PostgreSQL 14
Read the English manualSupported · Recorded build 14.24 · 2026-08-13
- First stable release
- 2021-09-30
- Support end
- 2026-11-12
- Indexed releases
- 25
- Original release-note entries
- 1206
Manuals & provenance
PostgreSQL 14 English manual · 1161 loaded pages.
Manual loaded 2026-09-27T00:10:47.078613.
Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.
Upgrade considerations
Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.
Compatibility notes for 14.0 · Changes from the initial release through 14.24
Original migration guidance for 14.0
A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 19.6 for general information on migrating to new major releases.
Version 14 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:
Release history
Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.
| Release | Date / snapshot cutoff | All changes | Bug fixes | Migration entries | CVE mentions |
|---|---|---|---|---|---|
| 14.24 | 2026-08-13 | 83 | 31 | 0 | 31 |
| 14.23 | 2026-05-14 | 38 | 15 | 0 | 8 |
| 14.22 | 2026-02-26 | 5 | 4 | 0 | 1 |
| 14.21 | 2026-02-12 | 37 | 16 | 0 | 4 |
| 14.20 | 2025-11-13 | 46 | 23 | 0 | 2 |
| 14.19 | 2025-08-14 | 47 | 12 | 0 | 5 |
| 14.18 | 2025-05-08 | 35 | 16 | 0 | 1 |
| 14.17 | 2025-02-20 | 2 | 1 | 0 | 1 |
| 14.16 | 2025-02-13 | 46 | 26 | 0 | 1 |
| 14.15 | 2024-11-21 | 7 | 3 | 0 | 1 |
| 14.14 | 2024-11-14 | 44 | 17 | 0 | 4 |
| 14.13 | 2024-08-08 | 42 | 21 | 0 | 2 |
| 14.12 | 2024-05-09 | 42 | 18 | 0 | 1 |
| 14.11 | 2024-02-08 | 49 | 18 | 0 | 1 |
| 14.10 | 2023-11-09 | 56 | 21 | 0 | 3 |
| 14.9 | 2023-08-10 | 39 | 20 | 0 | 1 |
| 14.8 | 2023-05-11 | 67 | 31 | 0 | 2 |
| 14.7 | 2023-02-09 | 47 | 23 | 0 | 1 |
| 14.6 | 2022-11-10 | 41 | 17 | 0 | 0 |
| 14.5 | 2022-08-11 | 39 | 18 | 0 | 2 |
| 14.4 | 2022-06-16 | 19 | 9 | 0 | 0 |
| 14.3 | 2022-05-12 | 52 | 25 | 0 | 1 |
| 14.2 | 2022-02-10 | 57 | 31 | 0 | 0 |
| 14.1 | 2021-11-11 | 46 | 21 | 0 | 2 |
| 14.0 | 2021-09-30 | 220 | 2 | 27 | 0 |
Initial release changes
Original entries from 14.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.
220 of 220 original entries.
User-defined objects that reference certain built-in array functions along with their argument types must be recreated Compatibility Migration
User-defined objects that reference certain built-in array functions along with their argument types must be recreated (Tom Lane) §
Specifically,
array_append(),array_prepend(),array_cat(),array_position(),array_positions(),array_remove(),array_replace(), andwidth_bucket()used to takeanyarrayarguments but now takeanycompatiblearray. Therefore, user-defined objects like aggregates and operators that reference those array function signatures must be dropped before upgrading, and recreated once the upgrade completes.Original release occurrence ·
14.0/migration/001Remove deprecated containment operators @ and ~ for built-in geometric data types and contrib modules cube, hstore, intarray, and seg Compatibility Migration
Remove deprecated containment operators
@and~for built-in geometric data types and contrib modules cube, hstore, intarray, and seg (Justin Pryzby) § §The more consistently named
<@and@>have been recommended for many years.Original release occurrence ·
14.0/migration/002Fix to_tsquery() and websearch_to_tsquery() to properly parse query text containing discarded tokens Compatibility Migration
Fix
to_tsquery()andwebsearch_to_tsquery()to properly parse query text containing discarded tokens (Alexander Korotkov) §Certain discarded tokens, like underscore, caused the output of these functions to produce incorrect tsquery output, e.g., both
websearch_to_tsquery('"pg_class pg"')andto_tsquery('pg_class <-> pg')used to output( 'pg' & 'class' ) <-> 'pg', but now both output'pg' <-> 'class' <-> 'pg'.Original release occurrence ·
14.0/migration/003Fix websearch_to_tsquery() to properly parse multiple adjacent discarded tokens in quotes Compatibility Migration
Fix
websearch_to_tsquery()to properly parse multiple adjacent discarded tokens in quotes (Alexander Korotkov) §Previously, quoted text that contained multiple adjacent discarded tokens was treated as multiple tokens, causing incorrect tsquery output, e.g.,
websearch_to_tsquery('"aaa: bbb"')used to output'aaa' <2> 'bbb', but now outputs'aaa' <-> 'bbb'.Original release occurrence ·
