PostgreSQL 13
Read the English manualEnd of life · Recorded build 13.23 · 2025-11-13
This major branch is no longer supported. These records describe its history; the absence of newer security records does not establish that it is safe to run.
- First stable release
- 2020-09-24
- Support end
- 2025-11-13
- Indexed releases
- 24
- Original release-note entries
- 1164
Manuals & provenance
PostgreSQL 13 English manual · 1142 loaded pages.
Manual loaded 2026-09-27T00:10:47.078613.
Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.
Upgrade considerations
Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.
Compatibility notes for 13.0 · Changes from the initial release through 13.23
Original migration guidance for 13.0
A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 18.6 for general information on migrating to new major releases.
Version 13 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:
Release history
Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.
| Release | Date / snapshot cutoff | All changes | Bug fixes | Migration entries | CVE mentions |
|---|---|---|---|---|---|
| 13.23 | 2025-11-13 | 43 | 22 | 0 | 2 |
| 13.22 | 2025-08-14 | 44 | 10 | 0 | 5 |
| 13.21 | 2025-05-08 | 28 | 12 | 0 | 1 |
| 13.20 | 2025-02-20 | 2 | 1 | 0 | 1 |
| 13.19 | 2025-02-13 | 45 | 26 | 0 | 1 |
| 13.18 | 2024-11-21 | 4 | 2 | 0 | 1 |
| 13.17 | 2024-11-14 | 38 | 14 | 0 | 4 |
| 13.16 | 2024-08-08 | 36 | 17 | 0 | 2 |
| 13.15 | 2024-05-09 | 35 | 15 | 0 | 0 |
| 13.14 | 2024-02-08 | 40 | 15 | 0 | 1 |
| 13.13 | 2023-11-09 | 48 | 17 | 0 | 3 |
| 13.12 | 2023-08-10 | 36 | 17 | 0 | 1 |
| 13.11 | 2023-05-11 | 55 | 28 | 0 | 2 |
| 13.10 | 2023-02-09 | 38 | 15 | 0 | 1 |
| 13.9 | 2022-11-10 | 41 | 19 | 0 | 0 |
| 13.8 | 2022-08-11 | 43 | 18 | 0 | 2 |
| 13.7 | 2022-05-12 | 38 | 20 | 0 | 1 |
| 13.6 | 2022-02-10 | 41 | 21 | 0 | 0 |
| 13.5 | 2021-11-11 | 77 | 36 | 0 | 2 |
| 13.4 | 2021-08-12 | 77 | 28 | 0 | 3 |
| 13.3 | 2021-05-13 | 48 | 27 | 0 | 3 |
| 13.2 | 2021-02-11 | 80 | 42 | 0 | 2 |
| 13.1 | 2020-11-12 | 49 | 24 | 0 | 3 |
| 13.0 | 2020-09-24 | 178 | 4 | 15 | 0 |
Initial release changes
Original entries from 13.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.
178 of 178 original entries.
Change SIMILAR TO ... ESCAPE NULL to return NULL Compatibility Migration
Change
SIMILAR TO ... ESCAPE NULLto returnNULL(Tom Lane) §This new behavior matches the SQL specification. Previously a null
ESCAPEvalue was taken to mean using the default escape string (a backslash character). This also applies tosubstring(. The previous behavior has been retained in old views by keeping the original function unchanged.textFROMpatternESCAPEtext)Original release occurrence ·
13.0/migration/001Make json[b]_to_tsvector() fully check the spelling of its string option Compatibility Migration
Make
json[b]_to_tsvector()fully check the spelling of itsstringoption (Dominik Czarnota) §Original release occurrence ·
13.0/migration/002Change the way non-default effective_io_concurrency values affect concurrency Compatibility Migration
Change the way non-default effective_io_concurrency values affect concurrency (Thomas Munro) §
Previously, this value was adjusted before setting the number of concurrent requests. The value is now used directly. Conversion of old values to new ones can be done using:
SELECT round(sum(
OLDVALUE/ n::float)) AS newvalue FROM generate_series(1,OLDVALUE) s(n);Original release occurrence ·
13.0/migration/003Prevent display of auxiliary processes in pg_stat_ssl and pg_stat_gssapi system views Compatibility Migration
Prevent display of auxiliary processes in pg_stat_ssl and pg_stat_gssapi system views (Euler Taveira) §
Queries that join these views to pg_stat_activity and wish to see auxiliary processes will need to use left joins.
Original release occurrence ·
13.0/migration/004Rename various wait events to improve consistency Compatibility Migration
Original release occurrence ·
13.0/migration/005Fix ALTER FOREIGN TABLE ... RENAME COLUMN to return a more appropriate command tag Compatibility Migration
Fix
ALTER FOREIGN TABLE ... RENAME COLUMNto return a more appropriate command tag (Fujii Masao) §Previously it returned
ALTER TABLE; now it returnsALTER FOREIGN TABLE.Original release occurrence ·
13.0/migration/006Fix ALTER MATERIALIZED VIEW ... RENAME COLUMN to return a more appropriate command tag Compatibility Migration
Fix
ALTER MATERIALIZED VIEW ... RENAME COLUMNto return a more appropriate command tag (Fujii Masao) §Previously it returned
ALTER TABLE; now it returnsALTER MATERIALIZED VIEW.Original release occurrence ·
13.0/migration/007Rename configuration parameter wal_keep_segments to wal_keep_size Compatibility Migration
Rename configuration parameter
wal_keep_segmentsto wal_keep_size (Fujii Masao) §This determines how much WAL to retain for standby servers. It is specified in megabytes, rather than number of files as with the old parameter. If you previously used
wal_keep_segments, the following formula will give you an approximately equivalent setting:wal_keep_size = wal_keep_segments * wal_segment_size (typically 16MB)
Original release occurrence ·
13.0/migration/008Remove support for defining operator classes using pre-PostgreSQL 8.0 syntax Compatibility Migration
Remove support for defining operator classes using pre-PostgreSQL 8.0 syntax (Daniel Gustafsson) §
Original release occurrence ·
13.0/migration/009Remove support for defining foreign key constraints using pre-PostgreSQL 7.3 syntax Compatibility Migration
Remove support for defining foreign key constraints using pre-PostgreSQL 7.3 syntax (Daniel Gustafsson) §
Original release occurrence ·
13.0/migration/010Remove support for "opaque" pseudo-types used by pre-PostgreSQL 7.3 servers Compatibility Migration
Remove support for "opaque" pseudo-types used by pre-PostgreSQL 7.3 servers (Daniel Gustafsson) §
Original release occurrence ·
13.0/migration/011Remove support for upgrading unpackaged (pre-9.1) extensions Compatibility Migration
Remove support for upgrading unpackaged (pre-9.1) extensions (Tom Lane) §
The
FROMoption ofCREATE EXTENSIONis no longer supported. Any installations still using unpackaged extensions should upgrade them to a packaged version before updating to PostgreSQL 13.Original release occurrence ·
13.0/migration/012Remove support for posixrules files in the timezone database Compatibility Migration
Remove support for
