↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Versions

PostgreSQL 13

Read the English manual

End of life · Recorded build 13.23 · 2025-11-13

This major branch is no longer supported. These records describe its history; the absence of newer security records does not establish that it is safe to run.

First stable release
2020-09-24
Support end
2025-11-13
Indexed releases
24
Original release-note entries
1164

Manuals & provenance

PostgreSQL 13 English manual · 1142 loaded pages.

Manual loaded 2026-09-27T00:10:47.078613.

Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.

Upgrade considerations

Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.

Compatibility notes for 13.0 · Changes from the initial release through 13.23

Original migration guidance for 13.0

A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 18.6 for general information on migrating to new major releases.

Version 13 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:

Release history

Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.

ReleaseDate / snapshot cutoffAll changesBug fixesMigration entriesCVE mentions
13.23 2025-11-13 432202
13.22 2025-08-14 441005
13.21 2025-05-08 281201
13.20 2025-02-20 2101
13.19 2025-02-13 452601
13.18 2024-11-21 4201
13.17 2024-11-14 381404
13.16 2024-08-08 361702
13.15 2024-05-09 351500
13.14 2024-02-08 401501
13.13 2023-11-09 481703
13.12 2023-08-10 361701
13.11 2023-05-11 552802
13.10 2023-02-09 381501
13.9 2022-11-10 411900
13.8 2022-08-11 431802
13.7 2022-05-12 382001
13.6 2022-02-10 412100
13.5 2021-11-11 773602
13.4 2021-08-12 772803
13.3 2021-05-13 482703
13.2 2021-02-11 804202
13.1 2020-11-12 492403
13.0 2020-09-24 1784150

Initial release changes

Original entries from 13.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.

178 of 178 original entries.

  • Change SIMILAR TO ... ESCAPE NULL to return NULL Compatibility Migration

    Change SIMILAR TO ... ESCAPE NULL to return NULL (Tom Lane) §

    This new behavior matches the SQL specification. Previously a null ESCAPE value was taken to mean using the default escape string (a backslash character). This also applies to substring(text FROM pattern ESCAPE text). The previous behavior has been retained in old views by keeping the original function unchanged.

    Original release occurrence · 13.0/migration/001

  • Make json[b]_to_tsvector() fully check the spelling of its string option Compatibility Migration

    Make json[b]_to_tsvector() fully check the spelling of its string option (Dominik Czarnota) §

    Original release occurrence · 13.0/migration/002

  • Change the way non-default effective_io_concurrency values affect concurrency Compatibility Migration

    Change the way non-default effective_io_concurrency values affect concurrency (Thomas Munro) §

    Previously, this value was adjusted before setting the number of concurrent requests. The value is now used directly. Conversion of old values to new ones can be done using:

    SELECT round(sum(OLDVALUE / n::float)) AS newvalue FROM generate_series(1, OLDVALUE) s(n);
    

    Original release occurrence · 13.0/migration/003

  • Prevent display of auxiliary processes in pg_stat_ssl and pg_stat_gssapi system views Compatibility Migration

    Prevent display of auxiliary processes in pg_stat_ssl and pg_stat_gssapi system views (Euler Taveira) §

    Queries that join these views to pg_stat_activity and wish to see auxiliary processes will need to use left joins.

    Original release occurrence · 13.0/migration/004

  • Rename various wait events to improve consistency Compatibility Migration

    Rename various wait events to improve consistency (Fujii Masao, Tom Lane) § § § § §

    Original release occurrence · 13.0/migration/005

  • Fix ALTER FOREIGN TABLE ... RENAME COLUMN to return a more appropriate command tag Compatibility Migration

    Fix ALTER FOREIGN TABLE ... RENAME COLUMN to return a more appropriate command tag (Fujii Masao) §

    Previously it returned ALTER TABLE; now it returns ALTER FOREIGN TABLE.

    Original release occurrence · 13.0/migration/006

  • Fix ALTER MATERIALIZED VIEW ... RENAME COLUMN to return a more appropriate command tag Compatibility Migration

    Fix ALTER MATERIALIZED VIEW ... RENAME COLUMN to return a more appropriate command tag (Fujii Masao) §

    Previously it returned ALTER TABLE; now it returns ALTER MATERIALIZED VIEW.

    Original release occurrence · 13.0/migration/007

  • Rename configuration parameter wal_keep_segments to wal_keep_size Compatibility Migration

    Rename configuration parameter wal_keep_segments to wal_keep_size (Fujii Masao) §

    This determines how much WAL to retain for standby servers. It is specified in megabytes, rather than number of files as with the old parameter. If you previously used wal_keep_segments, the following formula will give you an approximately equivalent setting:

    wal_keep_size = wal_keep_segments * wal_segment_size (typically 16MB)
    

    Original release occurrence · 13.0/migration/008

  • Remove support for defining operator classes using pre-PostgreSQL 8.0 syntax Compatibility Migration

    Remove support for defining operator classes using pre-PostgreSQL 8.0 syntax (Daniel Gustafsson) §

    Original release occurrence · 13.0/migration/009

  • Remove support for defining foreign key constraints using pre-PostgreSQL 7.3 syntax Compatibility Migration

    Remove support for defining foreign key constraints using pre-PostgreSQL 7.3 syntax (Daniel Gustafsson) §

    Original release occurrence · 13.0/migration/010

  • Remove support for "opaque" pseudo-types used by pre-PostgreSQL 7.3 servers Compatibility Migration

    Remove support for "opaque" pseudo-types used by pre-PostgreSQL 7.3 servers (Daniel Gustafsson) §

    Original release occurrence · 13.0/migration/011

  • Remove support for upgrading unpackaged (pre-9.1) extensions Compatibility Migration

    Remove support for upgrading unpackaged (pre-9.1) extensions (Tom Lane) §

    The FROM option of CREATE EXTENSION is no longer supported. Any installations still using unpackaged extensions should upgrade them to a packaged version before updating to PostgreSQL 13.

    Original release occurrence · 13.0/migration/012

  • Remove support for posixrules files in the timezone database Compatibility Migration

    Remove support for posixrules files in the timezone database (Tom Lane) §

    IANA's timezone group has deprecated this feature, meaning that it will gradually disappear from systems' timezone databases over the next few years. Rather than have a behavioral change appear unexpectedly with a timezone data update, we have removed PostgreSQL's support for this feature as of version 13. This affects only the behavior of POSIX-style time zone specifications that lack an explicit daylight savings transition rule; formerly the transition rule could be determined by installing a custom posixrules file, but now it is hard-wired. The recommended fix for any affected installations is to start using a geographical time zone name.

    Original release occurrence · 13.0/migration/013

  • In ltree, when an lquery pattern contains adjacent asterisks with braces, e.g., *{2}.*{3}, properly interpret that as *{5} Compatibility Migration

    In ltree, when an lquery pattern contains adjacent asterisks with braces, e.g., *{2}.*{3}, properly interpret that as *{5} (Nikita Glukhov) §

    Original release occurrence · 13.0/migration/014

  • Fix pageinspect's bt_metap() to return more appropriate data types that are less likely to overflow Compatibility Migration

    Fix pageinspect's bt_metap() to return more appropriate data types that are less likely to overflow (Peter Geoghegan) §

    Original release occurrence · 13.0/migration/015

  • Allow pruning of partitions to happen in more cases Features

    Allow pruning of partitions to happen in more cases (Yuzuko Hosoya, Amit Langote, Álvaro Herrera) § §

    Original release occurrence · 13.0/changes/001

  • Allow partitionwise joins to happen in more cases Features

    Allow partitionwise joins to happen in more cases (Ashutosh Bapat, Etsuro Fujita, Amit Langote, Tom Lane) § §

    For example, partitionwise joins can now happen between partitioned tables even when their partition bounds do not match exactly.

