↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Versions

PostgreSQL 14

Read the English manual

Supported · Recorded build 14.24 · 2026-08-13

First stable release
2021-09-30
Support end
2026-11-12
Indexed releases
25
Original release-note entries
1206

Manuals & provenance

PostgreSQL 14 English manual · 1161 loaded pages.

Manual loaded 2026-09-27T00:10:47.078613.

Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.

Upgrade considerations

Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.

Compatibility notes for 14.0 · Changes from the initial release through 14.24

Original migration guidance for 14.0

A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 19.6 for general information on migrating to new major releases.

Version 14 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:

Release history

Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.

ReleaseDate / snapshot cutoffAll changesBug fixesMigration entriesCVE mentions
14.24 2026-08-13 8331031
14.23 2026-05-14 381508
14.22 2026-02-26 5401
14.21 2026-02-12 371604
14.20 2025-11-13 462302
14.19 2025-08-14 471205
14.18 2025-05-08 351601
14.17 2025-02-20 2101
14.16 2025-02-13 462601
14.15 2024-11-21 7301
14.14 2024-11-14 441704
14.13 2024-08-08 422102
14.12 2024-05-09 421801
14.11 2024-02-08 491801
14.10 2023-11-09 562103
14.9 2023-08-10 392001
14.8 2023-05-11 673102
14.7 2023-02-09 472301
14.6 2022-11-10 411700
14.5 2022-08-11 391802
14.4 2022-06-16 19900
14.3 2022-05-12 522501
14.2 2022-02-10 573100
14.1 2021-11-11 462102
14.0 2021-09-30 2202270

Initial release changes

Original entries from 14.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.

220 of 220 original entries.

  • User-defined objects that reference certain built-in array functions along with their argument types must be recreated Compatibility Migration

    User-defined objects that reference certain built-in array functions along with their argument types must be recreated (Tom Lane) §

    Specifically, array_append(), array_prepend(), array_cat(), array_position(), array_positions(), array_remove(), array_replace(), and width_bucket() used to take anyarray arguments but now take anycompatiblearray. Therefore, user-defined objects like aggregates and operators that reference those array function signatures must be dropped before upgrading, and recreated once the upgrade completes.

    Original release occurrence · 14.0/migration/001

  • Remove deprecated containment operators @ and ~ for built-in geometric data types and contrib modules cube, hstore, intarray, and seg Compatibility Migration

    Remove deprecated containment operators @ and ~ for built-in geometric data types and contrib modules cube, hstore, intarray, and seg (Justin Pryzby) § §

    The more consistently named <@ and @> have been recommended for many years.

    Original release occurrence · 14.0/migration/002

  • Fix to_tsquery() and websearch_to_tsquery() to properly parse query text containing discarded tokens Compatibility Migration

    Fix to_tsquery() and websearch_to_tsquery() to properly parse query text containing discarded tokens (Alexander Korotkov) §

    Certain discarded tokens, like underscore, caused the output of these functions to produce incorrect tsquery output, e.g., both websearch_to_tsquery('"pg_class pg"') and to_tsquery('pg_class <-> pg') used to output ( 'pg' & 'class' ) <-> 'pg', but now both output 'pg' <-> 'class' <-> 'pg'.

    Original release occurrence · 14.0/migration/003

  • Fix websearch_to_tsquery() to properly parse multiple adjacent discarded tokens in quotes Compatibility Migration

    Fix websearch_to_tsquery() to properly parse multiple adjacent discarded tokens in quotes (Alexander Korotkov) §

    Previously, quoted text that contained multiple adjacent discarded tokens was treated as multiple tokens, causing incorrect tsquery output, e.g., websearch_to_tsquery('"aaa: bbb"') used to output 'aaa' <2> 'bbb', but now outputs 'aaa' <-> 'bbb'.

    Original release occurrence · 14.0/migration/004

  • Change EXTRACT() to return type numeric instead of float8 Compatibility Migration

    Change EXTRACT() to return type numeric instead of float8 (Peter Eisentraut) §

    This avoids loss-of-precision issues in some usages. The old behavior can still be obtained by using the old underlying function date_part().

    Also, EXTRACT(date) now throws an error for units that are not part of the date data type.

    Original release occurrence · 14.0/migration/005

  • Change var_samp() and stddev_samp() with numeric parameters to return NULL when the input is a single NaN value Compatibility Migration

    Change var_samp() and stddev_samp() with numeric parameters to return NULL when the input is a single NaN value (Tom Lane) §

    Previously NaN was returned.

    Original release occurrence · 14.0/migration/006

  • Return false for has_column_privilege() checks on non-existent or dropped columns when using attribute numbers Compatibility Migration

    Return false for has_column_privilege() checks on non-existent or dropped columns when using attribute numbers (Joe Conway) §

    Previously such attribute numbers returned an invalid-column error.

    Original release occurrence · 14.0/migration/007

  • Fix handling of infinite window function ranges Compatibility Migration

    Fix handling of infinite window function ranges (Tom Lane) §

    Previously window frame clauses like 'inf' PRECEDING AND 'inf' FOLLOWING returned incorrect results.

    Original release occurrence · 14.0/migration/008

  • Remove factorial operators ! and !!, as well as function numeric_fac() Compatibility Migration

    Remove factorial operators ! and !!, as well as function numeric_fac() (Mark Dilger) §

    The factorial() function is still supported.

    Original release occurrence · 14.0/migration/009

  • Disallow factorial() of negative numbers Compatibility Migration

    Disallow factorial() of negative numbers (Peter Eisentraut) §

    Previously such cases returned 1.

    Original release occurrence · 14.0/migration/010

  • Remove support for postfix (right-unary) operators Compatibility Migration

    Remove support for postfix (right-unary) operators (Mark Dilger) §

    pg_dump and pg_upgrade will warn if postfix operators are being dumped.

    Original release occurrence · 14.0/migration/011

  • Allow \D and \W shorthands to match newlines in regular expression newline-sensitive mode Compatibility Migration

    Allow \D and \W shorthands to match newlines in regular expression newline-sensitive mode (Tom Lane) §

    Previously they did not match newlines in this mode, but that disagrees with the behavior of other common regular expression engines. [^[:digit:]] or [^[:word:]] can be used to get the old behavior.

    Original release occurrence · 14.0/migration/012

  • Disregard constraints when matching regular expression back-references Compatibility Migration

    Disregard constraints when matching regular expression back-references (Tom Lane) §

    For example, in (^\d+).*\1, the ^ constraint should be applied at the start of the string, but not when matching \1.

    Original release occurrence · 14.0/migration/013

  • Disallow \w as a range start or end in regular expression character classes Compatibility Migration

    Disallow \w as a range start or end in regular expression character classes (Tom Lane) §

    This previously was allowed but produced unexpected results.

    Original release occurrence · 14.0/migration/014

  • Require custom server parameter names to use only characters that are valid in unquoted SQL identifiers Compatibility Migration

    Require custom server parameter names to use only characters that are valid in unquoted SQL identifiers (Tom Lane) § §

    Original release occurrence · 14.0/migration/015

  • Change the default of the password_encryption server parameter to scram-sha-256 Compatibility Migration

    Change the default of the password_encryption server parameter to scram-sha-256 (Peter Eisentraut) §

    Previously it was md5. All new passwords will be stored as SHA256 unless this server setting is changed or the password is specified in MD5 format. Also, the legacy (and undocumented) Boolean-like values which were previously synonyms for md5 are no longer accepted.

    Original release occurrence · 14.0/migration/016

  • Remove server parameter vacuum_cleanup_index_scale_factor Compatibility Migration

    Remove server parameter vacuum_cleanup_index_scale_factor (Peter Geoghegan) § §

    This setting was ignored starting in PostgreSQL version 13.3.

    Original release occurrence · 14.0/migration/017

  • Remove server parameter operator_precedence_warning Compatibility Migration

    Remove server parameter operator_precedence_warning (Tom Lane) §

    This setting was used for warning applications about PostgreSQL 9.5 changes.

    Original release occurrence · 14.0/migration/018

  • Overhaul the specification of clientcert in pg_hba.conf Compatibility Migration

    Overhaul the specification of clientcert in pg_hba.conf (Kyotaro Horiguchi) §

    Values 1/0/no-verify are no longer supported; only the strings verify-ca and verify-full can be used. Also, disallow verify-ca if cert authentication is enabled since cert requires verify-full checking.

    Original release occurrence · 14.0/migration/019

  • Remove support for SSL compression Compatibility Migration

    Remove support for SSL compression (Daniel Gustafsson, Michael Paquier) § §

    This was already disabled by default in previous PostgreSQL releases, and most modern OpenSSL and TLS versions no longer support it.