posixrulesfiles in the timezone database (Tom Lane) §IANA's timezone group has deprecated this feature, meaning that it will gradually disappear from systems' timezone databases over the next few years. Rather than have a behavioral change appear unexpectedly with a timezone data update, we have removed PostgreSQL's support for this feature as of version 13. This affects only the behavior of POSIX-style time zone specifications that lack an explicit daylight savings transition rule; formerly the transition rule could be determined by installing a custom
posixrulesfile, but now it is hard-wired. The recommended fix for any affected installations is to start using a geographical time zone name.Original release occurrence ·
13.0/migration/013In ltree, when an lquery pattern contains adjacent asterisks with braces, e.g., *{2}.*{3}, properly interpret that as *{5} Compatibility Migration
In ltree, when an
lquerypattern contains adjacent asterisks with braces, e.g.,*{2}.*{3}, properly interpret that as*{5}(Nikita Glukhov) §Original release occurrence ·
13.0/migration/014Fix pageinspect's bt_metap() to return more appropriate data types that are less likely to overflow Compatibility Migration
Fix pageinspect's
bt_metap()to return more appropriate data types that are less likely to overflow (Peter Geoghegan) §Original release occurrence ·
13.0/migration/015Allow pruning of partitions to happen in more cases Features
Allow pruning of partitions to happen in more cases (Yuzuko Hosoya, Amit Langote, Álvaro Herrera) § §
Original release occurrence ·
13.0/changes/001Allow partitionwise joins to happen in more cases Features
Allow partitionwise joins to happen in more cases (Ashutosh Bapat, Etsuro Fujita, Amit Langote, Tom Lane) § §
For example, partitionwise joins can now happen between partitioned tables even when their partition bounds do not match exactly.
Original release occurrence ·
13.0/changes/002Support row-level BEFORE triggers on partitioned tables Features
Support row-level
BEFOREtriggers on partitioned tables (Álvaro Herrera) §However, such a trigger is not allowed to change which partition is the destination.
Original release occurrence ·
13.0/changes/003Allow partitioned tables to be logically replicated via publications Features
Allow partitioned tables to be logically replicated via publications (Amit Langote) § §
Previously, partitions had to be replicated individually. Now a partitioned table can be published explicitly, causing all its partitions to be published automatically. Addition/removal of a partition causes it to be likewise added to or removed from the publication. The
CREATE PUBLICATIONoptionpublish_via_partition_rootcontrols whether changes to partitions are published as their own changes or their parent's.Original release occurrence ·
13.0/changes/004Allow logical replication into partitioned tables on subscribers Features
Allow logical replication into partitioned tables on subscribers (Amit Langote) §
Previously, subscribers could only receive rows into non-partitioned tables.
Original release occurrence ·
13.0/changes/005Allow whole-row variables (that is, table.*) to be used in partitioning expressions Features
Allow whole-row variables (that is,
table.*) to be used in partitioning expressions (Amit Langote) §Original release occurrence ·
13.0/changes/006More efficiently store duplicates in B-tree indexes Features
More efficiently store duplicates in B-tree indexes (Anastasia Lubennikova, Peter Geoghegan) §
This allows efficient B-tree indexing of low-cardinality columns by storing duplicate keys only once. Users upgrading with pg_upgrade will need to use
REINDEXto make an existing index use this feature.Original release occurrence ·
13.0/changes/007Allow GiST and SP-GiST indexes on box columns to support ORDER BY box <-> point queries Features
Allow GiST and SP-GiST indexes on
boxcolumns to supportORDER BYqueries (Nikita Glukhov) § §box<->pointOriginal release occurrence ·
13.0/changes/008Allow GIN indexes to more efficiently handle ! (NOT) clauses in tsquery searches Features
Allow GIN indexes to more efficiently handle
!(NOT) clauses intsquerysearches (Nikita Glukhov, Alexander Korotkov, Tom Lane, Julien Rouhaud) §Original release occurrence ·
13.0/changes/009Allow index operator classes to take parameters Features
Allow index operator classes to take parameters (Nikita Glukhov) §
Original release occurrence ·
13.0/changes/010Allow CREATE INDEX to specify the GiST signature length and maximum number of integer ranges Features
Allow
CREATE INDEXto specify the GiST signature length and maximum number of integer ranges (Nikita Glukhov) §Indexes created on four and eight-byte integer array, tsvector, pg_trgm, ltree, and hstore columns can now control these GiST index parameters, rather than using the defaults.
Original release occurrence ·
13.0/changes/011Prevent indexes that use non-default collations from being added as a table's unique or primary key constraint Features
Prevent indexes that use non-default collations from being added as a table's unique or primary key constraint (Tom Lane) §
The index's collation must match that of the underlying column, but
ALTER TABLEpreviously failed to check this.Original release occurrence ·
13.0/changes/012Improve the optimizer's selectivity estimation for containment/match operators Features
Improve the optimizer's selectivity estimation for containment/match operators (Tom Lane) §
Original release occurrence ·
13.0/changes/013Allow setting the statistics target for extended statistics Features
Allow setting the statistics target for extended statistics (Tomas Vondra) §
This is controlled with the new command option
ALTER STATISTICS ... SET STATISTICS. Previously this was computed based on more general statistics target settings.Original release occurrence ·
13.0/changes/014Allow use of multiple extended statistics objects in a single query Features
Original release occurrence ·
13.0/changes/015Allow use of extended statistics objects for OR clauses and IN/ANY constant lists Features
Allow use of extended statistics objects for OR clauses and IN/
ANYconstant lists (Pierre Ducroquet, Tomas Vondra) § § §Original release occurrence ·
13.0/changes/016Allow functions in FROM clauses to be pulled up (inlined) if they evaluate to constants Features
Allow functions in
FROMclauses to be pulled up (inlined) if they evaluate to constants (Alexander Kuzmenkov, Aleksandr Parfenov) § §Original release occurrence ·
13.0/changes/017Implement incremental sorting Performance
Implement incremental sorting (James Coleman, Alexander Korotkov, Tomas Vondra) § §
If an intermediate query result is known to be sorted by one or more leading keys of a required sort ordering, the additional sorting can be done considering only the remaining keys, if the rows are sorted in batches that have equal leading keys.
If necessary, this can be controlled using enable_incremental_sort.