14.0/migration/004Change EXTRACT() to return type numeric instead of float8 Compatibility Migration
Change
EXTRACT()to return typenumericinstead offloat8(Peter Eisentraut) §This avoids loss-of-precision issues in some usages. The old behavior can still be obtained by using the old underlying function
date_part().Also,
EXTRACT(date)now throws an error for units that are not part of thedatedata type.Original release occurrence ·
14.0/migration/005Change var_samp() and stddev_samp() with numeric parameters to return NULL when the input is a single NaN value Compatibility Migration
Change
var_samp()andstddev_samp()with numeric parameters to return NULL when the input is a single NaN value (Tom Lane) §Previously
NaNwas returned.Original release occurrence ·
14.0/migration/006Return false for has_column_privilege() checks on non-existent or dropped columns when using attribute numbers Compatibility Migration
Return false for
has_column_privilege()checks on non-existent or dropped columns when using attribute numbers (Joe Conway) §Previously such attribute numbers returned an invalid-column error.
Original release occurrence ·
14.0/migration/007Fix handling of infinite window function ranges Compatibility Migration
Fix handling of infinite window function ranges (Tom Lane) §
Previously window frame clauses like
'inf' PRECEDING AND 'inf' FOLLOWINGreturned incorrect results.Original release occurrence ·
14.0/migration/008Remove factorial operators ! and !!, as well as function numeric_fac() Compatibility Migration
Remove factorial operators
!and!!, as well as functionnumeric_fac()(Mark Dilger) §The
factorial()function is still supported.Original release occurrence ·
14.0/migration/009Disallow factorial() of negative numbers Compatibility Migration
Disallow
factorial()of negative numbers (Peter Eisentraut) §Previously such cases returned 1.
Original release occurrence ·
14.0/migration/010Remove support for postfix (right-unary) operators Compatibility Migration
Remove support for postfix (right-unary) operators (Mark Dilger) §
pg_dump and pg_upgrade will warn if postfix operators are being dumped.
Original release occurrence ·
14.0/migration/011Allow \D and \W shorthands to match newlines in regular expression newline-sensitive mode Compatibility Migration
Allow
\Dand\Wshorthands to match newlines in regular expression newline-sensitive mode (Tom Lane) §Previously they did not match newlines in this mode, but that disagrees with the behavior of other common regular expression engines.
[^[:digit:]]or[^[:word:]]can be used to get the old behavior.Original release occurrence ·
14.0/migration/012Disregard constraints when matching regular expression back-references Compatibility Migration
Disregard constraints when matching regular expression back-references (Tom Lane) §
For example, in
(^\d+).*\1, the^constraint should be applied at the start of the string, but not when matching\1.Original release occurrence ·
14.0/migration/013Disallow \w as a range start or end in regular expression character classes Compatibility Migration
Disallow
\was a range start or end in regular expression character classes (Tom Lane) §This previously was allowed but produced unexpected results.
Original release occurrence ·
14.0/migration/014Require custom server parameter names to use only characters that are valid in unquoted SQL identifiers Compatibility Migration
Require custom server parameter names to use only characters that are valid in unquoted SQL identifiers (Tom Lane) § §
Original release occurrence ·
14.0/migration/015Change the default of the password_encryption server parameter to scram-sha-256 Compatibility Migration
Change the default of the password_encryption server parameter to
scram-sha-256(Peter Eisentraut) §Previously it was
md5. All new passwords will be stored as SHA256 unless this server setting is changed or the password is specified in MD5 format. Also, the legacy (and undocumented) Boolean-like values which were previously synonyms formd5are no longer accepted.Original release occurrence ·
14.0/migration/016Remove server parameter vacuum_cleanup_index_scale_factor Compatibility Migration
Remove server parameter
vacuum_cleanup_index_scale_factor(Peter Geoghegan) § §This setting was ignored starting in PostgreSQL version 13.3.