    Original release occurrence · 14.0/migration/020

  • Remove server and libpq support for the version 2 wire protocol Compatibility Migration

    Remove server and libpq support for the version 2 wire protocol (Heikki Linnakangas) §

    This was last used as the default in PostgreSQL 7.3 (released in 2002).

    Original release occurrence · 14.0/migration/021

  • Disallow single-quoting of the language name in the CREATE/DROP LANGUAGE command Compatibility Migration

    Disallow single-quoting of the language name in the CREATE/DROP LANGUAGE command (Peter Eisentraut) §

    Original release occurrence · 14.0/migration/022

  • Remove the composite types that were formerly created for sequences and toast tables Compatibility Migration

    Remove the composite types that were formerly created for sequences and toast tables (Tom Lane) §

    Original release occurrence · 14.0/migration/023

  • Process doubled quote marks in ecpg SQL command strings correctly Compatibility Migration

    Process doubled quote marks in ecpg SQL command strings correctly (Tom Lane) § §

    Previously 'abc''def' was passed to the server as 'abc'def', and "abc""def" was passed as "abc"def", causing syntax errors.

    Original release occurrence · 14.0/migration/024

  • Prevent the containment operators (<@ and @>) for intarray from using GiST indexes Compatibility Migration

    Prevent the containment operators (<@ and @>) for intarray from using GiST indexes (Tom Lane) §

    Previously a full GiST index scan was required, so just avoid that and scan the heap, which is faster. Indexes created for this purpose should be removed.

    Original release occurrence · 14.0/migration/025

  • Remove contrib program pg_standby Compatibility Migration

    Remove contrib program pg_standby (Justin Pryzby) §

    Original release occurrence · 14.0/migration/026

  • Prevent tablefunc's function normal_rand() from accepting negative values Compatibility Migration

    Prevent tablefunc's function normal_rand() from accepting negative values (Ashutosh Bapat) §

    Negative values produced undesirable results.

    Original release occurrence · 14.0/migration/027

  • Add predefined roles pg_read_all_data and pg_write_all_data Features

    Add predefined roles pg_read_all_data and pg_write_all_data (Stephen Frost) §

    These non-login roles can be used to give read or write permission to all tables, views, and sequences.

    Original release occurrence · 14.0/changes/001

  • Add predefined role pg_database_owner that contains only the current database's owner Features

    Add predefined role pg_database_owner that contains only the current database's owner (Noah Misch) §

    This is especially useful in template databases.

    Original release occurrence · 14.0/changes/002

  • Remove temporary files after backend crashes Features

    Remove temporary files after backend crashes (Euler Taveira) §

    Previously, such files were retained for debugging purposes. If necessary, deletion can be disabled with the new server parameter remove_temp_files_after_crash.

    Original release occurrence · 14.0/changes/003

  • Allow long-running queries to be canceled if the client disconnects Features

    Allow long-running queries to be canceled if the client disconnects (Sergey Cherkashin, Thomas Munro) §

    The server parameter client_connection_check_interval allows control over whether loss of connection is checked for intra-query. (This is supported on Linux and a few other operating systems.)

    Original release occurrence · 14.0/changes/004

  • Add an optional timeout parameter to pg_terminate_backend() Features

    Add an optional timeout parameter to pg_terminate_backend() (Magnus Hagander) §

    Original release occurrence · 14.0/changes/005

  • Allow wide tuples to be always added to almost-empty heap pages Features

    Allow wide tuples to be always added to almost-empty heap pages (John Naylor, Floris van Nee) §

    Previously tuples whose insertion would have exceeded the page's fill factor were instead added to new pages.

    Original release occurrence · 14.0/changes/006

  • Add Server Name Indication (SNI) in SSL connection packets Features

    Add Server Name Indication (SNI) in SSL connection packets (Peter Eisentraut) §

    This can be disabled by turning off client connection option sslsni.

    Original release occurrence · 14.0/changes/007

  • Allow vacuum to skip index vacuuming when the number of removable index entries is insignificant Features

    Allow vacuum to skip index vacuuming when the number of removable index entries is insignificant (Masahiko Sawada, Peter Geoghegan) § §

    The vacuum parameter INDEX_CLEANUP has a new default of auto that enables this optimization.

    Original release occurrence · 14.0/changes/008

  • Allow vacuum to more eagerly add deleted btree pages to the free space map Features

    Allow vacuum to more eagerly add deleted btree pages to the free space map (Peter Geoghegan) §

    Previously vacuum could only add pages to the free space map that were marked as deleted by previous vacuums.

    Original release occurrence · 14.0/changes/009

  • Allow vacuum to reclaim space used by unused trailing heap line pointers Features

    Allow vacuum to reclaim space used by unused trailing heap line pointers (Matthias van de Meent, Peter Geoghegan) §

    Original release occurrence · 14.0/changes/010

  • Allow vacuum to be more aggressive in removing dead rows during minimal-locking index operations Features

    Allow vacuum to be more aggressive in removing dead rows during minimal-locking index operations (Álvaro Herrera) § § §

    Specifically, CREATE INDEX CONCURRENTLY and REINDEX CONCURRENTLY no longer limit the dead row removal of other relations.

    Original release occurrence · 14.0/changes/011

  • Speed up vacuuming of databases with many relations Performance

    Speed up vacuuming of databases with many relations (Tatsuhito Kasahara) §

    Original release occurrence · 14.0/changes/012

  • Reduce the default value of vacuum_cost_page_miss to better reflect current hardware capabilities Features

    Reduce the default value of vacuum_cost_page_miss to better reflect current hardware capabilities (Peter Geoghegan) §

    Original release occurrence · 14.0/changes/013

  • Add ability to skip vacuuming of TOAST tables Features

    Add ability to skip vacuuming of TOAST tables (Nathan Bossart) §

    VACUUM now has a PROCESS_TOAST option which can be set to false to disable TOAST processing, and vacuumdb has a --no-process-toast option.

    Original release occurrence · 14.0/changes/014

  • Have COPY FREEZE appropriately update page visibility bits Features

    Have COPY FREEZE appropriately update page visibility bits (Anastasia Lubennikova, Pavan Deolasee, Jeff Janes) §

    Original release occurrence · 14.0/changes/015

  • Cause vacuum operations to be more aggressive if the table is near xid or multixact wraparound Features

    Cause vacuum operations to be more aggressive if the table is near xid or multixact wraparound (Masahiko Sawada, Peter Geoghegan) §

    This is controlled by vacuum_failsafe_age and vacuum_multixact_failsafe_age.

    Original release occurrence · 14.0/changes/016

  • Increase warning time and hard limit before transaction id and multi-transaction wraparound Features

    Increase warning time and hard limit before transaction id and multi-transaction wraparound (Noah Misch) §

    This should reduce the possibility of failures that occur without having issued warnings about wraparound.

    Original release occurrence · 14.0/changes/017

  • Add per-index information to autovacuum logging output Features

    Add per-index information to autovacuum logging output (Masahiko Sawada) §

    Original release occurrence · 14.0/changes/018

  • Improve the performance of updates and deletes on partitioned tables with many partitions Performance

    Improve the performance of updates and deletes on partitioned tables with many partitions (Amit Langote, Tom Lane) § § §

    This change greatly reduces the planner's overhead for such cases, and also allows updates/deletes on partitioned tables to use execution-time partition pruning.

    Original release occurrence · 14.0/changes/019

  • Allow partitions to be detached in a non-blocking manner Features

    Allow partitions to be detached in a non-blocking manner (Álvaro Herrera) §

    The syntax is ALTER TABLE ... DETACH PARTITION ... CONCURRENTLY, and FINALIZE.

    Original release occurrence · 14.0/changes/020

  • Ignore COLLATE clauses in partition boundary values Features

    Ignore COLLATE clauses in partition boundary values (Tom Lane) §

    Previously any such clause had to match the collation of the partition key; but it's more consistent to consider that it's automatically coerced to the collation of the partition key.

    Original release occurrence · 14.0/changes/021

  • Allow btree index additions to remove expired index entries to prevent page splits Features

    Allow btree index additions to remove expired index entries to prevent page splits (Peter Geoghegan) § §

    This is particularly helpful for reducing index bloat on tables whose indexed columns are frequently updated.

    Original release occurrence · 14.0/changes/022

  • Allow BRIN indexes to record multiple min/max values per range Features

    Allow BRIN indexes to record multiple min/max values per range (Tomas Vondra) §

    This is useful if there are groups of values in each page range.