Original release occurrence ·
13.0/changes/018Improve the performance of sorting inet values Performance
Original release occurrence ·
13.0/changes/019Allow hash aggregation to use disk storage for large aggregation result sets Performance
Allow hash aggregation to use disk storage for large aggregation result sets (Jeff Davis) § § §
Previously, hash aggregation was avoided if it was expected to use more than work_mem memory. Now, a hash aggregation plan can be chosen despite that. The hash table will be spilled to disk if it exceeds
work_memtimes hash_mem_multiplier.This behavior is normally preferable to the old behavior, in which once hash aggregation had been chosen, the hash table would be kept in memory no matter how large it got — which could be very large if the planner had misestimated. If necessary, behavior similar to that can be obtained by increasing
hash_mem_multiplier.Original release occurrence ·
13.0/changes/020Allow inserts, not only updates and deletes, to trigger vacuuming activity in autovacuum Performance
Allow inserts, not only updates and deletes, to trigger vacuuming activity in autovacuum (Laurenz Albe, Darafei Praliaskouski) §
Previously, insert-only activity would trigger auto-analyze but not auto-vacuum, on the grounds that there could not be any dead tuples to remove. However, a vacuum scan has other useful side-effects such as setting page-all-visible bits, which improves the efficiency of index-only scans. Also, allowing an insert-only table to receive periodic vacuuming helps to spread out the work of “freezing” old tuples, so that there is not suddenly a large amount of freezing work to do when the entire table reaches the anti-wraparound threshold all at once.
If necessary, this behavior can be adjusted with the new parameters autovacuum_vacuum_insert_threshold and autovacuum_vacuum_insert_scale_factor, or the equivalent table storage options.
Original release occurrence ·
13.0/changes/021Add maintenance_io_concurrency parameter to control I/O concurrency for maintenance operations Performance
Add maintenance_io_concurrency parameter to control I/O concurrency for maintenance operations (Thomas Munro) §
Original release occurrence ·
13.0/changes/022Allow WAL writes to be skipped during a transaction that creates or rewrites a relation, if wal_level is minimal Performance
Allow WAL writes to be skipped during a transaction that creates or rewrites a relation, if wal_level is
minimal(Kyotaro Horiguchi) §Relations larger than wal_skip_threshold will have their files fsync'ed rather than generating WAL. Previously this was done only for
COPYoperations, but the implementation had a bug that could cause data loss during crash recovery.Original release occurrence ·
13.0/changes/023Improve performance when replaying DROP DATABASE commands when many tablespaces are in use Performance
Improve performance when replaying
DROP DATABASEcommands when many tablespaces are in use (Fujii Masao) §Original release occurrence ·
13.0/changes/024Improve performance for truncation of very large relations Performance
Improve performance for truncation of very large relations (Kirk Jamison) §
Original release occurrence ·
13.0/changes/025Improve retrieval of the leading bytes of TOAST'ed values Performance
Improve retrieval of the leading bytes of TOAST'ed values (Binguo Bao, Andrey Borodin) §
Previously, compressed out-of-line TOAST values were fully fetched even when it's known that only some leading bytes are needed. Now, only enough data to produce the result is fetched.
Original release occurrence ·
13.0/changes/026Improve performance of LISTEN/NOTIFY Performance
Original release occurrence ·
13.0/changes/027Speed up conversions of integers to text Performance
Speed up conversions of integers to text (David Fetter) §
Original release occurrence ·
13.0/changes/028Reduce memory usage for query strings and extension scripts that contain many SQL statements Performance
Reduce memory usage for query strings and extension scripts that contain many SQL statements (Amit Langote) §
Original release occurrence ·
13.0/changes/029Allow EXPLAIN, auto_explain, autovacuum, and pg_stat_statements to track WAL usage statistics Features
Allow
EXPLAIN, auto_explain, autovacuum, and pg_stat_statements to track WAL usage statistics (Kirill Bychik, Julien Rouhaud) § § §Original release occurrence ·
13.0/changes/030Allow a sample of SQL statements, rather than all statements, to be logged Features
Allow a sample of SQL statements, rather than all statements, to be logged (Adrien Nayrat) §
A log_statement_sample_rate fraction of those statements taking more than log_min_duration_sample duration will be logged.
Original release occurrence ·
13.0/changes/031Add the backend type to csvlog and optionally log_line_prefix log output Features
Add the backend type to csvlog and optionally log_line_prefix log output (Peter Eisentraut) §
Original release occurrence ·
13.0/changes/032Improve control of prepared statement parameter logging Features
Improve control of prepared statement parameter logging (Alexey Bashtanov, Álvaro Herrera) § §
The GUC setting log_parameter_max_length controls the maximum length of parameter values output during logging of non-error statements, while log_parameter_max_length_on_error does the same for logging of statements with errors. Previously, prepared statement parameters were never logged during errors.
Original release occurrence ·
13.0/changes/033Allow function call backtraces to be logged after errors Features
Allow function call backtraces to be logged after errors (Peter Eisentraut, Álvaro Herrera) § §
The new parameter backtrace_functions specifies which C functions should generate backtraces on error.
Original release occurrence ·
13.0/changes/034Make vacuum buffer counters 64-bits wide to avoid overflow Bug fixes
Original release occurrence ·
13.0/changes/035Add leader_pid to pg_stat_activity to report a parallel worker's leader process Features
Add
leader_pidto pg_stat_activity to report a parallel worker's leader process (Julien Rouhaud) §Original release occurrence ·
13.0/changes/036Add system view pg_stat_progress_basebackup to report the progress of streaming base backups Features
Add system view
pg_stat_progress_basebackupto report the progress of streaming base backups (Fujii Masao) §Original release occurrence ·
13.0/changes/037Add system view pg_stat_progress_analyze to report ANALYZE progress Features
Add system view
pg_stat_progress_analyzeto report ANALYZE progress (Álvaro Herrera, Tatsuro Yamada, Vinayak Pokale) §Original release occurrence ·
13.0/changes/038Add system view pg_shmem_allocations to display shared memory usage Features
Add system view
pg_shmem_allocationsto display shared memory usage (Andres Freund, Robert Haas) §Original release occurrence ·
13.0/changes/039Add system view pg_stat_slru to monitor internal SLRU caches Features
Add system view
pg_stat_slruto monitor internal SLRU caches (Tomas Vondra) §Original release occurrence ·
13.0/changes/040Allow track_activity_query_size to be set as high as 1MB Features
Allow track_activity_query_size to be set as high as 1MB (Vyacheslav Makarov) §
The previous maximum was 100kB.