Original release occurrence ·
14.0/migration/017Remove server parameter operator_precedence_warning Compatibility Migration
Remove server parameter
operator_precedence_warning(Tom Lane) §This setting was used for warning applications about PostgreSQL 9.5 changes.
Original release occurrence ·
14.0/migration/018Overhaul the specification of clientcert in pg_hba.conf Compatibility Migration
Overhaul the specification of
clientcertinpg_hba.conf(Kyotaro Horiguchi) §Values
1/0/no-verifyare no longer supported; only the stringsverify-caandverify-fullcan be used. Also, disallowverify-caif cert authentication is enabled since cert requiresverify-fullchecking.Original release occurrence ·
14.0/migration/019Remove support for SSL compression Compatibility Migration
Remove support for SSL compression (Daniel Gustafsson, Michael Paquier) § §
This was already disabled by default in previous PostgreSQL releases, and most modern OpenSSL and TLS versions no longer support it.
Original release occurrence ·
14.0/migration/020Remove server and libpq support for the version 2 wire protocol Compatibility Migration
Remove server and libpq support for the version 2 wire protocol (Heikki Linnakangas) §
This was last used as the default in PostgreSQL 7.3 (released in 2002).
Original release occurrence ·
14.0/migration/021Disallow single-quoting of the language name in the CREATE/DROP LANGUAGE command Compatibility Migration
Disallow single-quoting of the language name in the
CREATE/DROP LANGUAGEcommand (Peter Eisentraut) §Original release occurrence ·
14.0/migration/022Remove the composite types that were formerly created for sequences and toast tables Compatibility Migration
Remove the composite types that were formerly created for sequences and toast tables (Tom Lane) §
Original release occurrence ·
14.0/migration/023Process doubled quote marks in ecpg SQL command strings correctly Compatibility Migration
Process doubled quote marks in ecpg SQL command strings correctly (Tom Lane) § §
Previously
'abc''def'was passed to the server as'abc'def', and"abc""def"was passed as"abc"def", causing syntax errors.Original release occurrence ·
14.0/migration/024Prevent the containment operators (<@ and @>) for intarray from using GiST indexes Compatibility Migration
Prevent the containment operators (
<@and@>) for intarray from using GiST indexes (Tom Lane) §Previously a full GiST index scan was required, so just avoid that and scan the heap, which is faster. Indexes created for this purpose should be removed.
Original release occurrence ·
14.0/migration/025Remove contrib program pg_standby Compatibility Migration
Remove contrib program pg_standby (Justin Pryzby) §
Original release occurrence ·
14.0/migration/026Prevent tablefunc's function normal_rand() from accepting negative values Compatibility Migration
Prevent tablefunc's function
normal_rand()from accepting negative values (Ashutosh Bapat) §Negative values produced undesirable results.
Original release occurrence ·
14.0/migration/027Add predefined roles pg_read_all_data and pg_write_all_data Features
Add predefined roles
pg_read_all_dataandpg_write_all_data(Stephen Frost) §These non-login roles can be used to give read or write permission to all tables, views, and sequences.
Original release occurrence ·
14.0/changes/001Add predefined role pg_database_owner that contains only the current database's owner Features
Add predefined role
pg_database_ownerthat contains only the current database's owner (Noah Misch) §This is especially useful in template databases.
Original release occurrence ·
14.0/changes/002Remove temporary files after backend crashes Features
Remove temporary files after backend crashes (Euler Taveira) §
Previously, such files were retained for debugging purposes. If necessary, deletion can be disabled with the new server parameter remove_temp_files_after_crash.
Original release occurrence ·
14.0/changes/003Allow long-running queries to be canceled if the client disconnects Features
Allow long-running queries to be canceled if the client disconnects (Sergey Cherkashin, Thomas Munro) §
The server parameter client_connection_check_interval allows control over whether loss of connection is checked for intra-query. (This is supported on Linux and a few other operating systems.)
Original release occurrence ·
14.0/changes/004Add an optional timeout parameter to pg_terminate_backend() Features
Add an optional timeout parameter to
pg_terminate_backend()(Magnus Hagander) §Original release occurrence ·
14.0/changes/005Allow wide tuples to be always added to almost-empty heap pages Features
Allow wide tuples to be always added to almost-empty heap pages (John Naylor, Floris van Nee) §
Previously tuples whose insertion would have exceeded the page's fill factor were instead added to new pages.