    Original release occurrence · 13.0/changes/002

  • Support row-level BEFORE triggers on partitioned tables Features

    Support row-level BEFORE triggers on partitioned tables (Álvaro Herrera) §

    However, such a trigger is not allowed to change which partition is the destination.

    Original release occurrence · 13.0/changes/003

  • Allow partitioned tables to be logically replicated via publications Features

    Allow partitioned tables to be logically replicated via publications (Amit Langote) § §

    Previously, partitions had to be replicated individually. Now a partitioned table can be published explicitly, causing all its partitions to be published automatically. Addition/removal of a partition causes it to be likewise added to or removed from the publication. The CREATE PUBLICATION option publish_via_partition_root controls whether changes to partitions are published as their own changes or their parent's.

    Original release occurrence · 13.0/changes/004

  • Allow logical replication into partitioned tables on subscribers Features

    Allow logical replication into partitioned tables on subscribers (Amit Langote) §

    Previously, subscribers could only receive rows into non-partitioned tables.

    Original release occurrence · 13.0/changes/005

  • Allow whole-row variables (that is, table.*) to be used in partitioning expressions Features

    Allow whole-row variables (that is, table.*) to be used in partitioning expressions (Amit Langote) §

    Original release occurrence · 13.0/changes/006

  • More efficiently store duplicates in B-tree indexes Features

    More efficiently store duplicates in B-tree indexes (Anastasia Lubennikova, Peter Geoghegan) §

    This allows efficient B-tree indexing of low-cardinality columns by storing duplicate keys only once. Users upgrading with pg_upgrade will need to use REINDEX to make an existing index use this feature.

    Original release occurrence · 13.0/changes/007

  • Allow GiST and SP-GiST indexes on box columns to support ORDER BY box <-> point queries Features

    Allow GiST and SP-GiST indexes on box columns to support ORDER BY box <-> point queries (Nikita Glukhov) § §

    Original release occurrence · 13.0/changes/008

  • Allow GIN indexes to more efficiently handle ! (NOT) clauses in tsquery searches Features

    Allow GIN indexes to more efficiently handle ! (NOT) clauses in tsquery searches (Nikita Glukhov, Alexander Korotkov, Tom Lane, Julien Rouhaud) §

    Original release occurrence · 13.0/changes/009

  • Allow index operator classes to take parameters Features

    Allow index operator classes to take parameters (Nikita Glukhov) §

    Original release occurrence · 13.0/changes/010

  • Allow CREATE INDEX to specify the GiST signature length and maximum number of integer ranges Features

    Allow CREATE INDEX to specify the GiST signature length and maximum number of integer ranges (Nikita Glukhov) §

    Indexes created on four and eight-byte integer array, tsvector, pg_trgm, ltree, and hstore columns can now control these GiST index parameters, rather than using the defaults.

    Original release occurrence · 13.0/changes/011

  • Prevent indexes that use non-default collations from being added as a table's unique or primary key constraint Features

    Prevent indexes that use non-default collations from being added as a table's unique or primary key constraint (Tom Lane) §

    The index's collation must match that of the underlying column, but ALTER TABLE previously failed to check this.

    Original release occurrence · 13.0/changes/012

  • Improve the optimizer's selectivity estimation for containment/match operators Features

    Improve the optimizer's selectivity estimation for containment/match operators (Tom Lane) §

    Original release occurrence · 13.0/changes/013

  • Allow setting the statistics target for extended statistics Features

    Allow setting the statistics target for extended statistics (Tomas Vondra) §

    This is controlled with the new command option ALTER STATISTICS ... SET STATISTICS. Previously this was computed based on more general statistics target settings.

    Original release occurrence · 13.0/changes/014

  • Allow use of multiple extended statistics objects in a single query Features

    Allow use of multiple extended statistics objects in a single query (Tomas Vondra) § §

    Original release occurrence · 13.0/changes/015

  • Allow use of extended statistics objects for OR clauses and IN/ANY constant lists Features

    Allow use of extended statistics objects for OR clauses and IN/ANY constant lists (Pierre Ducroquet, Tomas Vondra) § § §

    Original release occurrence · 13.0/changes/016

  • Allow functions in FROM clauses to be pulled up (inlined) if they evaluate to constants Features

    Allow functions in FROM clauses to be pulled up (inlined) if they evaluate to constants (Alexander Kuzmenkov, Aleksandr Parfenov) § §

    Original release occurrence · 13.0/changes/017

  • Implement incremental sorting Performance

    Implement incremental sorting (James Coleman, Alexander Korotkov, Tomas Vondra) § §

    If an intermediate query result is known to be sorted by one or more leading keys of a required sort ordering, the additional sorting can be done considering only the remaining keys, if the rows are sorted in batches that have equal leading keys.

    If necessary, this can be controlled using enable_incremental_sort.

    Original release occurrence · 13.0/changes/018

  • Improve the performance of sorting inet values Performance

    Improve the performance of sorting inet values (Brandur Leach) §

    Original release occurrence · 13.0/changes/019

  • Allow hash aggregation to use disk storage for large aggregation result sets Performance

    Allow hash aggregation to use disk storage for large aggregation result sets (Jeff Davis) § § §

    Previously, hash aggregation was avoided if it was expected to use more than work_mem memory. Now, a hash aggregation plan can be chosen despite that. The hash table will be spilled to disk if it exceeds work_mem times hash_mem_multiplier.

    This behavior is normally preferable to the old behavior, in which once hash aggregation had been chosen, the hash table would be kept in memory no matter how large it got — which could be very large if the planner had misestimated. If necessary, behavior similar to that can be obtained by increasing hash_mem_multiplier.

    Original release occurrence · 13.0/changes/020

  • Allow inserts, not only updates and deletes, to trigger vacuuming activity in autovacuum Performance

    Allow inserts, not only updates and deletes, to trigger vacuuming activity in autovacuum (Laurenz Albe, Darafei Praliaskouski) §

    Previously, insert-only activity would trigger auto-analyze but not auto-vacuum, on the grounds that there could not be any dead tuples to remove. However, a vacuum scan has other useful side-effects such as setting page-all-visible bits, which improves the efficiency of index-only scans. Also, allowing an insert-only table to receive periodic vacuuming helps to spread out the work of “freezing” old tuples, so that there is not suddenly a large amount of freezing work to do when the entire table reaches the anti-wraparound threshold all at once.

    If necessary, this behavior can be adjusted with the new parameters autovacuum_vacuum_insert_threshold and autovacuum_vacuum_insert_scale_factor, or the equivalent table storage options.