Original release occurrence ·
13.0/changes/041Report a wait event while creating a DSM segment with posix_fallocate() Features
Report a wait event while creating a DSM segment with
posix_fallocate()(Thomas Munro) §Original release occurrence ·
13.0/changes/042Add wait event VacuumDelay to report on cost-based vacuum delay Features
Add wait event VacuumDelay to report on cost-based vacuum delay (Justin Pryzby) §
Original release occurrence ·
13.0/changes/043Add wait events for WAL archive and recovery pause Features
Add wait events for WAL archive and recovery pause (Fujii Masao) §
The new events are BackupWaitWalArchive and RecoveryPause.
Original release occurrence ·
13.0/changes/044Add wait events RecoveryConflictSnapshot and RecoveryConflictTablespace to monitor recovery conflicts Features
Add wait events RecoveryConflictSnapshot and RecoveryConflictTablespace to monitor recovery conflicts (Masahiko Sawada) §
Original release occurrence ·
13.0/changes/045Improve performance of wait events on BSD-based systems Performance
Improve performance of wait events on BSD-based systems (Thomas Munro) §
Original release occurrence ·
13.0/changes/046Allow only superusers to view the ssl_passphrase_command setting Features
Allow only superusers to view the ssl_passphrase_command setting (Insung Moon) §
This was changed as a security precaution.
Original release occurrence ·
13.0/changes/047Change the server's default minimum TLS version for encrypted connections from 1.0 to 1.2 Features
Change the server's default minimum TLS version for encrypted connections from 1.0 to 1.2 (Peter Eisentraut) §
This choice can be controlled by ssl_min_protocol_version.
Original release occurrence ·
13.0/changes/048Tighten rules on which utility commands are allowed in read-only transaction mode Features
Tighten rules on which utility commands are allowed in read-only transaction mode (Robert Haas) §
This change also increases the number of utility commands that can run in parallel queries.
Original release occurrence ·
13.0/changes/049Allow allow_system_table_mods to be changed after server start Features
Allow allow_system_table_mods to be changed after server start (Peter Eisentraut) §
Original release occurrence ·
13.0/changes/050Disallow non-superusers from modifying system tables when allow_system_table_mods is set Features
Disallow non-superusers from modifying system tables when allow_system_table_mods is set (Peter Eisentraut) §
Previously, if allow_system_table_mods was set at server start, non-superusers could issue
INSERT/UPDATE/DELETEcommands on system tables.Original release occurrence ·
13.0/changes/051Enable support for Unix-domain sockets on Windows Features
Enable support for Unix-domain sockets on Windows (Peter Eisentraut) §
Original release occurrence ·
13.0/changes/052Allow streaming replication configuration settings to be changed by reload Features
Allow streaming replication configuration settings to be changed by reload (Sergei Kornilov) §
Previously, a server restart was required to change primary_conninfo and primary_slot_name.
Original release occurrence ·
13.0/changes/053Allow WAL receivers to use a temporary replication slot when a permanent one is not specified Features
Allow WAL receivers to use a temporary replication slot when a permanent one is not specified (Peter Eisentraut, Sergei Kornilov) § §
This behavior can be enabled using wal_receiver_create_temp_slot.
Original release occurrence ·
13.0/changes/054Allow WAL storage for replication slots to be limited by max_slot_wal_keep_size Features
Allow WAL storage for replication slots to be limited by max_slot_wal_keep_size (Kyotaro Horiguchi) §
Replication slots that would require exceeding this value are marked invalid.
Original release occurrence ·
13.0/changes/055Allow standby promotion to cancel any requested pause Features
Allow standby promotion to cancel any requested pause (Fujii Masao) §
Previously, promotion could not happen while the standby was in paused state.
Original release occurrence ·
13.0/changes/056Generate an error if recovery does not reach the specified recovery target Features
Generate an error if recovery does not reach the specified recovery target (Leif Gunnar Erlandsen, Peter Eisentraut) §
Previously, a standby would promote itself upon reaching the end of WAL, even if the target was not reached.
Original release occurrence ·
13.0/changes/057Allow control over how much memory is used by logical decoding before it is spilled to disk Features
Allow control over how much memory is used by logical decoding before it is spilled to disk (Tomas Vondra, Dilip Kumar, Amit Kapila) §
This is controlled by logical_decoding_work_mem.
Original release occurrence ·
13.0/changes/058Allow recovery to continue even if invalid pages are referenced by WAL Features
Allow recovery to continue even if invalid pages are referenced by WAL (Fujii Masao) §
This is enabled using ignore_invalid_pages.
Original release occurrence ·
13.0/changes/059Allow VACUUM to process a table's indexes in parallel Features
Allow
VACUUMto process a table's indexes in parallel (Masahiko Sawada, Amit Kapila) §The new
PARALLELoption controls this.Original release occurrence ·
13.0/changes/060Allow FETCH FIRST to use WITH TIES to return any additional rows that match the last result row Features
Allow
FETCH FIRSTto useWITH TIESto return any additional rows that match the last result row (Surafel Temesgen) §Original release occurrence ·
13.0/changes/061Report planning-time buffer usage in EXPLAIN's BUFFER output Features
Original release occurrence ·
13.0/changes/062Make CREATE TABLE LIKE propagate a CHECK constraint's NO INHERIT property to the created table Features
Make
CREATE TABLE LIKEpropagate aCHECKconstraint'sNO INHERITproperty to the created table (Ildar Musin, Chris Travers) §Original release occurrence ·
13.0/changes/063When using LOCK TABLE on a partitioned table, do not check permissions on the child tables Features
When using
LOCK TABLEon a partitioned table, do not check permissions on the child tables (Amit Langote) §Original release occurrence ·
13.0/changes/064Allow OVERRIDING USER VALUE on inserts into identity columns Features
Allow
OVERRIDING USER VALUEon inserts into identity columns (Dean Rasheed) §Original release occurrence ·
13.0/changes/065Add ALTER TABLE ... DROP EXPRESSION to allow removing the GENERATED property from a column Features
Add
ALTER TABLE ... DROP EXPRESSIONto allow removing theGENERATEDproperty from a column (Peter Eisentraut) §Original release occurrence ·
13.0/changes/066Fix bugs in multi-step ALTER TABLE commands Bug fixes
Fix bugs in multi-step
ALTER TABLEcommands (Tom Lane) §IF NOT EXISTSclauses now work as expected, in that derived actions (such as index creation) do not execute if the column already exists. Also, certain cases of combining related actions into oneALTER TABLEnow work when they did not before.Original release occurrence ·
13.0/changes/067Add ALTER VIEW syntax to rename view columns Features
Add
ALTER VIEWsyntax to rename view columns (Fujii Masao) §Renaming view columns was already possible, but one had to write
ALTER TABLE RENAME COLUMN, which is confusing.Original release occurrence ·
13.0/changes/068Add ALTER TYPE options to modify a base type's TOAST properties and support functions Features
Add
ALTER TYPEoptions to modify a base type's TOAST properties and support functions (Tomas Vondra, Tom Lane) §Original release occurrence ·
13.0/changes/069Add CREATE DATABASE LOCALE option Features
Add
CREATE DATABASELOCALEoption (Peter Eisentraut) §This combines the existing options
LC_COLLATEandLC_CTYPEinto a single option.Original release occurrence ·
13.0/changes/070Allow DROP DATABASE to disconnect sessions using the target database, allowing the drop to succeed Features
Allow
DROP DATABASEto disconnect sessions using the target database, allowing the drop to succeed (Pavel Stehule, Amit Kapila) §This is enabled by the
FORCEoption.Original release occurrence ·
13.0/changes/071Add structure member tg_updatedcols to allow C-language update triggers to know which column(s) were updated Features
Add structure member
tg_updatedcolsto allow C-language update triggers to know which column(s) were updated (Peter Eisentraut) §Original release occurrence ·
13.0/changes/072Add polymorphic data types for use by functions requiring compatible arguments Features
Add polymorphic data types for use by functions requiring compatible arguments (Pavel Stehule) §
The new data types are
anycompatible,anycompatiblearray,anycompatiblenonarray, andanycompatiblerange.Original release occurrence ·
13.0/changes/073Add SQL data type xid8 to expose FullTransactionId Features
Add SQL data type
xid8to expose FullTransactionId (Thomas Munro) §The existing
xiddata type is only four bytes so it does not provide the transaction epoch.Original release occurrence ·
13.0/changes/074Add data type regcollation and associated functions, to represent OIDs of collation objects Features
Add data type
regcollationand associated functions, to represent OIDs of collation objects (Julien Rouhaud) §Original release occurrence ·
13.0/changes/075Use the glibc version in some cases as a collation version identifier Features
Use the glibc version in some cases as a collation version identifier (Thomas Munro) §
If the glibc version changes, a warning will be issued about possible corruption of collation-dependent indexes.