    Original release occurrence · 14.0/changes/023

  • Allow BRIN indexes to use bloom filters Features

    Allow BRIN indexes to use bloom filters (Tomas Vondra) §

    This allows BRIN indexes to be used effectively with data that is not well-localized in the heap.

    Original release occurrence · 14.0/changes/024

  • Allow some GiST indexes to be built by presorting the data Features

    Allow some GiST indexes to be built by presorting the data (Andrey Borodin) §

    Presorting happens automatically and allows for faster index creation and smaller indexes.

    Original release occurrence · 14.0/changes/025

  • Allow SP-GiST indexes to contain INCLUDE'd columns Features

    Allow SP-GiST indexes to contain INCLUDE'd columns (Pavel Borisov) §

    Original release occurrence · 14.0/changes/026

  • Allow hash lookup for IN clauses with many constants Features

    Allow hash lookup for IN clauses with many constants (James Coleman, David Rowley) §

    Previously the code always sequentially scanned the list of values.

    Original release occurrence · 14.0/changes/027

  • Increase the number of places extended statistics can be used for OR clause estimation Features

    Increase the number of places extended statistics can be used for OR clause estimation (Tomas Vondra, Dean Rasheed) § § §

    Original release occurrence · 14.0/changes/028

  • Allow extended statistics on expressions Features

    Allow extended statistics on expressions (Tomas Vondra) §

    This allows statistics on a group of expressions and columns, rather than only columns like previously. System view pg_stats_ext_exprs reports such statistics.

    Original release occurrence · 14.0/changes/029

  • Allow efficient heap scanning of a range of TIDs Features

    Allow efficient heap scanning of a range of TIDs (Edmund Horner, David Rowley) §

    Previously a sequential scan was required for non-equality TID specifications.

    Original release occurrence · 14.0/changes/030

  • Fix EXPLAIN CREATE TABLE AS and EXPLAIN CREATE MATERIALIZED VIEW to honor IF NOT EXISTS Bug fixes

    Fix EXPLAIN CREATE TABLE AS and EXPLAIN CREATE MATERIALIZED VIEW to honor IF NOT EXISTS (Bharath Rupireddy) §

    Previously, if the object already existed, EXPLAIN would fail.

    Original release occurrence · 14.0/changes/031

  • Improve the speed of computing MVCC visibility snapshots on systems with many CPUs and high session counts Performance

    Improve the speed of computing MVCC visibility snapshots on systems with many CPUs and high session counts (Andres Freund) § § § § § §

    This also improves performance when there are many idle sessions.

    Original release occurrence · 14.0/changes/032

  • Add executor method to memoize results from the inner side of a nested-loop join Performance

    Add executor method to memoize results from the inner side of a nested-loop join (David Rowley) §

    This is useful if only a small percentage of rows is checked on the inner side. It can be disabled via server parameter enable_memoize.

    Original release occurrence · 14.0/changes/033

  • Allow window functions to perform incremental sorts Performance

    Allow window functions to perform incremental sorts (David Rowley) §

    Original release occurrence · 14.0/changes/034

  • Improve the I/O performance of parallel sequential scans Performance

    Improve the I/O performance of parallel sequential scans (Thomas Munro, David Rowley) §

    This was done by allocating blocks in groups to parallel workers.

    Original release occurrence · 14.0/changes/035

  • Allow a query referencing multiple foreign tables to perform foreign table scans in parallel Performance

    Allow a query referencing multiple foreign tables to perform foreign table scans in parallel (Robert Haas, Kyotaro Horiguchi, Thomas Munro, Etsuro Fujita) §

    postgres_fdw supports this type of scan if async_capable is set.

    Original release occurrence · 14.0/changes/036

  • Allow analyze to do page prefetching Performance

    Allow analyze to do page prefetching (Stephen Frost) §

    This is controlled by maintenance_io_concurrency.

    Original release occurrence · 14.0/changes/037

  • Improve performance of regular expression searches Performance

    Improve performance of regular expression searches (Tom Lane) § § § § § § § § § § §

    Original release occurrence · 14.0/changes/038

  • Dramatically improve Unicode normalization performance Performance

    Dramatically improve Unicode normalization performance (John Naylor) § §

    This speeds normalize() and IS NORMALIZED.

    Original release occurrence · 14.0/changes/039

  • Add ability to use LZ4 compression on TOAST data Performance

    Add ability to use LZ4 compression on TOAST data (Dilip Kumar) §

    This can be set at the column level, or set as a default via server parameter default_toast_compression. The server must be compiled with --with-lz4 to support this feature. The default setting is still pglz.

    Original release occurrence · 14.0/changes/040

  • If server parameter compute_query_id is enabled, display the query id in pg_stat_activity, EXPLAIN VERBOSE, csvlog, and optionally in log_line_prefix Features

    If server parameter compute_query_id is enabled, display the query id in pg_stat_activity, EXPLAIN VERBOSE, csvlog, and optionally in log_line_prefix (Julien Rouhaud) § § § § §

    A query id computed by an extension will also be displayed.

    Original release occurrence · 14.0/changes/041

  • Improve logging of auto-vacuum and auto-analyze Features

    Improve logging of auto-vacuum and auto-analyze (Stephen Frost, Jakub Wartak) §

    This reports I/O timings for auto-vacuum and auto-analyze if track_io_timing is enabled. Also, report buffer read and dirty rates for auto-analyze.

    Original release occurrence · 14.0/changes/042

  • Add information about the original user name supplied by the client to the output of log_connections Features

    Add information about the original user name supplied by the client to the output of log_connections (Jacob Champion) §

    Original release occurrence · 14.0/changes/043

  • Add system view pg_stat_progress_copy to report COPY progress Features

    Add system view pg_stat_progress_copy to report COPY progress (Josef Šimánek, Matthias van de Meent) § §

    Original release occurrence · 14.0/changes/044

  • Add system view pg_stat_wal to report WAL activity Features

    Add system view pg_stat_wal to report WAL activity (Masahiro Ikeda) § § §

    Original release occurrence · 14.0/changes/045

  • Add system view pg_stat_replication_slots to report replication slot activity Features

    Add system view pg_stat_replication_slots to report replication slot activity (Masahiko Sawada, Amit Kapila, Vignesh C) § § § §

    The function pg_stat_reset_replication_slot() resets slot statistics.

    Original release occurrence · 14.0/changes/046

  • Add system view pg_backend_memory_contexts to report session memory usage Features

    Add system view pg_backend_memory_contexts to report session memory usage (Atsushi Torikoshi, Fujii Masao) § §

    Original release occurrence · 14.0/changes/047

  • Add function pg_log_backend_memory_contexts() to output the memory contexts of arbitrary backends Features

    Add function pg_log_backend_memory_contexts() to output the memory contexts of arbitrary backends (Atsushi Torikoshi) §

    Original release occurrence · 14.0/changes/048

  • Add session statistics to the pg_stat_database system view Features

    Add session statistics to the pg_stat_database system view (Laurenz Albe) §

    Original release occurrence · 14.0/changes/049

  • Add columns to pg_prepared_statements to report generic and custom plan counts Features

    Add columns to pg_prepared_statements to report generic and custom plan counts (Atsushi Torikoshi, Kyotaro Horiguchi) §

    Original release occurrence · 14.0/changes/050

  • Add lock wait start time to pg_locks Features

    Add lock wait start time to pg_locks (Atsushi Torikoshi) §

    Original release occurrence · 14.0/changes/051

  • Make the archiver process visible in pg_stat_activity Features

    Make the archiver process visible in pg_stat_activity (Kyotaro Horiguchi) §

    Original release occurrence · 14.0/changes/052

  • Add wait event WalReceiverExit to report WAL receiver exit wait time Features

    Add wait event WalReceiverExit to report WAL receiver exit wait time (Fujii Masao) §

    Original release occurrence · 14.0/changes/053

  • Implement information schema view routine_column_usage to track columns referenced by function and procedure default expressions Features

    Implement information schema view routine_column_usage to track columns referenced by function and procedure default expressions (Peter Eisentraut) §

    Original release occurrence · 14.0/changes/054

  • Allow an SSL certificate's distinguished name (DN) to be matched for client certificate authentication Features

    Allow an SSL certificate's distinguished name (DN) to be matched for client certificate authentication (Andrew Dunstan) §

    The new pg_hba.conf option clientname=DN allows comparison with certificate attributes beyond the CN and can be combined with ident maps.

    Original release occurrence · 14.0/changes/055

  • Allow pg_hba.conf and pg_ident.conf records to span multiple lines Features

    Allow pg_hba.conf and pg_ident.conf records to span multiple lines (Fabien Coelho) §

    A backslash at the end of a line allows record contents to be continued on the next line.