    Original release occurrence · 13.0/changes/021

  • Add maintenance_io_concurrency parameter to control I/O concurrency for maintenance operations Performance

    Add maintenance_io_concurrency parameter to control I/O concurrency for maintenance operations (Thomas Munro) §

    Original release occurrence · 13.0/changes/022

  • Allow WAL writes to be skipped during a transaction that creates or rewrites a relation, if wal_level is minimal Performance

    Allow WAL writes to be skipped during a transaction that creates or rewrites a relation, if wal_level is minimal (Kyotaro Horiguchi) §

    Relations larger than wal_skip_threshold will have their files fsync'ed rather than generating WAL. Previously this was done only for COPY operations, but the implementation had a bug that could cause data loss during crash recovery.

    Original release occurrence · 13.0/changes/023

  • Improve performance when replaying DROP DATABASE commands when many tablespaces are in use Performance

    Improve performance when replaying DROP DATABASE commands when many tablespaces are in use (Fujii Masao) §

    Original release occurrence · 13.0/changes/024

  • Improve performance for truncation of very large relations Performance

    Improve performance for truncation of very large relations (Kirk Jamison) §

    Original release occurrence · 13.0/changes/025

  • Improve retrieval of the leading bytes of TOAST'ed values Performance

    Improve retrieval of the leading bytes of TOAST'ed values (Binguo Bao, Andrey Borodin) §

    Previously, compressed out-of-line TOAST values were fully fetched even when it's known that only some leading bytes are needed. Now, only enough data to produce the result is fetched.

    Original release occurrence · 13.0/changes/026

  • Improve performance of LISTEN/NOTIFY Performance

    Improve performance of LISTEN/NOTIFY (Martijn van Oosterhout, Tom Lane) § § §

    Original release occurrence · 13.0/changes/027

  • Speed up conversions of integers to text Performance

    Speed up conversions of integers to text (David Fetter) §

    Original release occurrence · 13.0/changes/028

  • Reduce memory usage for query strings and extension scripts that contain many SQL statements Performance

    Reduce memory usage for query strings and extension scripts that contain many SQL statements (Amit Langote) §

    Original release occurrence · 13.0/changes/029

  • Allow EXPLAIN, auto_explain, autovacuum, and pg_stat_statements to track WAL usage statistics Features

    Allow EXPLAIN, auto_explain, autovacuum, and pg_stat_statements to track WAL usage statistics (Kirill Bychik, Julien Rouhaud) § § §

    Original release occurrence · 13.0/changes/030

  • Allow a sample of SQL statements, rather than all statements, to be logged Features

    Allow a sample of SQL statements, rather than all statements, to be logged (Adrien Nayrat) §

    A log_statement_sample_rate fraction of those statements taking more than log_min_duration_sample duration will be logged.

    Original release occurrence · 13.0/changes/031

  • Add the backend type to csvlog and optionally log_line_prefix log output Features

    Add the backend type to csvlog and optionally log_line_prefix log output (Peter Eisentraut) §

    Original release occurrence · 13.0/changes/032

  • Improve control of prepared statement parameter logging Features

    Improve control of prepared statement parameter logging (Alexey Bashtanov, Álvaro Herrera) § §

    The GUC setting log_parameter_max_length controls the maximum length of parameter values output during logging of non-error statements, while log_parameter_max_length_on_error does the same for logging of statements with errors. Previously, prepared statement parameters were never logged during errors.

    Original release occurrence · 13.0/changes/033

  • Allow function call backtraces to be logged after errors Features

    Allow function call backtraces to be logged after errors (Peter Eisentraut, Álvaro Herrera) § §

    The new parameter backtrace_functions specifies which C functions should generate backtraces on error.

    Original release occurrence · 13.0/changes/034

  • Make vacuum buffer counters 64-bits wide to avoid overflow Bug fixes

    Make vacuum buffer counters 64-bits wide to avoid overflow (Álvaro Herrera) §

    Original release occurrence · 13.0/changes/035

  • Add leader_pid to pg_stat_activity to report a parallel worker's leader process Features

    Add leader_pid to pg_stat_activity to report a parallel worker's leader process (Julien Rouhaud) §

    Original release occurrence · 13.0/changes/036

  • Add system view pg_stat_progress_basebackup to report the progress of streaming base backups Features

    Add system view pg_stat_progress_basebackup to report the progress of streaming base backups (Fujii Masao) §

    Original release occurrence · 13.0/changes/037

  • Add system view pg_stat_progress_analyze to report ANALYZE progress Features

    Add system view pg_stat_progress_analyze to report ANALYZE progress (Álvaro Herrera, Tatsuro Yamada, Vinayak Pokale) §

    Original release occurrence · 13.0/changes/038

  • Add system view pg_shmem_allocations to display shared memory usage Features

    Add system view pg_shmem_allocations to display shared memory usage (Andres Freund, Robert Haas) §

    Original release occurrence · 13.0/changes/039

  • Add system view pg_stat_slru to monitor internal SLRU caches Features

    Add system view pg_stat_slru to monitor internal SLRU caches (Tomas Vondra) §

    Original release occurrence · 13.0/changes/040

  • Allow track_activity_query_size to be set as high as 1MB Features

    Allow track_activity_query_size to be set as high as 1MB (Vyacheslav Makarov) §

    The previous maximum was 100kB.

    Original release occurrence · 13.0/changes/041

  • Report a wait event while creating a DSM segment with posix_fallocate() Features

    Report a wait event while creating a DSM segment with posix_fallocate() (Thomas Munro) §

    Original release occurrence · 13.0/changes/042

  • Add wait event VacuumDelay to report on cost-based vacuum delay Features

    Add wait event VacuumDelay to report on cost-based vacuum delay (Justin Pryzby) §

    Original release occurrence · 13.0/changes/043

  • Add wait events for WAL archive and recovery pause Features

    Add wait events for WAL archive and recovery pause (Fujii Masao) §

    The new events are BackupWaitWalArchive and RecoveryPause.

    Original release occurrence · 13.0/changes/044

  • Add wait events RecoveryConflictSnapshot and RecoveryConflictTablespace to monitor recovery conflicts Features

    Add wait events RecoveryConflictSnapshot and RecoveryConflictTablespace to monitor recovery conflicts (Masahiko Sawada) §

    Original release occurrence · 13.0/changes/045

  • Improve performance of wait events on BSD-based systems Performance

    Improve performance of wait events on BSD-based systems (Thomas Munro) §

    Original release occurrence · 13.0/changes/046

  • Allow only superusers to view the ssl_passphrase_command setting Features

    Allow only superusers to view the ssl_passphrase_command setting (Insung Moon) §

    This was changed as a security precaution.

    Original release occurrence · 13.0/changes/047

  • Change the server's default minimum TLS version for encrypted connections from 1.0 to 1.2 Features

    Change the server's default minimum TLS version for encrypted connections from 1.0 to 1.2 (Peter Eisentraut) §

    This choice can be controlled by ssl_min_protocol_version.

    Original release occurrence · 13.0/changes/048

  • Tighten rules on which utility commands are allowed in read-only transaction mode Features

    Tighten rules on which utility commands are allowed in read-only transaction mode (Robert Haas) §

    This change also increases the number of utility commands that can run in parallel queries.