Original release occurrence ·
13.0/changes/076Add support for collation versions on Windows Features
Add support for collation versions on Windows (Thomas Munro) §
Original release occurrence ·
13.0/changes/077Allow ROW expressions to have their members extracted with suffix notation Features
Allow
ROWexpressions to have their members extracted with suffix notation (Tom Lane) §For example,
(ROW(4, 5.0)).f1now returns 4.Original release occurrence ·
13.0/changes/078Add alternate version of jsonb_set() with improved NULL handling Features
Add alternate version of
jsonb_set()with improvedNULLhandling (Andrew Dunstan) §The new function,
jsonb_set_lax(), handles aNULLnew value by either setting the specified key to a JSON null, deleting the key, raising an exception, or returning thejsonbvalue unmodified, as requested.Original release occurrence ·
13.0/changes/079Add jsonpath .datetime() method Features
Add jsonpath .
datetime()method (Nikita Glukhov, Teodor Sigaev, Oleg Bartunov, Alexander Korotkov) §This function allows JSON values to be converted to timestamps, which can then be processed in
jsonpathexpressions. This change also addsjsonpathfunctions that support time-zone-aware output.Original release occurrence ·
13.0/changes/080Add SQL functions NORMALIZE() to normalize Unicode strings, and IS NORMALIZED to check for normalization Features
Add SQL functions
NORMALIZE() to normalize Unicode strings, andIS NORMALIZEDto check for normalization (Peter Eisentraut) §Original release occurrence ·
13.0/changes/081Add min() and max() aggregates for pg_lsn Features
Add
min()andmax()aggregates forpg_lsn(Fabrízio de Royes Mello) §These are particularly useful in monitoring queries.
Original release occurrence ·
13.0/changes/082Allow Unicode escapes, e.g., E'\unnnn' or U&'\nnnn', to specify any character available in the database encoding, even when the database encoding is not UTF-8 Features
Allow Unicode escapes, e.g.,
E'\uornnnn'U&'\, to specify any character available in the database encoding, even when the database encoding is not UTF-8 (Tom Lane) §nnnn'Original release occurrence ·
13.0/changes/083Allow to_date() and to_timestamp() to recognize non-English month/day names Features
Allow
to_date()andto_timestamp()to recognize non-English month/day names (Juan José Santamaría Flecha, Tom Lane) §The names recognized are the same as those output by
to_char()with the same format patterns.Original release occurrence ·
13.0/changes/084Add datetime format patterns FF1 – FF6 to specify input or output of 1 to 6 fractional-second digits Features
Add datetime format patterns
FF1–FF6to specify input or output of 1 to 6 fractional-second digits (Alexander Korotkov, Nikita Glukhov, Teodor Sigaev, Oleg Bartunov) §These patterns can be used by
to_char(),to_timestamp(), and jsonpath's .datetime().Original release occurrence ·
13.0/changes/085Add SSSSS datetime format pattern as an SQL-standard alias for SSSS Features
Add
SSSSSdatetime format pattern as an SQL-standard alias forSSSS(Nikita Glukhov, Alexander Korotkov) §Original release occurrence ·
13.0/changes/086Add function gen_random_uuid() to generate version-4 UUIDs Features
Add function
gen_random_uuid()to generate version-4 UUIDs (Peter Eisentraut) §Previously UUID generation functions were only available in the external modules uuid-ossp and pgcrypto.