Original release occurrence ·
14.0/changes/006Add Server Name Indication (SNI) in SSL connection packets Features
Add Server Name Indication (SNI) in SSL connection packets (Peter Eisentraut) §
This can be disabled by turning off client connection option
sslsni.Original release occurrence ·
14.0/changes/007Allow vacuum to skip index vacuuming when the number of removable index entries is insignificant Features
Allow vacuum to skip index vacuuming when the number of removable index entries is insignificant (Masahiko Sawada, Peter Geoghegan) § §
The vacuum parameter
INDEX_CLEANUPhas a new default ofautothat enables this optimization.Original release occurrence ·
14.0/changes/008Allow vacuum to more eagerly add deleted btree pages to the free space map Features
Allow vacuum to more eagerly add deleted btree pages to the free space map (Peter Geoghegan) §
Previously vacuum could only add pages to the free space map that were marked as deleted by previous vacuums.
Original release occurrence ·
14.0/changes/009Allow vacuum to reclaim space used by unused trailing heap line pointers Features
Allow vacuum to reclaim space used by unused trailing heap line pointers (Matthias van de Meent, Peter Geoghegan) §
Original release occurrence ·
14.0/changes/010Allow vacuum to be more aggressive in removing dead rows during minimal-locking index operations Features
Allow vacuum to be more aggressive in removing dead rows during minimal-locking index operations (Álvaro Herrera) § § §
Specifically,
CREATE INDEX CONCURRENTLYandREINDEX CONCURRENTLYno longer limit the dead row removal of other relations.Original release occurrence ·
14.0/changes/011Speed up vacuuming of databases with many relations Performance
Speed up vacuuming of databases with many relations (Tatsuhito Kasahara) §
Original release occurrence ·
14.0/changes/012Reduce the default value of vacuum_cost_page_miss to better reflect current hardware capabilities Features
Reduce the default value of vacuum_cost_page_miss to better reflect current hardware capabilities (Peter Geoghegan) §
Original release occurrence ·
14.0/changes/013Add ability to skip vacuuming of TOAST tables Features
Add ability to skip vacuuming of TOAST tables (Nathan Bossart) §
VACUUMnow has aPROCESS_TOASToption which can be set to false to disable TOAST processing, and vacuumdb has a--no-process-toastoption.Original release occurrence ·
14.0/changes/014Have COPY FREEZE appropriately update page visibility bits Features
Have
COPY FREEZEappropriately update page visibility bits (Anastasia Lubennikova, Pavan Deolasee, Jeff Janes) §Original release occurrence ·
14.0/changes/015Cause vacuum operations to be more aggressive if the table is near xid or multixact wraparound Features
Cause vacuum operations to be more aggressive if the table is near xid or multixact wraparound (Masahiko Sawada, Peter Geoghegan) §
This is controlled by vacuum_failsafe_age and vacuum_multixact_failsafe_age.
Original release occurrence ·
14.0/changes/016Increase warning time and hard limit before transaction id and multi-transaction wraparound Features
Increase warning time and hard limit before transaction id and multi-transaction wraparound (Noah Misch) §
This should reduce the possibility of failures that occur without having issued warnings about wraparound.
Original release occurrence ·
14.0/changes/017Add per-index information to autovacuum logging output Features
Add per-index information to autovacuum logging output (Masahiko Sawada) §
Original release occurrence ·
14.0/changes/018Improve the performance of updates and deletes on partitioned tables with many partitions Performance
Improve the performance of updates and deletes on partitioned tables with many partitions (Amit Langote, Tom Lane) § § §
This change greatly reduces the planner's overhead for such cases, and also allows updates/deletes on partitioned tables to use execution-time partition pruning.
Original release occurrence ·
14.0/changes/019Allow partitions to be detached in a non-blocking manner Features
Allow partitions to be detached in a non-blocking manner (Álvaro Herrera) §
The syntax is
ALTER TABLE ... DETACH PARTITION ... CONCURRENTLY, andFINALIZE.Original release occurrence ·
14.0/changes/020Ignore COLLATE clauses in partition boundary values Features
Ignore
COLLATEclauses in partition boundary values (Tom Lane) §Previously any such clause had to match the collation of the partition key; but it's more consistent to consider that it's automatically coerced to the collation of the partition key.
Original release occurrence ·
14.0/changes/021Allow btree index additions to remove expired index entries to prevent page splits Features
Allow btree index additions to remove expired index entries to prevent page splits (Peter Geoghegan) § §
This is particularly helpful for reducing index bloat on tables whose indexed columns are frequently updated.