    Original release occurrence · 13.0/changes/049

  • Allow allow_system_table_mods to be changed after server start Features

    Allow allow_system_table_mods to be changed after server start (Peter Eisentraut) §

    Original release occurrence · 13.0/changes/050

  • Disallow non-superusers from modifying system tables when allow_system_table_mods is set Features

    Disallow non-superusers from modifying system tables when allow_system_table_mods is set (Peter Eisentraut) §

    Previously, if allow_system_table_mods was set at server start, non-superusers could issue INSERT/UPDATE/DELETE commands on system tables.

    Original release occurrence · 13.0/changes/051

  • Enable support for Unix-domain sockets on Windows Features

    Enable support for Unix-domain sockets on Windows (Peter Eisentraut) §

    Original release occurrence · 13.0/changes/052

  • Allow streaming replication configuration settings to be changed by reload Features

    Allow streaming replication configuration settings to be changed by reload (Sergei Kornilov) §

    Previously, a server restart was required to change primary_conninfo and primary_slot_name.

    Original release occurrence · 13.0/changes/053

  • Allow WAL receivers to use a temporary replication slot when a permanent one is not specified Features

    Allow WAL receivers to use a temporary replication slot when a permanent one is not specified (Peter Eisentraut, Sergei Kornilov) § §

    This behavior can be enabled using wal_receiver_create_temp_slot.

    Original release occurrence · 13.0/changes/054

  • Allow WAL storage for replication slots to be limited by max_slot_wal_keep_size Features

    Allow WAL storage for replication slots to be limited by max_slot_wal_keep_size (Kyotaro Horiguchi) §

    Replication slots that would require exceeding this value are marked invalid.

    Original release occurrence · 13.0/changes/055

  • Allow standby promotion to cancel any requested pause Features

    Allow standby promotion to cancel any requested pause (Fujii Masao) §

    Previously, promotion could not happen while the standby was in paused state.

    Original release occurrence · 13.0/changes/056

  • Generate an error if recovery does not reach the specified recovery target Features

    Generate an error if recovery does not reach the specified recovery target (Leif Gunnar Erlandsen, Peter Eisentraut) §

    Previously, a standby would promote itself upon reaching the end of WAL, even if the target was not reached.

    Original release occurrence · 13.0/changes/057

  • Allow control over how much memory is used by logical decoding before it is spilled to disk Features

    Allow control over how much memory is used by logical decoding before it is spilled to disk (Tomas Vondra, Dilip Kumar, Amit Kapila) §

    This is controlled by logical_decoding_work_mem.

    Original release occurrence · 13.0/changes/058

  • Allow recovery to continue even if invalid pages are referenced by WAL Features

    Allow recovery to continue even if invalid pages are referenced by WAL (Fujii Masao) §

    This is enabled using ignore_invalid_pages.

    Original release occurrence · 13.0/changes/059

  • Allow VACUUM to process a table's indexes in parallel Features

    Allow VACUUM to process a table's indexes in parallel (Masahiko Sawada, Amit Kapila) §

    The new PARALLEL option controls this.

    Original release occurrence · 13.0/changes/060

  • Allow FETCH FIRST to use WITH TIES to return any additional rows that match the last result row Features

    Allow FETCH FIRST to use WITH TIES to return any additional rows that match the last result row (Surafel Temesgen) §

    Original release occurrence · 13.0/changes/061

  • Report planning-time buffer usage in EXPLAIN's BUFFER output Features

    Report planning-time buffer usage in EXPLAIN's BUFFER output (Julien Rouhaud) §

    Original release occurrence · 13.0/changes/062

  • Make CREATE TABLE LIKE propagate a CHECK constraint's NO INHERIT property to the created table Features

    Make CREATE TABLE LIKE propagate a CHECK constraint's NO INHERIT property to the created table (Ildar Musin, Chris Travers) §

    Original release occurrence · 13.0/changes/063

  • When using LOCK TABLE on a partitioned table, do not check permissions on the child tables Features

    When using LOCK TABLE on a partitioned table, do not check permissions on the child tables (Amit Langote) §

    Original release occurrence · 13.0/changes/064

  • Allow OVERRIDING USER VALUE on inserts into identity columns Features

    Allow OVERRIDING USER VALUE on inserts into identity columns (Dean Rasheed) §

    Original release occurrence · 13.0/changes/065

  • Add ALTER TABLE ... DROP EXPRESSION to allow removing the GENERATED property from a column Features

    Add ALTER TABLE ... DROP EXPRESSION to allow removing the GENERATED property from a column (Peter Eisentraut) §

    Original release occurrence · 13.0/changes/066

  • Fix bugs in multi-step ALTER TABLE commands Bug fixes

    Fix bugs in multi-step ALTER TABLE commands (Tom Lane) §

    IF NOT EXISTS clauses now work as expected, in that derived actions (such as index creation) do not execute if the column already exists. Also, certain cases of combining related actions into one ALTER TABLE now work when they did not before.

    Original release occurrence · 13.0/changes/067

  • Add ALTER VIEW syntax to rename view columns Features

    Add ALTER VIEW syntax to rename view columns (Fujii Masao) §

    Renaming view columns was already possible, but one had to write ALTER TABLE RENAME COLUMN, which is confusing.

    Original release occurrence · 13.0/changes/068

  • Add ALTER TYPE options to modify a base type's TOAST properties and support functions Features

    Add ALTER TYPE options to modify a base type's TOAST properties and support functions (Tomas Vondra, Tom Lane) §

    Original release occurrence · 13.0/changes/069

  • Add CREATE DATABASE LOCALE option Features

    Add CREATE DATABASE LOCALE option (Peter Eisentraut) §

    This combines the existing options LC_COLLATE and LC_CTYPE into a single option.

    Original release occurrence · 13.0/changes/070

  • Allow DROP DATABASE to disconnect sessions using the target database, allowing the drop to succeed Features

    Allow DROP DATABASE to disconnect sessions using the target database, allowing the drop to succeed (Pavel Stehule, Amit Kapila) §

    This is enabled by the FORCE option.

    Original release occurrence · 13.0/changes/071

  • Add structure member tg_updatedcols to allow C-language update triggers to know which column(s) were updated Features

    Add structure member tg_updatedcols to allow C-language update triggers to know which column(s) were updated (Peter Eisentraut) §

    Original release occurrence · 13.0/changes/072

  • Add polymorphic data types for use by functions requiring compatible arguments Features

    Add polymorphic data types for use by functions requiring compatible arguments (Pavel Stehule) §

    The new data types are anycompatible, anycompatiblearray, anycompatiblenonarray, and anycompatiblerange.

    Original release occurrence · 13.0/changes/073

  • Add SQL data type xid8 to expose FullTransactionId Features

    Add SQL data type xid8 to expose FullTransactionId (Thomas Munro) §

    The existing xid data type is only four bytes so it does not provide the transaction epoch.

    Original release occurrence · 13.0/changes/074

  • Add data type regcollation and associated functions, to represent OIDs of collation objects Features

    Add data type regcollation and associated functions, to represent OIDs of collation objects (Julien Rouhaud) §

    Original release occurrence · 13.0/changes/075

  • Use the glibc version in some cases as a collation version identifier Features

    Use the glibc version in some cases as a collation version identifier (Thomas Munro) §

    If the glibc version changes, a warning will be issued about possible corruption of collation-dependent indexes.