    Original release occurrence · 14.0/changes/056

  • Allow the specification of a certificate revocation list (CRL) directory Features

    Allow the specification of a certificate revocation list (CRL) directory (Kyotaro Horiguchi) §

    This is controlled by server parameter ssl_crl_dir and libpq connection option sslcrldir. Previously only single CRL files could be specified.

    Original release occurrence · 14.0/changes/057

  • Allow passwords of an arbitrary length Features

    Allow passwords of an arbitrary length (Tom Lane, Nathan Bossart) §

    Original release occurrence · 14.0/changes/058

  • Add server parameter idle_session_timeout to close idle sessions Features

    Add server parameter idle_session_timeout to close idle sessions (Li Japin) §

    This is similar to idle_in_transaction_session_timeout.

    Original release occurrence · 14.0/changes/059

  • Change checkpoint_completion_target default to 0.9 Features

    Change checkpoint_completion_target default to 0.9 (Stephen Frost) §

    The previous default was 0.5.

    Original release occurrence · 14.0/changes/060

  • Allow %P in log_line_prefix to report the parallel group leader's PID for a parallel worker Features

    Allow %P in log_line_prefix to report the parallel group leader's PID for a parallel worker (Justin Pryzby) §

    Original release occurrence · 14.0/changes/061

  • Allow unix_socket_directories to specify paths as individual, comma-separated quoted strings Features

    Allow unix_socket_directories to specify paths as individual, comma-separated quoted strings (Ian Lawrence Barwick) §

    Previously all the paths had to be in a single quoted string.

    Original release occurrence · 14.0/changes/062

  • Allow startup allocation of dynamic shared memory Features

    Allow startup allocation of dynamic shared memory (Thomas Munro) §

    This is controlled by min_dynamic_shared_memory. This allows more use of huge pages.

    Original release occurrence · 14.0/changes/063

  • Add server parameter huge_page_size to control the size of huge pages used on Linux Features

    Add server parameter huge_page_size to control the size of huge pages used on Linux (Odin Ugedal) §

    Original release occurrence · 14.0/changes/064

  • Allow standby servers to be rewound via pg_rewind Features

    Allow standby servers to be rewound via pg_rewind (Heikki Linnakangas) §

    Original release occurrence · 14.0/changes/065

  • Allow the restore_command setting to be changed during a server reload Features

    Allow the restore_command setting to be changed during a server reload (Sergei Kornilov) §

    You can also set restore_command to an empty string and reload to force recovery to only read from the pg_wal directory.

    Original release occurrence · 14.0/changes/066

  • Add server parameter log_recovery_conflict_waits to report long recovery conflict wait times Features

    Add server parameter log_recovery_conflict_waits to report long recovery conflict wait times (Bertrand Drouvot, Masahiko Sawada) § §

    Original release occurrence · 14.0/changes/067

  • Pause recovery on a hot standby server if the primary changes its parameters in a way that prevents replay on the standby Features

    Pause recovery on a hot standby server if the primary changes its parameters in a way that prevents replay on the standby (Peter Eisentraut) §

    Previously the standby would shut down immediately.

    Original release occurrence · 14.0/changes/068

  • Add function pg_get_wal_replay_pause_state() to report the recovery state Features

    Add function pg_get_wal_replay_pause_state() to report the recovery state (Dilip Kumar) §

    It gives more detailed information than pg_is_wal_replay_paused(), which still exists.

    Original release occurrence · 14.0/changes/069

  • Add new read-only server parameter in_hot_standby Features

    Add new read-only server parameter in_hot_standby (Haribabu Kommi, Greg Nancarrow, Tom Lane) §

    This allows clients to easily detect whether they are connected to a hot standby server.

    Original release occurrence · 14.0/changes/070

  • Speed truncation of small tables during recovery on clusters with a large number of shared buffers Features

    Speed truncation of small tables during recovery on clusters with a large number of shared buffers (Kirk Jamison) §

    Original release occurrence · 14.0/changes/071

  • Allow file system sync at the start of crash recovery on Linux Features

    Allow file system sync at the start of crash recovery on Linux (Thomas Munro) §

    By default, PostgreSQL opens and fsyncs each data file in the database cluster at the start of crash recovery. A new setting, recovery_init_sync_method=syncfs, instead syncs each filesystem used by the cluster. This allows for faster recovery on systems with many database files.

    Original release occurrence · 14.0/changes/072

  • Add function pg_xact_commit_timestamp_origin() to return the commit timestamp and replication origin of the specified transaction Features

    Add function pg_xact_commit_timestamp_origin() to return the commit timestamp and replication origin of the specified transaction (Movead Li) §

    Original release occurrence · 14.0/changes/073

  • Add the replication origin to the record returned by pg_last_committed_xact() Features

    Add the replication origin to the record returned by pg_last_committed_xact() (Movead Li) §

    Original release occurrence · 14.0/changes/074

  • Allow replication origin functions to be controlled using standard function permission controls Features

    Allow replication origin functions to be controlled using standard function permission controls (Martín Marqués) §

    Previously these functions could only be executed by superusers, and this is still the default.

    Original release occurrence · 14.0/changes/075

  • Allow logical replication to stream long in-progress transactions to subscribers Features

    Allow logical replication to stream long in-progress transactions to subscribers (Dilip Kumar, Amit Kapila, Ajin Cherian, Tomas Vondra, Nikhil Sontakke, Stas Kelvich) § § § §

    Previously transactions that exceeded logical_decoding_work_mem were written to disk until the transaction completed.

    Original release occurrence · 14.0/changes/076

  • Enhance the logical replication API to allow streaming large in-progress transactions Features

    Enhance the logical replication API to allow streaming large in-progress transactions (Tomas Vondra, Dilip Kumar, Amit Kapila) §

    The output functions begin with stream. test_decoding also supports these.

    Original release occurrence · 14.0/changes/077

  • Allow multiple transactions during table sync in logical replication Features

    Allow multiple transactions during table sync in logical replication (Peter Smith, Amit Kapila, Takamichi Osumi) §

    Original release occurrence · 14.0/changes/078

  • Immediately WAL-log subtransaction and top-level XID association Features

    Immediately WAL-log subtransaction and top-level XID association (Tomas Vondra, Dilip Kumar, Amit Kapila) §

    This is useful for logical decoding.

    Original release occurrence · 14.0/changes/079

  • Enhance logical decoding APIs to handle two-phase commits Features

    Enhance logical decoding APIs to handle two-phase commits (Ajin Cherian, Amit Kapila, Nikhil Sontakke, Stas Kelvich) § § §

    This is controlled via pg_create_logical_replication_slot().

    Original release occurrence · 14.0/changes/080

  • Add cache invalidation messages to the WAL during command completion when using logical replication Features

    Add cache invalidation messages to the WAL during command completion when using logical replication (Dilip Kumar, Tomas Vondra, Amit Kapila) §

    This allows logical streaming of in-progress transactions. When logical replication is disabled, invalidation messages are generated only at transaction completion.

    Original release occurrence · 14.0/changes/081

  • Allow logical decoding to more efficiently process cache invalidation messages Features

    Allow logical decoding to more efficiently process cache invalidation messages (Dilip Kumar) §

    This allows logical decoding to work efficiently in presence of a large amount of DDL.

    Original release occurrence · 14.0/changes/082

  • Allow control over whether logical decoding messages are sent to the replication stream Features

    Allow control over whether logical decoding messages are sent to the replication stream (David Pirotte, Euler Taveira) §

    Original release occurrence · 14.0/changes/083

  • Allow logical replication subscriptions to use binary transfer mode Features

    Allow logical replication subscriptions to use binary transfer mode (Dave Cramer) §

    This is faster than text mode, but slightly less robust.

    Original release occurrence · 14.0/changes/084

  • Allow logical decoding to be filtered by xid Features

    Allow logical decoding to be filtered by xid (Markus Wanner) §

    Original release occurrence · 14.0/changes/085

  • Reduce the number of keywords that can't be used as column labels without AS Features

    Reduce the number of keywords that can't be used as column labels without AS (Mark Dilger) §

    There are now 90% fewer restricted keywords.

    Original release occurrence · 14.0/changes/086

  • Allow an alias to be specified for JOIN's USING clause Features

    Allow an alias to be specified for JOIN's USING clause (Peter Eisentraut) §

    The alias is created by writing AS after the USING clause. It can be used as a table qualification for the merged USING columns.