Original release occurrence ·
14.0/changes/022Allow BRIN indexes to record multiple min/max values per range Features
Allow BRIN indexes to record multiple min/max values per range (Tomas Vondra) §
This is useful if there are groups of values in each page range.
Original release occurrence ·
14.0/changes/023Allow BRIN indexes to use bloom filters Features
Allow BRIN indexes to use bloom filters (Tomas Vondra) §
This allows BRIN indexes to be used effectively with data that is not well-localized in the heap.
Original release occurrence ·
14.0/changes/024Allow some GiST indexes to be built by presorting the data Features
Allow some GiST indexes to be built by presorting the data (Andrey Borodin) §
Presorting happens automatically and allows for faster index creation and smaller indexes.
Original release occurrence ·
14.0/changes/025Allow SP-GiST indexes to contain INCLUDE'd columns Features
Original release occurrence ·
14.0/changes/026Allow hash lookup for IN clauses with many constants Features
Allow hash lookup for
INclauses with many constants (James Coleman, David Rowley) §Previously the code always sequentially scanned the list of values.
Original release occurrence ·
14.0/changes/027Increase the number of places extended statistics can be used for OR clause estimation Features
Increase the number of places extended statistics can be used for
ORclause estimation (Tomas Vondra, Dean Rasheed) § § §Original release occurrence ·
14.0/changes/028Allow extended statistics on expressions Features
Allow extended statistics on expressions (Tomas Vondra) §
This allows statistics on a group of expressions and columns, rather than only columns like previously. System view
pg_stats_ext_exprsreports such statistics.Original release occurrence ·
14.0/changes/029Allow efficient heap scanning of a range of TIDs Features
Allow efficient heap scanning of a range of
TIDs(Edmund Horner, David Rowley) §Previously a sequential scan was required for non-equality
TIDspecifications.Original release occurrence ·
14.0/changes/030Fix EXPLAIN CREATE TABLE AS and EXPLAIN CREATE MATERIALIZED VIEW to honor IF NOT EXISTS Bug fixes
Fix
EXPLAIN CREATE TABLE ASandEXPLAIN CREATE MATERIALIZED VIEWto honorIF NOT EXISTS(Bharath Rupireddy) §Previously, if the object already existed,
EXPLAINwould fail.Original release occurrence ·
14.0/changes/031Improve the speed of computing MVCC visibility snapshots on systems with many CPUs and high session counts Performance
Improve the speed of computing MVCC visibility snapshots on systems with many CPUs and high session counts (Andres Freund) § § § § § §
This also improves performance when there are many idle sessions.
Original release occurrence ·
14.0/changes/032Add executor method to memoize results from the inner side of a nested-loop join Performance
Add executor method to memoize results from the inner side of a nested-loop join (David Rowley) §
This is useful if only a small percentage of rows is checked on the inner side. It can be disabled via server parameter enable_memoize.
Original release occurrence ·
14.0/changes/033Allow window functions to perform incremental sorts Performance
Allow window functions to perform incremental sorts (David Rowley) §
Original release occurrence ·
14.0/changes/034Improve the I/O performance of parallel sequential scans Performance
Improve the I/O performance of parallel sequential scans (Thomas Munro, David Rowley) §
This was done by allocating blocks in groups to parallel workers.
Original release occurrence ·
14.0/changes/035Allow a query referencing multiple foreign tables to perform foreign table scans in parallel Performance
Allow a query referencing multiple foreign tables to perform foreign table scans in parallel (Robert Haas, Kyotaro Horiguchi, Thomas Munro, Etsuro Fujita) §
postgres_fdw supports this type of scan if
async_capableis set.Original release occurrence ·
14.0/changes/036Allow analyze to do page prefetching Performance
Allow analyze to do page prefetching (Stephen Frost) §
This is controlled by maintenance_io_concurrency.
Original release occurrence ·
14.0/changes/037Dramatically improve Unicode normalization performance Performance
Dramatically improve Unicode normalization performance (John Naylor) § §
This speeds
normalize()andIS NORMALIZED.Original release occurrence ·
14.0/changes/039Add ability to use LZ4 compression on TOAST data Performance
Add ability to use LZ4 compression on TOAST data (Dilip Kumar) §
This can be set at the column level, or set as a default via server parameter default_toast_compression. The server must be compiled with
--with-lz4to support this feature. The default setting is still pglz.Original release occurrence ·
14.0/changes/040If server parameter compute_query_id is enabled, display the query id in pg_stat_activity, EXPLAIN VERBOSE, csvlog, and optionally in log_line_prefix Features
If server parameter compute_query_id is enabled, display the query id in
pg_stat_activity,EXPLAIN VERBOSE, csvlog, and optionally in log_line_prefix (Julien Rouhaud) § § § § §A query id computed by an extension will also be displayed.