    Original release occurrence · 13.0/changes/076

  • Add support for collation versions on Windows Features

    Add support for collation versions on Windows (Thomas Munro) §

    Original release occurrence · 13.0/changes/077

  • Allow ROW expressions to have their members extracted with suffix notation Features

    Allow ROW expressions to have their members extracted with suffix notation (Tom Lane) §

    For example, (ROW(4, 5.0)).f1 now returns 4.

    Original release occurrence · 13.0/changes/078

  • Add alternate version of jsonb_set() with improved NULL handling Features

    Add alternate version of jsonb_set() with improved NULL handling (Andrew Dunstan) §

    The new function, jsonb_set_lax(), handles a NULL new value by either setting the specified key to a JSON null, deleting the key, raising an exception, or returning the jsonb value unmodified, as requested.

    Original release occurrence · 13.0/changes/079

  • Add jsonpath .datetime() method Features

    Add jsonpath .datetime() method (Nikita Glukhov, Teodor Sigaev, Oleg Bartunov, Alexander Korotkov) §

    This function allows JSON values to be converted to timestamps, which can then be processed in jsonpath expressions. This change also adds jsonpath functions that support time-zone-aware output.

    Original release occurrence · 13.0/changes/080

  • Add SQL functions NORMALIZE() to normalize Unicode strings, and IS NORMALIZED to check for normalization Features

    Add SQL functions NORMALIZE() to normalize Unicode strings, and IS NORMALIZED to check for normalization (Peter Eisentraut) §

    Original release occurrence · 13.0/changes/081

  • Add min() and max() aggregates for pg_lsn Features

    Add min() and max() aggregates for pg_lsn (Fabrízio de Royes Mello) §

    These are particularly useful in monitoring queries.

    Original release occurrence · 13.0/changes/082

  • Allow Unicode escapes, e.g., E'\unnnn' or U&'\nnnn', to specify any character available in the database encoding, even when the database encoding is not UTF-8 Features

    Allow Unicode escapes, e.g., E'\unnnn' or U&'\nnnn', to specify any character available in the database encoding, even when the database encoding is not UTF-8 (Tom Lane) §

    Original release occurrence · 13.0/changes/083

  • Allow to_date() and to_timestamp() to recognize non-English month/day names Features

    Allow to_date() and to_timestamp() to recognize non-English month/day names (Juan José Santamaría Flecha, Tom Lane) §

    The names recognized are the same as those output by to_char() with the same format patterns.

    Original release occurrence · 13.0/changes/084

  • Add datetime format patterns FF1 – FF6 to specify input or output of 1 to 6 fractional-second digits Features

    Add datetime format patterns FF1 – FF6 to specify input or output of 1 to 6 fractional-second digits (Alexander Korotkov, Nikita Glukhov, Teodor Sigaev, Oleg Bartunov) §

    These patterns can be used by to_char(), to_timestamp(), and jsonpath's .datetime().

    Original release occurrence · 13.0/changes/085

  • Add SSSSS datetime format pattern as an SQL-standard alias for SSSS Features

    Add SSSSS datetime format pattern as an SQL-standard alias for SSSS (Nikita Glukhov, Alexander Korotkov) §

    Original release occurrence · 13.0/changes/086

  • Add function gen_random_uuid() to generate version-4 UUIDs Features

    Add function gen_random_uuid() to generate version-4 UUIDs (Peter Eisentraut) §

    Previously UUID generation functions were only available in the external modules uuid-ossp and pgcrypto.

    Original release occurrence · 13.0/changes/087

  • Add greatest-common-denominator (gcd) and least-common-multiple (lcm) functions Features

    Add greatest-common-denominator (gcd) and least-common-multiple (lcm) functions (Vik Fearing) §

    Original release occurrence · 13.0/changes/088

  • Improve the performance and accuracy of the numeric type's square root (sqrt) and natural log (ln) functions Performance

    Improve the performance and accuracy of the numeric type's square root (sqrt) and natural log (ln) functions (Dean Rasheed) § §

    Original release occurrence · 13.0/changes/089

  • Add function min_scale() that returns the number of digits to the right of the decimal point that are required to represent a numeric value with full accuracy Features

    Add function min_scale() that returns the number of digits to the right of the decimal point that are required to represent a numeric value with full accuracy (Pavel Stehule) §

    Original release occurrence · 13.0/changes/090

  • Add function trim_scale() to reduce the scale of a numeric value by removing trailing zeros Features

    Add function trim_scale() to reduce the scale of a numeric value by removing trailing zeros (Pavel Stehule) §

    Original release occurrence · 13.0/changes/091

  • Add commutators of distance operators Features

    Add commutators of distance operators (Nikita Glukhov) §

    For example, previously only point <-> line was supported, now line <-> point works too.

    Original release occurrence · 13.0/changes/092

  • Create xid8 versions of all transaction ID functions Features

    Create xid8 versions of all transaction ID functions (Thomas Munro) §

    The old xid-based functions still exist, for backward compatibility.

    Original release occurrence · 13.0/changes/093

  • Allow get_bit() and set_bit() to set bits beyond the first 256MB of a bytea value Features

    Allow get_bit() and set_bit() to set bits beyond the first 256MB of a bytea value (Movead Li) §

    Original release occurrence · 13.0/changes/094

  • Allow advisory-lock functions to be used in some parallel operations Features

    Allow advisory-lock functions to be used in some parallel operations (Tom Lane) §

    Original release occurrence · 13.0/changes/095

  • Add the ability to remove an object's dependency on an extension Features

    Add the ability to remove an object's dependency on an extension (Álvaro Herrera) §

    The object can be a function, materialized view, index, or trigger. The syntax is ALTER .. NO DEPENDS ON.

    Original release occurrence · 13.0/changes/096

  • Improve performance of simple PL/pgSQL expressions Performance

    Improve performance of simple PL/pgSQL expressions (Tom Lane, Amit Langote) §

    Original release occurrence · 13.0/changes/097

  • Improve performance of PL/pgSQL functions that use immutable expressions Performance

    Improve performance of PL/pgSQL functions that use immutable expressions (Konstantin Knizhnik) §

    Original release occurrence · 13.0/changes/098

  • Allow libpq clients to require channel binding for encrypted connections Features

    Allow libpq clients to require channel binding for encrypted connections (Jeff Davis) §

    Using the libpq connection parameter channel_binding forces the other end of the TLS connection to prove it knows the user's password. This prevents man-in-the-middle attacks.

    Original release occurrence · 13.0/changes/099

  • Add libpq connection parameters to control the minimum and maximum TLS version allowed for an encrypted connection Features

    Add libpq connection parameters to control the minimum and maximum TLS version allowed for an encrypted connection (Daniel Gustafsson) § § §

    The settings are ssl_min_protocol_version and ssl_max_protocol_version. By default, the minimum TLS version is 1.2 (this represents a behavioral change from previous releases).

    Original release occurrence · 13.0/changes/100

  • Allow use of passwords to unlock client certificates Features

    Allow use of passwords to unlock client certificates (Craig Ringer, Andrew Dunstan) §

    This is enabled by libpq's sslpassword connection parameter.