    Original release occurrence · 14.0/changes/087

  • Allow DISTINCT to be added to GROUP BY to remove duplicate GROUPING SET combinations Features

    Allow DISTINCT to be added to GROUP BY to remove duplicate GROUPING SET combinations (Vik Fearing) §

    For example, GROUP BY CUBE (a,b), CUBE (b,c) will generate duplicate grouping combinations without DISTINCT.

    Original release occurrence · 14.0/changes/088

  • Properly handle DEFAULT entries in multi-row VALUES lists in INSERT Features

    Properly handle DEFAULT entries in multi-row VALUES lists in INSERT (Dean Rasheed) §

    Such cases used to throw an error.

    Original release occurrence · 14.0/changes/089

  • Add SQL-standard SEARCH and CYCLE clauses for common table expressions Features

    Add SQL-standard SEARCH and CYCLE clauses for common table expressions (Peter Eisentraut) § §

    The same results could be accomplished using existing syntax, but much less conveniently.

    Original release occurrence · 14.0/changes/090

  • Allow column names in the WHERE clause of ON CONFLICT to be table-qualified Features

    Allow column names in the WHERE clause of ON CONFLICT to be table-qualified (Tom Lane) §

    Only the target table can be referenced, however.

    Original release occurrence · 14.0/changes/091

  • Allow REFRESH MATERIALIZED VIEW to use parallelism Features

    Allow REFRESH MATERIALIZED VIEW to use parallelism (Bharath Rupireddy) §

    Original release occurrence · 14.0/changes/092

  • Allow REINDEX to change the tablespace of the new index Features

    Allow REINDEX to change the tablespace of the new index (Alexey Kondratov, Michael Paquier, Justin Pryzby) § §

    This is done by specifying a TABLESPACE clause. A --tablespace option was also added to reindexdb to control this.

    Original release occurrence · 14.0/changes/093

  • Allow REINDEX to process all child tables or indexes of a partitioned relation Features

    Allow REINDEX to process all child tables or indexes of a partitioned relation (Justin Pryzby, Michael Paquier) §

    Original release occurrence · 14.0/changes/094

  • Allow index commands using CONCURRENTLY to avoid waiting for the completion of other operations using CONCURRENTLY Features

    Allow index commands using CONCURRENTLY to avoid waiting for the completion of other operations using CONCURRENTLY (Álvaro Herrera) § § §

    Original release occurrence · 14.0/changes/095

  • Improve the performance of COPY FROM in binary mode Performance

    Improve the performance of COPY FROM in binary mode (Bharath Rupireddy, Amit Langote) §

    Original release occurrence · 14.0/changes/096

  • Preserve SQL standard syntax for SQL-defined functions in view definitions Features

    Preserve SQL standard syntax for SQL-defined functions in view definitions (Tom Lane) §

    Previously, calls to SQL-standard functions such as EXTRACT() were shown in plain function-call syntax. The original syntax is now preserved when displaying a view or rule.

    Original release occurrence · 14.0/changes/097

  • Add the SQL-standard clause GRANTED BY to GRANT and REVOKE Features

    Add the SQL-standard clause GRANTED BY to GRANT and REVOKE (Peter Eisentraut) §

    Original release occurrence · 14.0/changes/098

  • Add OR REPLACE option for CREATE TRIGGER Features

    Add OR REPLACE option for CREATE TRIGGER (Takamichi Osumi) §

    This allows pre-existing triggers to be conditionally replaced.

    Original release occurrence · 14.0/changes/099

  • Allow TRUNCATE to operate on foreign tables Features

    Allow TRUNCATE to operate on foreign tables (Kazutaka Onishi, Kohei KaiGai) §

    The postgres_fdw module also now supports this.

    Original release occurrence · 14.0/changes/100

  • Allow publications to be more easily added to and removed from a subscription Features

    Allow publications to be more easily added to and removed from a subscription (Japin Li) §

    The new syntax is ALTER SUBSCRIPTION ... ADD/DROP PUBLICATION. This avoids having to specify all publications to add/remove entries.

    Original release occurrence · 14.0/changes/101

  • Add primary keys, unique constraints, and foreign keys to system catalogs Features

    Add primary keys, unique constraints, and foreign keys to system catalogs (Peter Eisentraut) § §

    These changes help GUI tools analyze the system catalogs. The existing unique indexes of catalogs now have associated UNIQUE or PRIMARY KEY constraints. Foreign key relationships are not actually stored or implemented as constraints, but can be obtained for display from the function pg_get_catalog_foreign_keys().

    Original release occurrence · 14.0/changes/102

  • Allow CURRENT_ROLE every place CURRENT_USER is accepted Features

    Allow CURRENT_ROLE every place CURRENT_USER is accepted (Peter Eisentraut) §

    Original release occurrence · 14.0/changes/103

  • Allow extensions and built-in data types to implement subscripting Features

    Allow extensions and built-in data types to implement subscripting (Dmitry Dolgov) §

    Previously subscript handling was hard-coded into the server, so that subscripting could only be applied to array types. This change allows subscript notation to be used to extract or assign portions of a value of any type for which the concept makes sense.

    Original release occurrence · 14.0/changes/104

  • Allow subscripting of JSONB Features

    Allow subscripting of JSONB (Dmitry Dolgov) § § §

    JSONB subscripting can be used to extract and assign to portions of JSONB documents.

    Original release occurrence · 14.0/changes/105

  • Add support for multirange data types Features

    Add support for multirange data types (Paul Jungwirth, Alexander Korotkov) § § § §

    These are like range data types, but they allow the specification of multiple, ordered, non-overlapping ranges. An associated multirange type is automatically created for every range type.

    Original release occurrence · 14.0/changes/106

  • Add support for the stemming of languages Armenian, Basque, Catalan, Hindi, Serbian, and Yiddish Features

    Add support for the stemming of languages Armenian, Basque, Catalan, Hindi, Serbian, and Yiddish (Peter Eisentraut) § § §

    Original release occurrence · 14.0/changes/107

  • Allow tsearch data files to have unlimited line lengths Features

    Allow tsearch data files to have unlimited line lengths (Tom Lane) §

    The previous limit was 4K bytes. Also remove function t_readline().

    Original release occurrence · 14.0/changes/108

  • Add support for Infinity and -Infinity values in the numeric data type Features

    Add support for Infinity and -Infinity values in the numeric data type (Tom Lane) §

    Floating-point data types already supported these.

    Original release occurrence · 14.0/changes/109

  • Add point operators <<| and |>> representing strictly above/below tests Features

    Add point operators <<| and |>> representing strictly above/below tests (Emre Hasegeli) §

    Previously these were called >^ and <^, but that naming is inconsistent with other geometric data types. The old names remain available, but may someday be removed.

    Original release occurrence · 14.0/changes/110

  • Add operators to add and subtract LSN and numeric (byte) values Features

    Add operators to add and subtract LSN and numeric (byte) values (Fujii Masao) §

    Original release occurrence · 14.0/changes/111

  • Allow binary data transfer to be more forgiving of array and record OID mismatches Features

    Allow binary data transfer to be more forgiving of array and record OID mismatches (Tom Lane) §

    Original release occurrence · 14.0/changes/112

  • Create composite array types for system catalogs Features

    Create composite array types for system catalogs (Wenjing Zeng) §

    User-defined relations have long had composite types associated with them, and also array types over those composite types. System catalogs now do as well. This change also fixes an inconsistency that creating a user-defined table in single-user mode would fail to create a composite array type.

    Original release occurrence · 14.0/changes/113

  • Allow SQL-language functions and procedures to use SQL-standard function bodies Features

    Allow SQL-language functions and procedures to use SQL-standard function bodies (Peter Eisentraut) §

    Previously only string-literal function bodies were supported. When writing a function or procedure in SQL-standard syntax, the body is parsed immediately and stored as a parse tree. This allows better tracking of function dependencies, and can have security benefits.

    Original release occurrence · 14.0/changes/114

  • Allow procedures to have OUT parameters Features

    Allow procedures to have OUT parameters (Peter Eisentraut) § §

    Original release occurrence · 14.0/changes/115

  • Allow some array functions to operate on a mix of compatible data types Features

    Allow some array functions to operate on a mix of compatible data types (Tom Lane) §

    The functions array_append(), array_prepend(), array_cat(), array_position(), array_positions(), array_remove(), array_replace(), and width_bucket() now take anycompatiblearray instead of anyarray arguments. This makes them less fussy about exact matches of argument types.

    Original release occurrence · 14.0/changes/116

  • Add SQL-standard trim_array() function Features

    Add SQL-standard trim_array() function (Vik Fearing) §

    This could already be done with array slices, but less easily.