Original release occurrence ·
14.0/changes/041Improve logging of auto-vacuum and auto-analyze Features
Improve logging of auto-vacuum and auto-analyze (Stephen Frost, Jakub Wartak) §
This reports I/O timings for auto-vacuum and auto-analyze if track_io_timing is enabled. Also, report buffer read and dirty rates for auto-analyze.
Original release occurrence ·
14.0/changes/042Add information about the original user name supplied by the client to the output of log_connections Features
Add information about the original user name supplied by the client to the output of log_connections (Jacob Champion) §
Original release occurrence ·
14.0/changes/043Add system view pg_stat_progress_copy to report COPY progress Features
Add system view
pg_stat_progress_copyto reportCOPYprogress (Josef Šimánek, Matthias van de Meent) § §Original release occurrence ·
14.0/changes/044Add system view pg_stat_wal to report WAL activity Features
Add system view
pg_stat_walto report WAL activity (Masahiro Ikeda) § § §Original release occurrence ·
14.0/changes/045Add system view pg_stat_replication_slots to report replication slot activity Features
Add system view
pg_stat_replication_slotsto report replication slot activity (Masahiko Sawada, Amit Kapila, Vignesh C) § § § §The function
pg_stat_reset_replication_slot()resets slot statistics.Original release occurrence ·
14.0/changes/046Add system view pg_backend_memory_contexts to report session memory usage Features
Add system view
pg_backend_memory_contextsto report session memory usage (Atsushi Torikoshi, Fujii Masao) § §Original release occurrence ·
14.0/changes/047Add function pg_log_backend_memory_contexts() to output the memory contexts of arbitrary backends Features
Add function
pg_log_backend_memory_contexts()to output the memory contexts of arbitrary backends (Atsushi Torikoshi) §Original release occurrence ·
14.0/changes/048Add session statistics to the pg_stat_database system view Features
Add session statistics to the
pg_stat_databasesystem view (Laurenz Albe) §Original release occurrence ·
14.0/changes/049Add columns to pg_prepared_statements to report generic and custom plan counts Features
Add columns to
pg_prepared_statementsto report generic and custom plan counts (Atsushi Torikoshi, Kyotaro Horiguchi) §Original release occurrence ·
14.0/changes/050Add lock wait start time to pg_locks Features
Original release occurrence ·
14.0/changes/051Make the archiver process visible in pg_stat_activity Features
Make the archiver process visible in
pg_stat_activity(Kyotaro Horiguchi) §Original release occurrence ·
14.0/changes/052Add wait event WalReceiverExit to report WAL receiver exit wait time Features
Add wait event
WalReceiverExitto report WAL receiver exit wait time (Fujii Masao) §Original release occurrence ·
14.0/changes/053Implement information schema view routine_column_usage to track columns referenced by function and procedure default expressions Features
Implement information schema view
routine_column_usageto track columns referenced by function and procedure default expressions (Peter Eisentraut) §Original release occurrence ·
14.0/changes/054Allow an SSL certificate's distinguished name (DN) to be matched for client certificate authentication Features
Allow an SSL certificate's distinguished name (DN) to be matched for client certificate authentication (Andrew Dunstan) §
The new
pg_hba.confoptionclientname=DNallows comparison with certificate attributes beyond theCNand can be combined with ident maps.Original release occurrence ·
14.0/changes/055Allow pg_hba.conf and pg_ident.conf records to span multiple lines Features
Allow
pg_hba.confandpg_ident.confrecords to span multiple lines (Fabien Coelho) §A backslash at the end of a line allows record contents to be continued on the next line.
Original release occurrence ·
14.0/changes/056Allow the specification of a certificate revocation list (CRL) directory Features
Allow the specification of a certificate revocation list (CRL) directory (Kyotaro Horiguchi) §
This is controlled by server parameter ssl_crl_dir and libpq connection option sslcrldir. Previously only single CRL files could be specified.
Original release occurrence ·
14.0/changes/057Allow passwords of an arbitrary length Features
Allow passwords of an arbitrary length (Tom Lane, Nathan Bossart) §
Original release occurrence ·
14.0/changes/058Add server parameter idle_session_timeout to close idle sessions Features
Add server parameter idle_session_timeout to close idle sessions (Li Japin) §
This is similar to idle_in_transaction_session_timeout.