Original release occurrence ·
13.0/changes/087Add greatest-common-denominator (gcd) and least-common-multiple (lcm) functions Features
Original release occurrence ·
13.0/changes/088Improve the performance and accuracy of the numeric type's square root (sqrt) and natural log (ln) functions Performance
Improve the performance and accuracy of the
numerictype's square root (sqrt) and natural log (ln) functions (Dean Rasheed) § §Original release occurrence ·
13.0/changes/089Add function min_scale() that returns the number of digits to the right of the decimal point that are required to represent a numeric value with full accuracy Features
Add function
min_scale()that returns the number of digits to the right of the decimal point that are required to represent anumericvalue with full accuracy (Pavel Stehule) §Original release occurrence ·
13.0/changes/090Add function trim_scale() to reduce the scale of a numeric value by removing trailing zeros Features
Add function
trim_scale()to reduce the scale of anumericvalue by removing trailing zeros (Pavel Stehule) §Original release occurrence ·
13.0/changes/091Add commutators of distance operators Features
Add commutators of distance operators (Nikita Glukhov) §
For example, previously only
point<->linewas supported, nowline<->pointworks too.Original release occurrence ·
13.0/changes/092Create xid8 versions of all transaction ID functions Features
Create
xid8versions of all transaction ID functions (Thomas Munro) §The old
xid-based functions still exist, for backward compatibility.Original release occurrence ·
13.0/changes/093Allow get_bit() and set_bit() to set bits beyond the first 256MB of a bytea value Features
Original release occurrence ·
13.0/changes/094Allow advisory-lock functions to be used in some parallel operations Features
Allow advisory-lock functions to be used in some parallel operations (Tom Lane) §
Original release occurrence ·
13.0/changes/095Add the ability to remove an object's dependency on an extension Features
Add the ability to remove an object's dependency on an extension (Álvaro Herrera) §
The object can be a function, materialized view, index, or trigger. The syntax is
ALTER .. NO DEPENDS ON.Original release occurrence ·
13.0/changes/096Improve performance of simple PL/pgSQL expressions Performance
Improve performance of simple PL/pgSQL expressions (Tom Lane, Amit Langote) §
Original release occurrence ·
13.0/changes/097Improve performance of PL/pgSQL functions that use immutable expressions Performance
Improve performance of PL/pgSQL functions that use immutable expressions (Konstantin Knizhnik) §
Original release occurrence ·
13.0/changes/098Allow libpq clients to require channel binding for encrypted connections Features
Allow libpq clients to require channel binding for encrypted connections (Jeff Davis) §
Using the libpq connection parameter
channel_bindingforces the other end of the TLS connection to prove it knows the user's password. This prevents man-in-the-middle attacks.Original release occurrence ·
13.0/changes/099Add libpq connection parameters to control the minimum and maximum TLS version allowed for an encrypted connection Features
Add libpq connection parameters to control the minimum and maximum TLS version allowed for an encrypted connection (Daniel Gustafsson) § § §
The settings are ssl_min_protocol_version and ssl_max_protocol_version. By default, the minimum TLS version is 1.2 (this represents a behavioral change from previous releases).
Original release occurrence ·
13.0/changes/100Allow use of passwords to unlock client certificates Features
Allow use of passwords to unlock client certificates (Craig Ringer, Andrew Dunstan) §
This is enabled by libpq's sslpassword connection parameter.
Original release occurrence ·
13.0/changes/101Allow libpq to use DER-encoded client certificates Features
Allow libpq to use DER-encoded client certificates (Craig Ringer, Andrew Dunstan) §
Original release occurrence ·
13.0/changes/102Fix ecpg's EXEC SQL elif directive to work correctly Bug fixes
Fix ecpg's
EXEC SQL elifdirective to work correctly (Tom Lane) §Previously it behaved the same as
endiffollowed byifdef, so that a successful previous branch of the sameifconstruct did not prevent expansion of theelifbranch or following branches.Original release occurrence ·
13.0/changes/103Add transaction status (%x) to psql's default prompts Features
Original release occurrence ·
13.0/changes/104Allow the secondary psql prompt to be blank but the same width as the primary prompt Features
Allow the secondary psql prompt to be blank but the same width as the primary prompt (Thomas Munro) §
This is accomplished by setting
PROMPT2to%w.Original release occurrence ·
13.0/changes/105Allow psql's \g and \gx commands to change \pset output options for the duration of that single command Features
Allow psql's
\gand\gxcommands to change \pset output options for the duration of that single command (Tom Lane) §This feature allows syntax like
\g (expand=on), which is equivalent to\gx.Original release occurrence ·
13.0/changes/106Add psql commands to display operator classes and operator families Features
Add psql commands to display operator classes and operator families (Sergey Cherkashin, Nikita Glukhov, Alexander Korotkov) §
The new commands are
\dAc,\dAf,\dAo, and\dAp.Original release occurrence ·
13.0/changes/107Show table persistence in psql's \dt+ and related commands Features
Show table persistence in psql's
\dt+and related commands (David Fetter) §In verbose mode, the table/index/view shows if the object is permanent, temporary, or unlogged.
Original release occurrence ·
13.0/changes/108Improve output of psql's \d for TOAST tables Features
Original release occurrence ·
13.0/changes/109Fix redisplay after psql's \e command Bug fixes
Fix redisplay after psql's
\ecommand (Tom Lane) §When exiting the editor, if the query doesn't end with a semicolon or
\g, the query buffer contents will now be displayed.Original release occurrence ·
13.0/changes/110Add \warn command to psql Features
Add
\warncommand to psql (David Fetter) §This is like
\echoexcept that the text is sent to stderr instead of stdout.Original release occurrence ·
13.0/changes/111Add the PostgreSQL home page to command-line --help output Features
Add the PostgreSQL home page to command-line
--helpoutput (Peter Eisentraut) §Original release occurrence ·
13.0/changes/112Allow pgbench to partition its “accounts” table Features
Allow pgbench to partition its “accounts” table (Fabien Coelho) §
This allows performance testing of partitioning.
Original release occurrence ·
13.0/changes/113Add pgbench command \aset, which behaves like \gset, but for multiple queries Features
Add pgbench command
\aset, which behaves like\gset, but for multiple queries (Fabien Coelho) §Original release occurrence ·
13.0/changes/114Allow pgbench to generate its initial data server-side, rather than client-side Features
Allow pgbench to generate its initial data server-side, rather than client-side (Fabien Coelho) §
Original release occurrence ·
13.0/changes/115Allow pgbench to show script contents using option --show-script Features
Allow pgbench to show script contents using option
--show-script(Fabien Coelho) §Original release occurrence ·
13.0/changes/116Generate backup manifests for base backups, and verify them Features
Generate backup manifests for base backups, and verify them (Robert Haas) § §
A new tool pg_verifybackup can verify backups.