    Original release occurrence · 14.0/changes/117

  • Add bytea equivalents of ltrim() and rtrim() Features

    Add bytea equivalents of ltrim() and rtrim() (Joel Jacobson) §

    Original release occurrence · 14.0/changes/118

  • Support negative indexes in split_part() Features

    Support negative indexes in split_part() (Nikhil Benesch) §

    Negative values start from the last field and count backward.

    Original release occurrence · 14.0/changes/119

  • Add string_to_table() function to split a string on delimiters Features

    Add string_to_table() function to split a string on delimiters (Pavel Stehule) §

    This is similar to the regexp_split_to_table() function.

    Original release occurrence · 14.0/changes/120

  • Add unistr() function to allow Unicode characters to be specified as backslash-hex escapes in strings Features

    Add unistr() function to allow Unicode characters to be specified as backslash-hex escapes in strings (Pavel Stehule) §

    This is similar to how Unicode can be specified in literal strings.

    Original release occurrence · 14.0/changes/121

  • Add bit_xor() XOR aggregate function Features

    Add bit_xor() XOR aggregate function (Alexey Bashtanov) §

    Original release occurrence · 14.0/changes/122

  • Add function bit_count() to return the number of bits set in a bit or byte string Features

    Add function bit_count() to return the number of bits set in a bit or byte string (David Fetter) §

    Original release occurrence · 14.0/changes/123

  • Add date_bin() function Features

    Add date_bin() function (John Naylor) § §

    This function “bins” input timestamps, grouping them into intervals of a uniform length aligned with a specified origin.

    Original release occurrence · 14.0/changes/124

  • Allow make_timestamp()/make_timestamptz() to accept negative years Features

    Allow make_timestamp()/make_timestamptz() to accept negative years (Peter Eisentraut) §

    Negative values are interpreted as BC years.

    Original release occurrence · 14.0/changes/125

  • Add newer regular expression substring() syntax Features

    Add newer regular expression substring() syntax (Peter Eisentraut) §

    The new SQL-standard syntax is SUBSTRING(text SIMILAR pattern ESCAPE escapechar). The previous standard syntax was SUBSTRING(text FROM pattern FOR escapechar), which is still accepted by PostgreSQL.

    Original release occurrence · 14.0/changes/126

  • Allow complemented character class escapes \D, \S, and \W within regular expression brackets Features

    Allow complemented character class escapes \D, \S, and \W within regular expression brackets (Tom Lane) §

    Original release occurrence · 14.0/changes/127

  • Add [[:word:]] as a regular expression character class, equivalent to \w Features

    Add [[:word:]] as a regular expression character class, equivalent to \w (Tom Lane) §

    Original release occurrence · 14.0/changes/128

  • Allow more flexible data types for default values of lead() and lag() window functions Features

    Allow more flexible data types for default values of lead() and lag() window functions (Vik Fearing) §

    Original release occurrence · 14.0/changes/129

  • Make non-zero floating-point values divided by infinity return zero Features

    Make non-zero floating-point values divided by infinity return zero (Kyotaro Horiguchi) §

    Previously such operations produced underflow errors.

    Original release occurrence · 14.0/changes/130

  • Make floating-point division of NaN by zero return NaN Features

    Make floating-point division of NaN by zero return NaN (Tom Lane) §

    Previously this returned an error.

    Original release occurrence · 14.0/changes/131

  • Cause exp() and power() for negative-infinity exponents to return zero Features

    Cause exp() and power() for negative-infinity exponents to return zero (Tom Lane) § § §

    Previously they often returned underflow errors.

    Original release occurrence · 14.0/changes/132

  • Improve the accuracy of geometric computations involving infinity Features

    Improve the accuracy of geometric computations involving infinity (Tom Lane) §

    Original release occurrence · 14.0/changes/133

  • Mark built-in type coercion functions as leakproof where possible Features

    Mark built-in type coercion functions as leakproof where possible (Tom Lane) §

    This allows more use of functions that require type conversion in security-sensitive situations.

    Original release occurrence · 14.0/changes/134

  • Change pg_describe_object(), pg_identify_object(), and pg_identify_object_as_address() to always report helpful error messages for non-existent objects Features

    Change pg_describe_object(), pg_identify_object(), and pg_identify_object_as_address() to always report helpful error messages for non-existent objects (Michael Paquier) §

    Original release occurrence · 14.0/changes/135

  • Improve PL/pgSQL's expression and assignment parsing Features

    Improve PL/pgSQL's expression and assignment parsing (Tom Lane) §

    This change allows assignment to array slices and nested record fields.

    Original release occurrence · 14.0/changes/136

  • Allow plpgsql's RETURN QUERY to execute its query using parallelism Features

    Allow plpgsql's RETURN QUERY to execute its query using parallelism (Tom Lane) §

    Original release occurrence · 14.0/changes/137

  • Improve performance of repeated CALLs within plpgsql procedures Performance

    Improve performance of repeated CALLs within plpgsql procedures (Pavel Stehule, Tom Lane) §

    Original release occurrence · 14.0/changes/138

  • Add pipeline mode to libpq Features

    Add pipeline mode to libpq (Craig Ringer, Matthieu Garrigues, Álvaro Herrera) §

    This allows multiple queries to be sent, only waiting for completion when a specific synchronization message is sent.

    Original release occurrence · 14.0/changes/139

  • Enhance libpq's target_session_attrs parameter options Features

    Enhance libpq's target_session_attrs parameter options (Haribabu Kommi, Greg Nancarrow, Vignesh C, Tom Lane) § §

    The new options are read-only, primary, standby, and prefer-standby.

    Original release occurrence · 14.0/changes/140

  • Improve the output format of libpq's PQtrace() Features

    Improve the output format of libpq's PQtrace() (Aya Iwata, Álvaro Herrera) §

    Original release occurrence · 14.0/changes/141

  • Allow an ECPG SQL identifier to be linked to a specific connection Features

    Allow an ECPG SQL identifier to be linked to a specific connection (Hayato Kuroda) §

    This is done via DECLARE ... STATEMENT.

    Original release occurrence · 14.0/changes/142

  • Allow vacuumdb to skip index cleanup and truncation Features

    Allow vacuumdb to skip index cleanup and truncation (Nathan Bossart) §

    The options are --no-index-cleanup and --no-truncate.

    Original release occurrence · 14.0/changes/143

  • Allow pg_dump to dump only certain extensions Features

    Allow pg_dump to dump only certain extensions (Guillaume Lelarge) §

    This is controlled by option --extension.

    Original release occurrence · 14.0/changes/144

  • Add pgbench permute() function to randomly shuffle values Features

    Add pgbench permute() function to randomly shuffle values (Fabien Coelho, Hironobu Suzuki, Dean Rasheed) §

    Original release occurrence · 14.0/changes/145

  • Include disconnection times in the reconnection overhead measured by pgbench with -C Features

    Include disconnection times in the reconnection overhead measured by pgbench with -C (Yugo Nagata) §

    Original release occurrence · 14.0/changes/146

  • Allow multiple verbose option specifications (-v) to increase the logging verbosity Features

    Allow multiple verbose option specifications (-v) to increase the logging verbosity (Tom Lane) §

    This behavior is supported by pg_dump, pg_dumpall, and pg_restore.

    Original release occurrence · 14.0/changes/147

  • Allow psql's \df and \do commands to specify function and operator argument types Features

    Allow psql's \df and \do commands to specify function and operator argument types (Greg Sabino Mullane, Tom Lane) §

    This helps reduce the number of matches printed for overloaded names.

    Original release occurrence · 14.0/changes/148

  • Add an access method column to psql's \d[i|m|t]+ output Features

    Add an access method column to psql's \d[i|m|t]+ output (Georgios Kokolatos) §

    Original release occurrence · 14.0/changes/149

  • Allow psql's \dt and \di to show TOAST tables and their indexes Features

    Allow psql's \dt and \di to show TOAST tables and their indexes (Justin Pryzby) §

    Original release occurrence · 14.0/changes/150

  • Add psql command \dX to list extended statistics objects Features

    Add psql command \dX to list extended statistics objects (Tatsuro Yamada) §

    Original release occurrence · 14.0/changes/151

  • Fix psql's \dT to understand array syntax and backend grammar aliases, like int for integer Bug fixes

    Fix psql's \dT to understand array syntax and backend grammar aliases, like int for integer (Greg Sabino Mullane, Tom Lane) §

    Original release occurrence · 14.0/changes/152

  • When editing the previous query or a file with psql's \e, or using \ef and \ev, ignore the results if the editor exits without saving Features

    When editing the previous query or a file with psql's \e, or using \ef and \ev, ignore the results if the editor exits without saving (Laurenz Albe) §

    Previously, such edits would load the previous query into the query buffer, and typically execute it immediately. This was deemed to be probably not what the user wants.