Original release occurrence ·
14.0/changes/059Change checkpoint_completion_target default to 0.9 Features
Change checkpoint_completion_target default to 0.9 (Stephen Frost) §
The previous default was 0.5.
Original release occurrence ·
14.0/changes/060Allow %P in log_line_prefix to report the parallel group leader's PID for a parallel worker Features
Allow
%Pin log_line_prefix to report the parallel group leader's PID for a parallel worker (Justin Pryzby) §Original release occurrence ·
14.0/changes/061Allow unix_socket_directories to specify paths as individual, comma-separated quoted strings Features
Allow unix_socket_directories to specify paths as individual, comma-separated quoted strings (Ian Lawrence Barwick) §
Previously all the paths had to be in a single quoted string.
Original release occurrence ·
14.0/changes/062Allow startup allocation of dynamic shared memory Features
Allow startup allocation of dynamic shared memory (Thomas Munro) §
This is controlled by min_dynamic_shared_memory. This allows more use of huge pages.
Original release occurrence ·
14.0/changes/063Add server parameter huge_page_size to control the size of huge pages used on Linux Features
Add server parameter huge_page_size to control the size of huge pages used on Linux (Odin Ugedal) §
Original release occurrence ·
14.0/changes/064Allow standby servers to be rewound via pg_rewind Features
Original release occurrence ·
14.0/changes/065Allow the restore_command setting to be changed during a server reload Features
Allow the restore_command setting to be changed during a server reload (Sergei Kornilov) §
You can also set
restore_commandto an empty string and reload to force recovery to only read from thepg_waldirectory.Original release occurrence ·
14.0/changes/066Add server parameter log_recovery_conflict_waits to report long recovery conflict wait times Features
Add server parameter log_recovery_conflict_waits to report long recovery conflict wait times (Bertrand Drouvot, Masahiko Sawada) § §
Original release occurrence ·
14.0/changes/067Pause recovery on a hot standby server if the primary changes its parameters in a way that prevents replay on the standby Features
Pause recovery on a hot standby server if the primary changes its parameters in a way that prevents replay on the standby (Peter Eisentraut) §
Previously the standby would shut down immediately.
Original release occurrence ·
14.0/changes/068Add function pg_get_wal_replay_pause_state() to report the recovery state Features
Add function
pg_get_wal_replay_pause_state()to report the recovery state (Dilip Kumar) §It gives more detailed information than
pg_is_wal_replay_paused(), which still exists.Original release occurrence ·
14.0/changes/069Add new read-only server parameter in_hot_standby Features
Add new read-only server parameter in_hot_standby (Haribabu Kommi, Greg Nancarrow, Tom Lane) §
This allows clients to easily detect whether they are connected to a hot standby server.
Original release occurrence ·
14.0/changes/070Speed truncation of small tables during recovery on clusters with a large number of shared buffers Features
Speed truncation of small tables during recovery on clusters with a large number of shared buffers (Kirk Jamison) §
Original release occurrence ·
14.0/changes/071Allow file system sync at the start of crash recovery on Linux Features
Allow file system sync at the start of crash recovery on Linux (Thomas Munro) §
By default, PostgreSQL opens and fsyncs each data file in the database cluster at the start of crash recovery. A new setting, recovery_init_sync_method
=syncfs, instead syncs each filesystem used by the cluster. This allows for faster recovery on systems with many database files.Original release occurrence ·
14.0/changes/072Add function pg_xact_commit_timestamp_origin() to return the commit timestamp and replication origin of the specified transaction Features
Add function
pg_xact_commit_timestamp_origin()to return the commit timestamp and replication origin of the specified transaction (Movead Li) §Original release occurrence ·
14.0/changes/073Add the replication origin to the record returned by pg_last_committed_xact() Features
Add the replication origin to the record returned by
pg_last_committed_xact()(Movead Li) §Original release occurrence ·
14.0/changes/074Allow replication origin functions to be controlled using standard function permission controls Features
Allow replication origin functions to be controlled using standard function permission controls (Martín Marqués) §
Previously these functions could only be executed by superusers, and this is still the default.
Original release occurrence ·
14.0/changes/075Allow logical replication to stream long in-progress transactions to subscribers Features
Allow logical replication to stream long in-progress transactions to subscribers (Dilip Kumar, Amit Kapila, Ajin Cherian, Tomas Vondra, Nikhil Sontakke, Stas Kelvich) § § § §
Previously transactions that exceeded logical_decoding_work_mem were written to disk until the transaction completed.