    Original release occurrence · 13.0/changes/101

  • Allow libpq to use DER-encoded client certificates Features

    Allow libpq to use DER-encoded client certificates (Craig Ringer, Andrew Dunstan) §

    Original release occurrence · 13.0/changes/102

  • Fix ecpg's EXEC SQL elif directive to work correctly Bug fixes

    Fix ecpg's EXEC SQL elif directive to work correctly (Tom Lane) §

    Previously it behaved the same as endif followed by ifdef, so that a successful previous branch of the same if construct did not prevent expansion of the elif branch or following branches.

    Original release occurrence · 13.0/changes/103

  • Add transaction status (%x) to psql's default prompts Features

    Add transaction status (%x) to psql's default prompts (Vik Fearing) §

    Original release occurrence · 13.0/changes/104

  • Allow the secondary psql prompt to be blank but the same width as the primary prompt Features

    Allow the secondary psql prompt to be blank but the same width as the primary prompt (Thomas Munro) §

    This is accomplished by setting PROMPT2 to %w.

    Original release occurrence · 13.0/changes/105

  • Allow psql's \g and \gx commands to change \pset output options for the duration of that single command Features

    Allow psql's \g and \gx commands to change \pset output options for the duration of that single command (Tom Lane) §

    This feature allows syntax like \g (expand=on), which is equivalent to \gx.

    Original release occurrence · 13.0/changes/106

  • Add psql commands to display operator classes and operator families Features

    Add psql commands to display operator classes and operator families (Sergey Cherkashin, Nikita Glukhov, Alexander Korotkov) §

    The new commands are \dAc, \dAf, \dAo, and \dAp.

    Original release occurrence · 13.0/changes/107

  • Show table persistence in psql's \dt+ and related commands Features

    Show table persistence in psql's \dt+ and related commands (David Fetter) §

    In verbose mode, the table/index/view shows if the object is permanent, temporary, or unlogged.

    Original release occurrence · 13.0/changes/108

  • Improve output of psql's \d for TOAST tables Features

    Improve output of psql's \d for TOAST tables (Justin Pryzby) §

    Original release occurrence · 13.0/changes/109

  • Fix redisplay after psql's \e command Bug fixes

    Fix redisplay after psql's \e command (Tom Lane) §

    When exiting the editor, if the query doesn't end with a semicolon or \g, the query buffer contents will now be displayed.

    Original release occurrence · 13.0/changes/110

  • Add \warn command to psql Features

    Add \warn command to psql (David Fetter) §

    This is like \echo except that the text is sent to stderr instead of stdout.

    Original release occurrence · 13.0/changes/111

  • Add the PostgreSQL home page to command-line --help output Features

    Add the PostgreSQL home page to command-line --help output (Peter Eisentraut) §

    Original release occurrence · 13.0/changes/112

  • Allow pgbench to partition its “accounts” table Features

    Allow pgbench to partition its “accounts” table (Fabien Coelho) §

    This allows performance testing of partitioning.

    Original release occurrence · 13.0/changes/113

  • Add pgbench command \aset, which behaves like \gset, but for multiple queries Features

    Add pgbench command \aset, which behaves like \gset, but for multiple queries (Fabien Coelho) §

    Original release occurrence · 13.0/changes/114

  • Allow pgbench to generate its initial data server-side, rather than client-side Features

    Allow pgbench to generate its initial data server-side, rather than client-side (Fabien Coelho) §

    Original release occurrence · 13.0/changes/115

  • Allow pgbench to show script contents using option --show-script Features

    Allow pgbench to show script contents using option --show-script (Fabien Coelho) §

    Original release occurrence · 13.0/changes/116

  • Generate backup manifests for base backups, and verify them Features

    Generate backup manifests for base backups, and verify them (Robert Haas) § §

    A new tool pg_verifybackup can verify backups.

    Original release occurrence · 13.0/changes/117

  • Have pg_basebackup estimate the total backup size by default Features

    Have pg_basebackup estimate the total backup size by default (Fujii Masao) §

    This computation allows pg_stat_progress_basebackup to show progress. If that is not needed, it can be disabled by using the --no-estimate-size option. Previously, this computation happened only if the --progress option was used.

    Original release occurrence · 13.0/changes/118

  • Add an option to pg_rewind to configure standbys Features

    Add an option to pg_rewind to configure standbys (Paul Guo, Jimmy Yih, Ashwin Agrawal) §

    This matches pg_basebackup's --write-recovery-conf option.

    Original release occurrence · 13.0/changes/119

  • Allow pg_rewind to use the target cluster's restore_command to retrieve needed WAL Features

    Allow pg_rewind to use the target cluster's restore_command to retrieve needed WAL (Alexey Kondratov) §

    This is enabled using the -c/--restore-target-wal option.

    Original release occurrence · 13.0/changes/120

  • Have pg_rewind automatically run crash recovery before rewinding Features

    Have pg_rewind automatically run crash recovery before rewinding (Paul Guo, Jimmy Yih, Ashwin Agrawal) §

    This can be disabled by using --no-ensure-shutdown.

    Original release occurrence · 13.0/changes/121

  • Increase the PREPARE TRANSACTION-related information reported by pg_waldump Features

    Increase the PREPARE TRANSACTION-related information reported by pg_waldump (Fujii Masao) §

    Original release occurrence · 13.0/changes/122

  • Add pg_waldump option --quiet to suppress non-error output Features

    Add pg_waldump option --quiet to suppress non-error output (Andres Freund, Robert Haas) §

    Original release occurrence · 13.0/changes/123

  • Add pg_dump option --include-foreign-data to dump data from foreign servers Features

    Add pg_dump option --include-foreign-data to dump data from foreign servers (Luis Carril) §

    Original release occurrence · 13.0/changes/124

  • Allow vacuum commands run by vacuumdb to operate in parallel mode Features

    Allow vacuum commands run by vacuumdb to operate in parallel mode (Masahiko Sawada) §

    This is enabled with the new --parallel option.

    Original release occurrence · 13.0/changes/125

  • Allow reindexdb to operate in parallel Features

    Allow reindexdb to operate in parallel (Julien Rouhaud) §

    Parallel mode is enabled with the new --jobs option.

    Original release occurrence · 13.0/changes/126

  • Allow dropdb to disconnect sessions using the target database, allowing the drop to succeed Features

    Allow dropdb to disconnect sessions using the target database, allowing the drop to succeed (Pavel Stehule) §

    This is enabled with the -f option.

    Original release occurrence · 13.0/changes/127

  • Remove --adduser and --no-adduser from createuser Features

    Remove --adduser and --no-adduser from createuser (Alexander Lakhin) §

    The long-supported preferred options for this are called --superuser and --no-superuser.