    Original release occurrence · 14.0/changes/153

  • Improve tab completion Features

    Improve tab completion (Vignesh C, Michael Paquier, Justin Pryzby, Georgios Kokolatos, Julien Rouhaud) § § § § § § § § § § § § § § § § § §

    Original release occurrence · 14.0/changes/154

  • Add command-line utility pg_amcheck to simplify running contrib/amcheck tests on many relations Features

    Add command-line utility pg_amcheck to simplify running contrib/amcheck tests on many relations (Mark Dilger) §

    Original release occurrence · 14.0/changes/155

  • Add --no-instructions option to initdb Features

    Add --no-instructions option to initdb (Magnus Hagander) §

    This suppresses the server startup instructions that are normally printed.

    Original release occurrence · 14.0/changes/156

  • Stop pg_upgrade from creating analyze_new_cluster script Features

    Stop pg_upgrade from creating analyze_new_cluster script (Magnus Hagander) §

    Instead, give comparable vacuumdb instructions.

    Original release occurrence · 14.0/changes/157

  • Remove support for the postmaster -o option Features

    Remove support for the postmaster -o option (Magnus Hagander) §

    This option was unnecessary since all passed options could already be specified directly.

    Original release occurrence · 14.0/changes/158

  • Rename "Default Roles" to "Predefined Roles" Features

    Rename "Default Roles" to "Predefined Roles" (Bruce Momjian, Stephen Frost) §

    Original release occurrence · 14.0/changes/159

  • Add documentation for the factorial() function Features

    Add documentation for the factorial() function (Peter Eisentraut) §

    With the removal of the ! operator in this release, factorial() is the only built-in way to compute a factorial.

    Original release occurrence · 14.0/changes/160

  • Add configure option --with-ssl={openssl} to allow future choice of the SSL library to use Features

    Add configure option --with-ssl={openssl} to allow future choice of the SSL library to use (Daniel Gustafsson, Michael Paquier) §

    The spelling --with-openssl is kept for compatibility.

    Original release occurrence · 14.0/changes/161

  • Add support for abstract Unix-domain sockets Features

    Add support for abstract Unix-domain sockets (Peter Eisentraut) §

    This is currently supported on Linux and Windows.

    Original release occurrence · 14.0/changes/162

  • Allow Windows to properly handle files larger than four gigabytes Features

    Allow Windows to properly handle files larger than four gigabytes (Juan José Santamaría Flecha) §

    For example this allows COPY, WAL files, and relation segment files to be larger than four gigabytes.

    Original release occurrence · 14.0/changes/163

  • Add server parameter debug_discard_caches to control cache flushing for test purposes Features

    Add server parameter debug_discard_caches to control cache flushing for test purposes (Craig Ringer) § § §

    Previously this behavior could only be set at compile time. To invoke it during initdb, use the new option --discard-caches.

    Original release occurrence · 14.0/changes/164

  • Various improvements in valgrind error detection ability Features

    Various improvements in valgrind error detection ability (Álvaro Herrera, Peter Geoghegan) § § §

    Original release occurrence · 14.0/changes/165

  • Add a test module for the regular expression package Features

    Add a test module for the regular expression package (Tom Lane) §

    Original release occurrence · 14.0/changes/166

  • Add support for LLVM version 12 Features

    Add support for LLVM version 12 (Andres Freund) §

    Original release occurrence · 14.0/changes/167

  • Change SHA1, SHA2, and MD5 hash computations to use the OpenSSL EVP API Features

    Change SHA1, SHA2, and MD5 hash computations to use the OpenSSL EVP API (Michael Paquier) § § § §

    This is more modern and supports FIPS mode.

    Original release occurrence · 14.0/changes/168

  • Remove separate build-time control over the choice of random number generator Features

    Remove separate build-time control over the choice of random number generator (Daniel Gustafsson) §

    This is now always determined by the choice of SSL library.

    Original release occurrence · 14.0/changes/169

  • Add direct conversion routines between EUC_TW and Big5 encodings Features

    Add direct conversion routines between EUC_TW and Big5 encodings (Heikki Linnakangas) §

    Original release occurrence · 14.0/changes/170

  • Add collation version support for FreeBSD Features

    Add collation version support for FreeBSD (Thomas Munro) §

    Original release occurrence · 14.0/changes/171

  • Add amadjustmembers to the index access method API Features

    Add amadjustmembers to the index access method API (Tom Lane) §

    This allows an index access method to provide validity checking during creation of a new operator class or family.

    Original release occurrence · 14.0/changes/172

  • Provide feature-test macros in libpq-fe.h for recently-added libpq features Features

    Provide feature-test macros in libpq-fe.h for recently-added libpq features (Tom Lane, Álvaro Herrera) §

    Historically, applications have usually used compile-time checks of PG_VERSION_NUM to test whether a feature is available. But that's normally the server version, which might not be a good guide to libpq's version. libpq-fe.h now offers #define symbols denoting application-visible features added in v14; the intent is to keep adding symbols for such features in future versions.

    Original release occurrence · 14.0/changes/173

  • Allow subscripting of hstore values Features

    Allow subscripting of hstore values (Tom Lane, Dmitry Dolgov) §

    Original release occurrence · 14.0/changes/174

  • Allow GiST/GIN pg_trgm indexes to do equality lookups Features

    Allow GiST/GIN pg_trgm indexes to do equality lookups (Julien Rouhaud) §

    This is similar to LIKE except no wildcards are honored.

    Original release occurrence · 14.0/changes/175

  • Allow the cube data type to be transferred in binary mode Features

    Allow the cube data type to be transferred in binary mode (KaiGai Kohei) §

    Original release occurrence · 14.0/changes/176

  • Allow pgstattuple_approx() to report on TOAST tables Features

    Allow pgstattuple_approx() to report on TOAST tables (Peter Eisentraut) §

    Original release occurrence · 14.0/changes/177

  • Add contrib module pg_surgery which allows changes to row visibility Features

    Add contrib module pg_surgery which allows changes to row visibility (Ashutosh Sharma) §

    This is useful for correcting database corruption.

    Original release occurrence · 14.0/changes/178

  • Add contrib module old_snapshot to report the XID/time mapping used by an active old_snapshot_threshold Features

    Add contrib module old_snapshot to report the XID/time mapping used by an active old_snapshot_threshold (Robert Haas) §

    Original release occurrence · 14.0/changes/179

  • Allow amcheck to also check heap pages Features

    Allow amcheck to also check heap pages (Mark Dilger) §

    Previously it only checked B-Tree index pages.

    Original release occurrence · 14.0/changes/180

  • Allow pageinspect to inspect GiST indexes Features

    Allow pageinspect to inspect GiST indexes (Andrey Borodin, Heikki Linnakangas) § §

    Original release occurrence · 14.0/changes/181

  • Change pageinspect block numbers to be bigints Features

    Change pageinspect block numbers to be bigints (Peter Eisentraut) §

    Original release occurrence · 14.0/changes/182

  • Mark btree_gist functions as parallel safe Features

    Mark btree_gist functions as parallel safe (Steven Winfield) §

    Original release occurrence · 14.0/changes/183

  • Move query hash computation from pg_stat_statements to the core server Features

    Move query hash computation from pg_stat_statements to the core server (Julien Rouhaud) §

    The new server parameter compute_query_id's default of auto will automatically enable query id computation when this extension is loaded.

    Original release occurrence · 14.0/changes/184

  • Cause pg_stat_statements to track top and nested statements separately Features

    Cause pg_stat_statements to track top and nested statements separately (Julien Rohaud) §

    Previously, when tracking all statements, identical top and nested statements were tracked as a single entry; but it seems more useful to separate such usages.

    Original release occurrence · 14.0/changes/185

  • Add row counts for utility commands to pg_stat_statements Features

    Add row counts for utility commands to pg_stat_statements (Fujii Masao, Katsuragi Yuta, Seino Yuki) § §

    Original release occurrence · 14.0/changes/186

  • Add pg_stat_statements_info system view to show pg_stat_statements activity Features

    Add pg_stat_statements_info system view to show pg_stat_statements activity (Katsuragi Yuta, Yuki Seino, Naoki Nakamichi) § §

    Original release occurrence · 14.0/changes/187

  • Allow postgres_fdw to INSERT rows in bulk Features

    Allow postgres_fdw to INSERT rows in bulk (Takayuki Tsunakawa, Tomas Vondra, Amit Langote) § §

    Original release occurrence · 14.0/changes/188

  • Allow postgres_fdw to import table partitions if specified by IMPORT FOREIGN SCHEMA ... LIMIT TO Features

    Allow postgres_fdw to import table partitions if specified by IMPORT FOREIGN SCHEMA ... LIMIT TO (Matthias van de Meent) §

    By default, only the root of a partitioned table is imported.

