O when using GSSAPI encryption (Tom Lane) §
These errors could result in dropping data (usually leading to subsequent wire-protocol-violation errors) or in a “livelock” situation where a sending process goes to sleep although not all its data has been sent. Moreover, libpq failed to keep separate encryption state for each connection, creating the possibility for failures in applications using multiple encrypted database connections.
Changes
Allow libpq to parse all GSS-related connection parameters even when the GSSAPI code hasn't been compiled in (Tom Lane) §
This makes the behavior similar to our SSL support, where it was long ago deemed to be a good idea to always accept all the related parameters, even if some are ignored or restricted due to lack of the feature in a particular build.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix incorrect handling of %b and %B format codes in ecpg's PGTYPEStimestamp_fmt_asc() function (Tomas Vondra) §
Due to an off-by-one error, these codes would print the wrong month name, or possibly crash.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Avoid crash after an out-of-memory failure in ecpglib (Tom Lane) §
Changes
Fix parallel pg_dump/pg_restore to more gracefully handle failure to create worker processes (Tom Lane) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Prevent possible crash or lockup when attempting to terminate a parallel pg_dump/pg_restore run via a signal (Tom Lane) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
In pg_upgrade, look inside arrays and ranges while searching for non-upgradable data types in tables (Tom Lane) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Apply more thorough syntax checking to createuser's --connection-limit option (Álvaro Herrera) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Cope with changes of the specific type referenced by a PL/pgSQL composite-type variable in more cases (Ashutosh Sharma, Tom Lane) §
Dropping and re-creating the composite type referenced by a PL/pgSQL variable could lead to “could not open relation with OID NNNN” errors.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Avoid crash in postgres_fdw when trying to send a command like UPDATE remote_tab SET (x,y) = (SELECT ...) to the remote server (Tom Lane) §
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
In contrib/dict_int, reject maxlen settings less than one (Tomas Vondra) §
This prevents a possible crash with silly settings for that parameter.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Disallow NULL category values in contrib/tablefunc's crosstab() function (Joe Conway) §
This case never worked usefully, and it would crash on some platforms.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix configure's probe for OpenSSL's SSL_clear_options() function so that it works with OpenSSL versions before 1.1.0 (Michael Paquier, Daniel Gustafsson) §
This problem could lead to failure to set the SSL compression option as desired, when PostgreSQL is built against an old version of OpenSSL.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Mark some timeout and statistics-tracking GUC variables as PGDLLIMPORT, to allow extensions to access them on Windows (Pascal Legrand) §
This applies to idle_in_transaction_session_timeout, lock_timeout, statement_timeout, track_activities, track_counts, and track_functions.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Avoid memory leak in sanity checks for “slab” memory contexts (Tomas Vondra) §
This isn't an issue for production builds, since they wouldn't ordinarily have memory context checking enabled; but the leak could be quite severe in a debug build.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix multiple statistics entries reported by the LWLock statistics mechanism (Fujii Masao) §
The LWLock statistics code (which is not built by default; it requires compiling with -DLWLOCK_STATS) could report multiple entries for the same LWLock and backend process, as a result of faulty hashtable key creation.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix race condition that led to delayed delivery of interprocess signals on Windows (Amit Kapila) §
This caused visible timing oddities in NOTIFY, and perhaps other misbehavior.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
Fix handling of a corner-case error result from Windows' ReadFile() function (Thomas Munro, Juan José Santamaría Flecha) §
So far as is known, this oversight just resulted in noisy log messages, not any actual query misbehavior.
Changes
On Windows, retry a few times after an ERROR_ACCESS_DENIED file access failure (Alexander Lakhin, Tom Lane) § §
This helps cope with cases where a file open attempt fails because the targeted file is flagged for deletion but not yet actually gone. pg_ctl, for example, frequently failed with such an error when probing to see if the postmaster had shut down yet.
“Same change” requires complete matching evidence. “Related commits” can cover independent changes, a partial backport, or a follow-up correction; each release keeps its own explanation.
Changes
On Windows, work around sharing violations for the postmaster's log file when pg_ctl is used to start the postmaster very shortly after it's been stopped, for example by pg_ctl restart (Alexander Lakhin) §
Try another search, or .
The comparison follows PostgreSQL release notes from just after the source through the target version. For a major upgrade, maintenance releases from each older branch are included only up to the next major release date, and never after the target date. A major version such as 18 means its initial release, 18.0. Previews and development snapshots are labeled separately.
Entries come from the original English manuals. Release coverage and commit evidence are verified against upstream sources. Every entry retains its complete explanation and source link. Categories aid browsing; read the full notes for impact, conditions, and migration steps.
Fixes can be backported to several branches. Confirmed duplicates are merged conservatively, with every branch explanation retained. A note describing several independent fixes is excluded only when all are already present in the source. Major-release features remain distinct from related maintenance patches unless their complete original descriptions match. Uncertain matches are retained. This is a release-note history, not an exhaustive comparison of compiled binaries.
CVE results are calculated independently from the PostgreSQL security registry and vulnerability records. A CVE counts as gained protection only when the source is affected and the target is fixed or unaffected. Remaining vulnerabilities are listed separately. Security entries and distinct CVEs are counted separately.
Interaction inspired by pgversions.com and pgversionreport. Content comes from PostgreSQL release notes. See the release notes archive.