    Original release occurrence · 13.0/changes/128

  • Use the directory of the pg_upgrade program as the default --new-bindir setting when running pg_upgrade Features

    Use the directory of the pg_upgrade program as the default --new-bindir setting when running pg_upgrade (Daniel Gustafsson) §

    Original release occurrence · 13.0/changes/129

  • Add a glossary to the documentation Features

    Add a glossary to the documentation (Corey Huinker, Jürgen Purtz, Roger Harkavy, Álvaro Herrera) §

    Original release occurrence · 13.0/changes/130

  • Reformat tables containing function and operator information for better clarity Features

    Reformat tables containing function and operator information for better clarity (Tom Lane) §

    Original release occurrence · 13.0/changes/131

  • Upgrade to use DocBook 4.5 Features

    Upgrade to use DocBook 4.5 (Peter Eisentraut) §

    Original release occurrence · 13.0/changes/132

  • Add support for building on Visual Studio 2019 Features

    Add support for building on Visual Studio 2019 (Haribabu Kommi) §

    Original release occurrence · 13.0/changes/133

  • Add build support for MSYS2 Features

    Add build support for MSYS2 (Peter Eisentraut) §

    Original release occurrence · 13.0/changes/134

  • Add compare_exchange and fetch_add assembly language code for Power PC compilers Features

    Add compare_exchange and fetch_add assembly language code for Power PC compilers (Noah Misch) §

    Original release occurrence · 13.0/changes/135

  • Update Snowball stemmer dictionaries used by full text search Features

    Update Snowball stemmer dictionaries used by full text search (Panagiotis Mavrogiorgos) §

    This adds Greek stemming and improves Danish and French stemming.

    Original release occurrence · 13.0/changes/136

  • Remove support for Windows 2000 Features

    Remove support for Windows 2000 (Michael Paquier) §

    Original release occurrence · 13.0/changes/137

  • Remove support for non-ELF BSD systems Features

    Remove support for non-ELF BSD systems (Peter Eisentraut) §

    Original release occurrence · 13.0/changes/138

  • Remove support for Python versions 2.5.X and earlier Features

    Remove support for Python versions 2.5.X and earlier (Peter Eisentraut) §

    Original release occurrence · 13.0/changes/139

  • Remove support for OpenSSL 0.9.8 and 1.0.0 Features

    Remove support for OpenSSL 0.9.8 and 1.0.0 (Michael Paquier) §

    Original release occurrence · 13.0/changes/140

  • Remove configure options --disable-float8-byval and --disable-float4-byval Features

    Remove configure options --disable-float8-byval and --disable-float4-byval (Peter Eisentraut) § §

    These were needed for compatibility with some version-zero C functions, but those are no longer supported.

    Original release occurrence · 13.0/changes/141

  • Pass the query string to planner hook functions Features

    Pass the query string to planner hook functions (Pascal Legrand, Julien Rouhaud) §

    Original release occurrence · 13.0/changes/142

  • Add TRUNCATE command hook Features

    Add TRUNCATE command hook (Yuli Khodorkovskiy) §

    Original release occurrence · 13.0/changes/143

  • Add TLS init hook Features

    Add TLS init hook (Andrew Dunstan) §

    Original release occurrence · 13.0/changes/144

  • Allow building with no predefined Unix-domain socket directory Features

    Allow building with no predefined Unix-domain socket directory (Peter Eisentraut) §

    Original release occurrence · 13.0/changes/145

  • Reduce the probability of SysV resource key collision on Unix platforms Features

    Reduce the probability of SysV resource key collision on Unix platforms (Tom Lane) §

    Original release occurrence · 13.0/changes/146

  • Use operating system functions to reliably erase memory that contains sensitive information Features

    Use operating system functions to reliably erase memory that contains sensitive information (Peter Eisentraut) §

    For example, this is used for clearing passwords stored in memory.

    Original release occurrence · 13.0/changes/147

  • Add headerscheck script to test C header-file compatibility Features

    Add headerscheck script to test C header-file compatibility (Tom Lane) §

    Original release occurrence · 13.0/changes/148

  • Implement internal lists as arrays, rather than a chain of cells Features

    Implement internal lists as arrays, rather than a chain of cells (Tom Lane) §

    This improves performance for queries that access many objects.

    Original release occurrence · 13.0/changes/149

  • Change the API for TS_execute() Features

    Change the API for TS_execute() (Tom Lane, Pavel Borisov) § §

    TS_execute callbacks must now provide ternary (yes/no/maybe) logic. Calculating NOT queries accurately is now the default.

    Original release occurrence · 13.0/changes/150

  • Allow extensions to be specified as trusted Features

    Allow extensions to be specified as trusted (Tom Lane) §

    Such extensions can be installed in a database by users with database-level CREATE privileges, even if they are not superusers. This change also removes the pg_pltemplate system catalog.

    Original release occurrence · 13.0/changes/151

  • Allow non-superusers to connect to postgres_fdw foreign servers without using a password Features

    Allow non-superusers to connect to postgres_fdw foreign servers without using a password (Craig Ringer) §

    Specifically, allow a superuser to set password_required to false for a user mapping. Care must still be taken to prevent non-superusers from using superuser credentials to connect to the foreign server.

    Original release occurrence · 13.0/changes/152

  • Allow postgres_fdw to use certificate authentication Features

    Allow postgres_fdw to use certificate authentication (Craig Ringer) §

    Different users can use different certificates.

    Original release occurrence · 13.0/changes/153

  • Allow sepgsql to control access to the TRUNCATE command Features

    Allow sepgsql to control access to the TRUNCATE command (Yuli Khodorkovskiy) §

    Original release occurrence · 13.0/changes/154

  • Add extension bool_plperl which transforms SQL booleans to/from PL/Perl booleans Features

    Add extension bool_plperl which transforms SQL booleans to/from PL/Perl booleans (Ivan Panchenko) §

    Original release occurrence · 13.0/changes/155

  • Have pg_stat_statements treat SELECT ... FOR UPDATE commands as distinct from those without FOR UPDATE Features

    Have pg_stat_statements treat SELECT ... FOR UPDATE commands as distinct from those without FOR UPDATE (Andrew Gierth, Vik Fearing) §

    Original release occurrence · 13.0/changes/156

  • Allow pg_stat_statements to optionally track the planning time of statements Features

    Allow pg_stat_statements to optionally track the planning time of statements (Julien Rouhaud, Pascal Legrand, Thomas Munro, Fujii Masao) § §

    Previously only execution time was tracked.

    Original release occurrence · 13.0/changes/157

  • Overhaul ltree's lquery syntax to treat NOT (!) more logically Features

    Overhaul ltree's lquery syntax to treat NOT (!) more logically (Filip Rembialkowski, Tom Lane, Nikita Glukhov) § §

    Also allow non-* queries to use a numeric range ({}) of matches.

    Original release occurrence · 13.0/changes/158

  • Add support for binary I/O of ltree, lquery, and ltxtquery types Features

    Add support for binary I/O of ltree, lquery, and ltxtquery types (Nino Floris) §

    Original release occurrence · 13.0/changes/159

  • Add an option to dict_int to ignore the sign of integers Features

    Add an option to dict_int to ignore the sign of integers (Jeff Janes) §

    Original release occurrence · 13.0/changes/160

  • Add adminpack function pg_file_sync() to allow fsync'ing a file Features

    Add adminpack function pg_file_sync() to allow fsync'ing a file (Fujii Masao) §

    Original release occurrence · 13.0/changes/161

  • Add pageinspect functions to output t_infomask/t_infomask2 values in human-readable format Features

    Add pageinspect functions to output t_infomask/t_infomask2 values in human-readable format (Craig Ringer, Sawada Masahiko, Michael Paquier) § §

    Original release occurrence · 13.0/changes/162

  • Add B-tree index de-duplication processing columns to pageinspect output Features

    Add B-tree index de-duplication processing columns to pageinspect output (Peter Geoghegan) §

    Original release occurrence · 13.0/changes/163

Security evidence

37 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.