Original release occurrence ·
13.0/changes/117Have pg_basebackup estimate the total backup size by default Features
Have pg_basebackup estimate the total backup size by default (Fujii Masao) §
This computation allows
pg_stat_progress_basebackupto show progress. If that is not needed, it can be disabled by using the--no-estimate-sizeoption. Previously, this computation happened only if the--progressoption was used.Original release occurrence ·
13.0/changes/118Add an option to pg_rewind to configure standbys Features
Add an option to pg_rewind to configure standbys (Paul Guo, Jimmy Yih, Ashwin Agrawal) §
This matches pg_basebackup's
--write-recovery-confoption.Original release occurrence ·
13.0/changes/119Allow pg_rewind to use the target cluster's restore_command to retrieve needed WAL Features
Allow pg_rewind to use the target cluster's restore_command to retrieve needed WAL (Alexey Kondratov) §
This is enabled using the
-c/--restore-target-waloption.Original release occurrence ·
13.0/changes/120Have pg_rewind automatically run crash recovery before rewinding Features
Have pg_rewind automatically run crash recovery before rewinding (Paul Guo, Jimmy Yih, Ashwin Agrawal) §
This can be disabled by using
--no-ensure-shutdown.Original release occurrence ·
13.0/changes/121Increase the PREPARE TRANSACTION-related information reported by pg_waldump Features
Increase the
PREPARE TRANSACTION-related information reported by pg_waldump (Fujii Masao) §Original release occurrence ·
13.0/changes/122Add pg_waldump option --quiet to suppress non-error output Features
Add pg_waldump option
--quietto suppress non-error output (Andres Freund, Robert Haas) §Original release occurrence ·
13.0/changes/123Add pg_dump option --include-foreign-data to dump data from foreign servers Features
Original release occurrence ·
13.0/changes/124Allow vacuum commands run by vacuumdb to operate in parallel mode Features
Allow vacuum commands run by vacuumdb to operate in parallel mode (Masahiko Sawada) §
This is enabled with the new
--paralleloption.Original release occurrence ·
13.0/changes/125Allow reindexdb to operate in parallel Features
Allow reindexdb to operate in parallel (Julien Rouhaud) §
Parallel mode is enabled with the new
--jobsoption.Original release occurrence ·
13.0/changes/126Allow dropdb to disconnect sessions using the target database, allowing the drop to succeed Features
Allow dropdb to disconnect sessions using the target database, allowing the drop to succeed (Pavel Stehule) §
This is enabled with the
-foption.Original release occurrence ·
13.0/changes/127Remove --adduser and --no-adduser from createuser Features
Remove
--adduserand--no-adduserfrom createuser (Alexander Lakhin) §The long-supported preferred options for this are called
--superuserand--no-superuser.Original release occurrence ·
13.0/changes/128Use the directory of the pg_upgrade program as the default --new-bindir setting when running pg_upgrade Features
Use the directory of the pg_upgrade program as the default
--new-bindirsetting when running pg_upgrade (Daniel Gustafsson) §Original release occurrence ·
13.0/changes/129Add a glossary to the documentation Features
Original release occurrence ·
13.0/changes/130Reformat tables containing function and operator information for better clarity Features
Reformat tables containing function and operator information for better clarity (Tom Lane) §
Original release occurrence ·
13.0/changes/131Upgrade to use DocBook 4.5 Features
Upgrade to use DocBook 4.5 (Peter Eisentraut) §
Original release occurrence ·
13.0/changes/132Add support for building on Visual Studio 2019 Features
Add support for building on Visual Studio 2019 (Haribabu Kommi) §
Original release occurrence ·
13.0/changes/133Add build support for MSYS2 Features
Add build support for MSYS2 (Peter Eisentraut) §
Original release occurrence ·
13.0/changes/134Add compare_exchange and fetch_add assembly language code for Power PC compilers Features
Add compare_exchange and fetch_add assembly language code for Power PC compilers (Noah Misch) §
Original release occurrence ·
13.0/changes/135Update Snowball stemmer dictionaries used by full text search Features
Update Snowball stemmer dictionaries used by full text search (Panagiotis Mavrogiorgos) §
This adds Greek stemming and improves Danish and French stemming.
Original release occurrence ·
13.0/changes/136Remove support for Windows 2000 Features
Remove support for Windows 2000 (Michael Paquier) §
Original release occurrence ·
13.0/changes/137Remove support for non-ELF BSD systems Features
Remove support for non-ELF BSD systems (Peter Eisentraut) §
Original release occurrence ·
13.0/changes/138Remove support for Python versions 2.5.X and earlier Features
Original release occurrence ·
13.0/changes/139Remove support for OpenSSL 0.9.8 and 1.0.0 Features
Original release occurrence ·
13.0/changes/140Remove configure options --disable-float8-byval and --disable-float4-byval Features
Remove configure options
--disable-float8-byvaland--disable-float4-byval(Peter Eisentraut) § §These were needed for compatibility with some version-zero C functions, but those are no longer supported.
Original release occurrence ·
13.0/changes/141Pass the query string to planner hook functions Features
Pass the query string to planner hook functions (Pascal Legrand, Julien Rouhaud) §
Original release occurrence ·
13.0/changes/142Add TRUNCATE command hook Features
Original release occurrence ·
13.0/changes/143Add TLS init hook Features
Add TLS init hook (Andrew Dunstan) §
Original release occurrence ·
13.0/changes/144Allow building with no predefined Unix-domain socket directory Features
Allow building with no predefined Unix-domain socket directory (Peter Eisentraut) §
Original release occurrence ·
13.0/changes/145Reduce the probability of SysV resource key collision on Unix platforms Features
Reduce the probability of SysV resource key collision on Unix platforms (Tom Lane) §
Original release occurrence ·
13.0/changes/146Use operating system functions to reliably erase memory that contains sensitive information Features
Use operating system functions to reliably erase memory that contains sensitive information (Peter Eisentraut) §
For example, this is used for clearing passwords stored in memory.
Original release occurrence ·
13.0/changes/147Add headerscheck script to test C header-file compatibility Features
Add
headerscheckscript to test C header-file compatibility (Tom Lane) §Original release occurrence ·
13.0/changes/148Implement internal lists as arrays, rather than a chain of cells Features
Implement internal lists as arrays, rather than a chain of cells (Tom Lane) §
This improves performance for queries that access many objects.
Original release occurrence ·
13.0/changes/149Change the API for TS_execute() Features
Change the API for
TS_execute()(Tom Lane, Pavel Borisov) § §TS_executecallbacks must now provide ternary (yes/no/maybe) logic. Calculating NOT queries accurately is now the default.Original release occurrence ·
13.0/changes/150Allow extensions to be specified as trusted Features
Allow extensions to be specified as trusted (Tom Lane) §
Such extensions can be installed in a database by users with database-level
CREATEprivileges, even if they are not superusers. This change also removes thepg_pltemplatesystem catalog.Original release occurrence ·
13.0/changes/151Allow non-superusers to connect to postgres_fdw foreign servers without using a password Features
Allow non-superusers to connect to postgres_fdw foreign servers without using a password (Craig Ringer) §
Specifically, allow a superuser to set
password_requiredto false for a user mapping. Care must still be taken to prevent non-superusers from using superuser credentials to connect to the foreign server.Original release occurrence ·
13.0/changes/152Allow postgres_fdw to use certificate authentication Features
Allow postgres_fdw to use certificate authentication (Craig Ringer) §
Different users can use different certificates.