    Original release occurrence · 14.0/changes/189

  • Add postgres_fdw function postgres_fdw_get_connections() to report open foreign server connections Features

    Add postgres_fdw function postgres_fdw_get_connections() to report open foreign server connections (Bharath Rupireddy) §

    Original release occurrence · 14.0/changes/190

  • Allow control over whether foreign servers keep connections open after transaction completion Features

    Allow control over whether foreign servers keep connections open after transaction completion (Bharath Rupireddy) §

    This is controlled by keep_connections and defaults to on.

    Original release occurrence · 14.0/changes/191

  • Allow postgres_fdw to reestablish foreign server connections if necessary Features

    Allow postgres_fdw to reestablish foreign server connections if necessary (Bharath Rupireddy) § §

    Previously foreign server restarts could cause foreign table access errors.

    Original release occurrence · 14.0/changes/192

  • Add postgres_fdw functions to discard cached connections Features

    Add postgres_fdw functions to discard cached connections (Bharath Rupireddy) §

    Original release occurrence · 14.0/changes/193

Security evidence

67 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.

CVE-2026-6637 · PostgreSQL refint allows stack buffer overflow and SQL injection CVSS 8.8

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 14.23. Component: contrib module.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6479 · PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion CVSS 7.5

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 14.23. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2026-6478 · PostgreSQL discloses MD5-hashed passwords via covert timing channel CVSS 6.5

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 14.23. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-6477 · PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory CVSS 8.8

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 14.23. Component: client.

Official affected-branch entry: 14.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6475 · PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice CVSS 8.8

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 14.23. Component: client.

Official affected-branch entry: 14.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6474 · PostgreSQL timeofday() can disclose portions of server memory CVSS 4.3

Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 14.23. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-6473 · PostgreSQL server undersizes allocations, via integer wraparound CVSS 8.8

Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 14.23. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6472 · PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege CVSS 5.4

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 14.23. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-6471 · PostgreSQL logical decoding can dlopen arbitrary file CVSS 7.2

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6470 · PostgreSQL fails to check type USAGE privilege CVSS 4.3

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2026-6469 · PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership CVSS 3.8

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

Release-note mentions:

CVE-2026-6464 · PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands CVSS 8.1

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: client.

Official affected-branch entry: 14.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2006 · PostgreSQL missing validation of multibyte character length executes arbitrary code CVSS 8.8

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 14.21. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2005 · PostgreSQL pgcrypto heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 14.21. Component: contrib module.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2004 · PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code CVSS 8.8

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 14.21. Component: contrib module.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2003 · PostgreSQL oidvector discloses a few bytes of memory CVSS 4.3

Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 14.21. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-19385 · PostgreSQL pg_dump heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: client.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-18408 · PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client CVSS 8.8

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: client.

Official affected-branch entry: 14.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-18024 · PostgreSQL ascii() function reads past end of buffer CVSS 4.3

Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-16241 · PostgreSQL ECPG integer underflow can crash the client CVSS 3.8

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: client.

Official affected-branch entry: 14.

AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

Release-note mentions:

CVE-2026-16239 · PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-16238 · PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-15742 · PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: contrib module.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-15741 · PostgreSQL expression deparse allows SQL injection via EXTRACT argument CVSS 8.8

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14681 · PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL CVSS 4.2

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14680 · PostgreSQL type confusion via "internal" arguments CVSS 8.8

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14679 · PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory CVSS 8.2

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Release-note mentions:

CVE-2026-14678 · PostgreSQL pg_trgm picksplit reads past end of buffer CVSS 4.3

Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: contrib module.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-14677 · PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14676 · PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

No fixed version for this branch is recorded. Component: contrib module.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14673 · PostgreSQL amcheck does not clear untrusted search path CVSS 3.8

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

Fixed in this branch: 14.24. Component: contrib module.

Official affected-branch entry: 14.

AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14672 · PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle CVSS 5.3

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-14671 · PostgreSQL refint plan cache type confusion executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: contrib module.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14670 · PostgreSQL plperl tied object heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14669 · PostgreSQL to_char heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14668 · PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read CVSS 8.1

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Release-note mentions:

CVE-2026-14666 · PostgreSQL row security caching disregards role modifications CVSS 4.2

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14664 · PostgreSQL regexp heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14663 · PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext CVSS 6.5

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: contrib module.

Official affected-branch entry: 14.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14662 · PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 14.24. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8715 · PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server CVSS 8.8

Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.

Fixed in this branch: 14.19. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client CVSS 8.8

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

Fixed in this branch: 14.19. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8713 · PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table CVSS 3.1

PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

Fixed in this branch: 14.19. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2025-4207 · PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation CVSS 5.9

Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.

Fixed in this branch: 14.18. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound CVSS 5.9

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Fixed in this branch: 14.20. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege CVSS 3.1

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Fixed in this branch: 14.20. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2025-1094 · PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation CVSS 8.1

Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.

Fixed in this branch: 14.16. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-7348 · PostgreSQL relation replacement during pg_dump executes arbitrary SQL CVSS 8.8

Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected. The PostgreSQL project thanks Noah Misch for reporting this problem.

Fixed in this branch: 14.13. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-4317 · Restrict visibility of "pg_stats_ext" and "pg_stats_ext_exprs" entries to the table owner CVSS 3.1

Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes, which are provided as a convenience in the below section. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected. This fix only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after this fix is applied. If you have a current PostgreSQL installation and are concerned about this issue, please use the following remediation steps to fix the issue: From the above URLs, you can click the URL that says "raw" to download a version that you can copy and paste. Be sure to use the script appropriate to your PostgreSQL major version. If you do not see this file, either your version is not vulnerable (only PostgreSQL 14, 15, and 16 are affected) or your minor version is too old to have the fix. \i /usr/share/postgresql/fix-CVE-2024-4317.sql ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; After executing the fix-CVE-2024-4317.sql script in template0 and template1 , you should revoke the ability for template0 to accept connections. You can do this with the following command: ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; The PostgreSQL project thanks Lukas Fittl for reporting this problem.

Fixed in this branch: 14.12. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code CVSS 8.8

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.

Fixed in this branch: 14.14. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID CVSS 4.2

Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 14.14. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle CVSS 3.1

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 14.14. Component: client.

Official affected-branch entry: 14.

AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes CVSS 4.2

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

Fixed in this branch: 14.14. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2024-0985 · PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL CVSS 8.0

UPDATE (June 19, 2024) : Added v16 as impacted. Updated description to clarify the attack vector. Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view.

Fixed in this branch: 14.11. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes CVSS 2.2

Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.

Fixed in this branch: 14.10. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2023-5869 · Buffer overrun from integer overflow in array modification CVSS 8.8

While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.

Fixed in this branch: 14.10. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-5868 · Memory disclosure in aggregate function calls CVSS 4.3

Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.

Fixed in this branch: 14.10. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection CVSS 7.5

An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.

Fixed in this branch: 14.9. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-2455 · Row security policies disregard user ID changes after inlining CVSS 4.2

While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.

Fixed in this branch: 14.8. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes CVSS 7.2

This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.

Fixed in this branch: 14.8. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2022-41862 · Client memory disclosure when connecting, with Kerberos, to modified server CVSS 3.7

A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. When a libpq client application has a Kerberos credential cache and doesn't explicitly disable option gssencmode , a server can cause libpq to over-read and report an error message containing uninitialized bytes from and following its receive buffer. If libpq's caller somehow makes that message accessible to the attacker, this achieves a disclosure of the over-read bytes. We have not confirmed or ruled out viability of attacks that arrange for a crash or for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 14.7. Component: client.

Official affected-branch entry: 14.

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2022-2625 · Extension scripts replace objects not belonging to the extension CVSS 7.1

Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.

Fixed in this branch: 14.5. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox CVSS 8.8

Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.

Fixed in this branch: 14.3. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle CVSS 3.7

A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 14.1. Component: client.

Official affected-branch entry: 14.

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle CVSS 8.1

When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 14.1. Component: core server.

Official affected-branch entry: 14.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2012-0868 · Line breaks in object names can be exploited to execute arbitrary SQL when reloading a pg_dump file.

No fixed version for this branch is recorded.

Release-note mentions:

Export this branch as JSON · Compare any two indexed releases