CVE-2025-8715 · PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server CVSS 8.8

Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.

Fixed in this branch: 13.22. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client CVSS 8.8

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

Fixed in this branch: 13.22. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8713 · PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table CVSS 3.1

PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

Fixed in this branch: 13.22. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2025-4207 · PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation CVSS 5.9

Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.

Fixed in this branch: 13.21. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound CVSS 5.9

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Fixed in this branch: 13.23. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege CVSS 3.1

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Fixed in this branch: 13.23. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2025-1094 · PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation CVSS 8.1

Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.

Fixed in this branch: 13.19. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-7348 · PostgreSQL relation replacement during pg_dump executes arbitrary SQL CVSS 8.8

Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected. The PostgreSQL project thanks Noah Misch for reporting this problem.

Fixed in this branch: 13.16. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code CVSS 8.8

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.

Fixed in this branch: 13.17. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID CVSS 4.2

Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 13.17. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle CVSS 3.1

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 13.17. Component: client.

Official affected-branch entry: 13.

AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes CVSS 4.2

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

Fixed in this branch: 13.17. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2024-0985 · PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL CVSS 8.0

UPDATE (June 19, 2024) : Added v16 as impacted. Updated description to clarify the attack vector. Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view.

Fixed in this branch: 13.14. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes CVSS 2.2

Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.

Fixed in this branch: 13.13. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2023-5869 · Buffer overrun from integer overflow in array modification CVSS 8.8

While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.

Fixed in this branch: 13.13. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-5868 · Memory disclosure in aggregate function calls CVSS 4.3

Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.

Fixed in this branch: 13.13. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection CVSS 7.5

An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.

Fixed in this branch: 13.12. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-2455 · Row security policies disregard user ID changes after inlining CVSS 4.2

While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.

Fixed in this branch: 13.11. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes CVSS 7.2

This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.

Fixed in this branch: 13.11. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2022-41862 · Client memory disclosure when connecting, with Kerberos, to modified server CVSS 3.7

A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. When a libpq client application has a Kerberos credential cache and doesn't explicitly disable option gssencmode , a server can cause libpq to over-read and report an error message containing uninitialized bytes from and following its receive buffer. If libpq's caller somehow makes that message accessible to the attacker, this achieves a disclosure of the over-read bytes. We have not confirmed or ruled out viability of attacks that arrange for a crash or for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 13.10. Component: client.

Official affected-branch entry: 13.

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2022-2625 · Extension scripts replace objects not belonging to the extension CVSS 7.1

Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.

Fixed in this branch: 13.8. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox CVSS 8.8

Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.

Fixed in this branch: 13.7. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2021-3677 · Memory disclosure in certain queries CVSS 6.5

A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0 , the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.

Fixed in this branch: 13.4. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Release-note mentions:

CVE-2021-3449 · CVE-2021-3449

No fixed version for this branch is recorded.

Release-note mentions:

CVE-2021-3393 · Partition constraint violation errors leak values of denied columns CVSS 3.1

A user having an UPDATE privilege on a partitioned table but lacking the SELECT privilege on some column may be able to acquire denied-column values from an error message. This is similar to CVE-2014-8161 , but the conditions to exploit are more rare. The PostgreSQL project thanks Heikki Linnakangas for reporting this problem.

Fixed in this branch: 13.2. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2021-32029 · Memory disclosure in partitioned-table UPDATE ... RETURNING CVSS 6.5

Using an UPDATE ... RETURNING on a purpose-crafted partitioned table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas typically cannot use this attack at will. The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 13.3. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Release-note mentions:

CVE-2021-32028 · Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE CVSS 6.5

Using an INSERT ... ON CONFLICT ... DO UPDATE command on a purpose-crafted table, an attacker can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can create prerequisite objects and complete this attack at will. A user lacking the CREATE and TEMPORARY privileges on all databases and the CREATE privilege on all schemas cannot use this attack at will. The PostgreSQL project thanks Andres Freund for reporting this problem.

Fixed in this branch: 13.3. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Release-note mentions:

CVE-2021-32027 · Buffer overrun from integer overflow in array subscripting calculations CVSS 6.5

While modifying certain SQL array values, missing bounds checks let authenticated database users write arbitrary bytes to a wide area of server memory. The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 13.3. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Release-note mentions:

CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle CVSS 3.7

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 13.5. Component: client.

Official affected-branch entry: 13.

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle CVSS 8.1

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 13.5. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2021-20229 · Single-column SELECT privilege enables reading all columns CVSS 3.1

A user having a SELECT privilege on an individual column can craft a special query that returns all columns of the table. Additionally, a stored view that uses column-level privileges will have incomplete column-usage bitmaps. In installations that depend on column-level permissions for security, it is recommended to execute CREATE OR REPLACE on all user-defined views to force them to be re-parsed. The PostgreSQL project thanks Sven Klemm for reporting this problem.

Fixed in this branch: 13.2. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2020-25696 · psql's \gset allows overwriting specially treated variables CVSS 7.5

The \gset meta-command, which sets psql variables based on query results, does not distinguish variables that control psql behavior. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating system account running psql . Using \gset with a prefix not found among specially treated variables, e.g. any lowercase string, precludes the attack in an unpatched psql . The PostgreSQL project thanks Nick Cleaton for reporting this problem.

Fixed in this branch: 13.1. Component: client.

Official affected-branch entry: 13.

AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-25695 · Multiple features escape "security restricted operation" sandbox CVSS 8.8

An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum and not manually running ANALYZE , CLUSTER , REINDEX , CREATE INDEX , VACUUM FULL , REFRESH MATERIALIZED VIEW , or a restore from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM without the FULL option is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Etienne Stalmans for reporting this problem.

Fixed in this branch: 13.1. Component: core server.

Official affected-branch entry: 13.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2020-25694 · Reconnection can downgrade connection security settings CVSS 8.1

Many PostgreSQL-provided client applications have options that create additional database connections. Some of those applications reuse only the basic connection parameters (e.g. host , user , port ), dropping others. If this drops a security-relevant parameter (e.g. channel_binding , sslmode , requirepeer , gssencmode ), the attacker has an opportunity to complete a MITM attack or observe cleartext transmission. Affected applications are clusterdb , pg_dump , pg_restore , psql , reindexdb , and vacuumdb . The vulnerability arises only if one invokes an affected client application with a connection string containing a security-relevant parameter. This also fixes how the \connect command of psql reuses connection parameters, i.e. all non-overridden parameters from a previous connection string now re-used. The PostgreSQL project thanks Peter Eisentraut for reporting this problem.

Fixed in this branch: 13.1. Component: client.

Official affected-branch entry: 13.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2012-0868 · Line breaks in object names can be exploited to execute arbitrary SQL when reloading a pg_dump file.

No fixed version for this branch is recorded.

Release-note mentions:

CVE-2006-2313 · An attacker able to submit crafted strings to an application that will embed those strings in SQL commands can use invalidly-encoded multibyte characters to bypass standard string-escaping methods, resulting in possible SQL injection.

Export this branch as JSON · Compare any two indexed releases