Original release occurrence ·
13.0/changes/153Allow sepgsql to control access to the TRUNCATE command Features
Original release occurrence ·
13.0/changes/154Add extension bool_plperl which transforms SQL booleans to/from PL/Perl booleans Features
Add extension bool_plperl which transforms SQL booleans to/from PL/Perl booleans (Ivan Panchenko) §
Original release occurrence ·
13.0/changes/155Have pg_stat_statements treat SELECT ... FOR UPDATE commands as distinct from those without FOR UPDATE Features
Have pg_stat_statements treat
SELECT ... FOR UPDATEcommands as distinct from those withoutFOR UPDATE(Andrew Gierth, Vik Fearing) §Original release occurrence ·
13.0/changes/156Allow pg_stat_statements to optionally track the planning time of statements Features
Allow pg_stat_statements to optionally track the planning time of statements (Julien Rouhaud, Pascal Legrand, Thomas Munro, Fujii Masao) § §
Previously only execution time was tracked.
Original release occurrence ·
13.0/changes/157Overhaul ltree's lquery syntax to treat NOT (!) more logically Features
Overhaul ltree's lquery syntax to treat
NOT(!) more logically (Filip Rembialkowski, Tom Lane, Nikita Glukhov) § §Also allow non-* queries to use a numeric range ({}) of matches.
Original release occurrence ·
13.0/changes/158Add support for binary I/O of ltree, lquery, and ltxtquery types Features
Original release occurrence ·
13.0/changes/159Add an option to dict_int to ignore the sign of integers Features
Original release occurrence ·
13.0/changes/160Add adminpack function pg_file_sync() to allow fsync'ing a file Features
Original release occurrence ·
13.0/changes/161Add pageinspect functions to output t_infomask/t_infomask2 values in human-readable format Features
Add pageinspect functions to output
t_infomask/t_infomask2values in human-readable format (Craig Ringer, Sawada Masahiko, Michael Paquier) § §Original release occurrence ·
13.0/changes/162Add B-tree index de-duplication processing columns to pageinspect output Features
Add B-tree index de-duplication processing columns to pageinspect output (Peter Geoghegan) §
Original release occurrence ·
13.0/changes/163
Security evidence
37 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.
CVE-2025-8715 · PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server CVSS 8.8
Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.
Fixed in this branch: 13.22. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
Fixed in this branch: 13.22. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2025-8713 · PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table CVSS 3.1
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
Fixed in this branch: 13.22. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2025-4207 · PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation CVSS 5.9
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
Fixed in this branch: 13.21. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound CVSS 5.9
Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
Fixed in this branch: 13.23. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege CVSS 3.1
Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
Fixed in this branch: 13.23. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2025-1094 · PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation CVSS 8.1
Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.
Fixed in this branch: 13.19. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-7348 · PostgreSQL relation replacement during pg_dump executes arbitrary SQL CVSS 8.8
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected. The PostgreSQL project thanks Noah Misch for reporting this problem.
Fixed in this branch: 13.16. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code CVSS 8.8
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.
Fixed in this branch: 13.17. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID CVSS 4.2
Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 13.17. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle CVSS 3.1
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 13.17. Component: client.
Official affected-branch entry: 13.
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes CVSS 4.2
Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
Fixed in this branch: 13.17. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2024-0985 · PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL CVSS 8.0
UPDATE (June 19, 2024) : Added v16 as impacted. Updated description to clarify the attack vector. Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view.
Fixed in this branch: 13.14. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes CVSS 2.2
Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.
Fixed in this branch: 13.13. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2023-5869 · Buffer overrun from integer overflow in array modification CVSS 8.8
While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.
Fixed in this branch: 13.13. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-5868 · Memory disclosure in aggregate function calls CVSS 4.3
Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.
Fixed in this branch: 13.13. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection CVSS 7.5
An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.
Fixed in this branch: 13.12. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-2455 · Row security policies disregard user ID changes after inlining CVSS 4.2
While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.
Fixed in this branch: 13.11. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes CVSS 7.2
This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
Fixed in this branch: 13.11. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2022-41862 · Client memory disclosure when connecting, with Kerberos, to modified server CVSS 3.7
A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. When a libpq client application has a Kerberos credential cache and doesn't explicitly disable option gssencmode , a server can cause libpq to over-read and report an error message containing uninitialized bytes from and following its receive buffer. If libpq's caller somehow makes that message accessible to the attacker, this achieves a disclosure of the over-read bytes. We have not confirmed or ruled out viability of attacks that arrange for a crash or for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 13.10. Component: client.
Official affected-branch entry: 13.
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2022-2625 · Extension scripts replace objects not belonging to the extension CVSS 7.1
Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.
Fixed in this branch: 13.8. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox CVSS 8.8
Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
Fixed in this branch: 13.7. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2021-3677 · Memory disclosure in certain queries CVSS 6.5
A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0 , the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.
Fixed in this branch: 13.4. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Release-note mentions:
CVE-2021-3449 · CVE-2021-3449
No fixed version for this branch is recorded.
Release-note mentions:
CVE-2021-3393 · Partition constraint violation errors leak values of denied columns CVSS 3.1
A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message. This is similar to CVE-2014-8161 , but the conditions to exploit are more rare. The PostgreSQL project thanks Heikki Linnakangas for reporting this problem.
Fixed in this branch: 13.2. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2021-32029 · Memory disclosure in partitioned-table UPDATE ... RETURNING CVSS 6.5
Using an UPDATE ... RETURNING on a purpose-crafted partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas typically cannot use this attack at will. The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 13.3. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Release-note mentions:
CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE CVSS 6.5
Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.
Fixed in this branch: 13.3. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Release-note mentions:
CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations CVSS 6.5
While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 13.3. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Release-note mentions:
CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle CVSS 3.7
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 13.5. Component: client.
Official affected-branch entry: 13.
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle CVSS 8.1
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 13.5. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2021-20229 · Single-column SELECT privilege enables reading all columns CVSS 3.1
A user having a SELECT privilege on an individual column can craft a special query that returns all columns of the table. Additionally, a stored view that uses column-level privileges will have incomplete column-usage bitmaps. In installations that depend on column-level permissions for security, it is recommended to execute CREATE OR REPLACE on all user-defined views to force them to be re-parsed. The PostgreSQL project thanks Sven Klemm for reporting this problem.
Fixed in this branch: 13.2. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2020-25696 · psql's \gset allows overwriting specially treated variables CVSS 7.5
The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.
Fixed in this branch: 13.1. Component: client.
Official affected-branch entry: 13.
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox CVSS 8.8
An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.
Fixed in this branch: 13.1. Component: core server.
Official affected-branch entry: 13.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2020-25694 · Reconnection can downgrade connection security settings CVSS 8.1
Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.
Fixed in this branch: 13.1. Component: client.
Official affected-branch entry: 13.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2012-0868 · Line breaks in object names can be exploited to execute arbitrary SQL when reloading a pg_dump file.
No fixed version for this branch is recorded.
Release-note mentions:
CVE-2006-2313 · An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible SQL injection.
No fixed version for this branch is recorded.
Release-note mentions:
Export this branch as JSON · Compare any two indexed releases