Original release occurrence ·
14.0/changes/076Enhance the logical replication API to allow streaming large in-progress transactions Features
Enhance the logical replication API to allow streaming large in-progress transactions (Tomas Vondra, Dilip Kumar, Amit Kapila) §
The output functions begin with
stream. test_decoding also supports these.Original release occurrence ·
14.0/changes/077Allow multiple transactions during table sync in logical replication Features
Allow multiple transactions during table sync in logical replication (Peter Smith, Amit Kapila, Takamichi Osumi) §
Original release occurrence ·
14.0/changes/078Immediately WAL-log subtransaction and top-level XID association Features
Immediately WAL-log subtransaction and top-level
XIDassociation (Tomas Vondra, Dilip Kumar, Amit Kapila) §This is useful for logical decoding.
Original release occurrence ·
14.0/changes/079Enhance logical decoding APIs to handle two-phase commits Features
Enhance logical decoding APIs to handle two-phase commits (Ajin Cherian, Amit Kapila, Nikhil Sontakke, Stas Kelvich) § § §
This is controlled via
pg_create_logical_replication_slot().Original release occurrence ·
14.0/changes/080Add cache invalidation messages to the WAL during command completion when using logical replication Features
Add cache invalidation messages to the WAL during command completion when using logical replication (Dilip Kumar, Tomas Vondra, Amit Kapila) §
This allows logical streaming of in-progress transactions. When logical replication is disabled, invalidation messages are generated only at transaction completion.
Original release occurrence ·
14.0/changes/081Allow logical decoding to more efficiently process cache invalidation messages Features
Allow logical decoding to more efficiently process cache invalidation messages (Dilip Kumar) §
This allows logical decoding to work efficiently in presence of a large amount of DDL.
Original release occurrence ·
14.0/changes/082Allow control over whether logical decoding messages are sent to the replication stream Features
Allow control over whether logical decoding messages are sent to the replication stream (David Pirotte, Euler Taveira) §
Original release occurrence ·
14.0/changes/083Allow logical replication subscriptions to use binary transfer mode Features
Allow logical replication subscriptions to use binary transfer mode (Dave Cramer) §
This is faster than text mode, but slightly less robust.
Original release occurrence ·
14.0/changes/084Allow logical decoding to be filtered by xid Features
Allow logical decoding to be filtered by xid (Markus Wanner) §
Original release occurrence ·
14.0/changes/085Reduce the number of keywords that can't be used as column labels without AS Features
Reduce the number of keywords that can't be used as column labels without
AS(Mark Dilger) §There are now 90% fewer restricted keywords.
Original release occurrence ·
14.0/changes/086Allow an alias to be specified for JOIN's USING clause Features
Allow an alias to be specified for
JOIN'sUSINGclause (Peter Eisentraut) §The alias is created by writing
ASafter theUSINGclause. It can be used as a table qualification for the mergedUSINGcolumns.Original release occurrence ·
14.0/changes/087Allow DISTINCT to be added to GROUP BY to remove duplicate GROUPING SET combinations Features
Allow
DISTINCTto be added toGROUP BYto remove duplicateGROUPING SETcombinations (Vik Fearing) §For example,
GROUP BY CUBE (a,b), CUBE (b,c)will generate duplicate grouping combinations withoutDISTINCT.Original release occurrence ·
14.0/changes/088Properly handle DEFAULT entries in multi-row VALUES lists in INSERT Features
Properly handle
DEFAULTentries in multi-rowVALUESlists inINSERT(Dean Rasheed) §Such cases used to throw an error.
Original release occurrence ·
14.0/changes/089Add SQL-standard SEARCH and CYCLE clauses for common table expressions Features
Add SQL-standard
SEARCHandCYCLEclauses for common table expressions (Peter Eisentraut) § §The same results could be accomplished using existing syntax, but much less conveniently.
Original release occurrence ·
14.0/changes/090Allow column names in the WHERE clause of ON CONFLICT to be table-qualified Features
Allow column names in the
WHEREclause ofON CONFLICTto be table-qualified (Tom Lane) §Only the target table can be referenced, however.
Original release occurrence ·
14.0/changes/091Allow REFRESH MATERIALIZED VIEW to use parallelism Features
Allow
REFRESH MATERIALIZED VIEWto use parallelism (Bharath Rupireddy) §Original release occurrence ·
14.0/changes/092Allow REINDEX to change the tablespace of the new index Features
Allow
REINDEXto change the tablespace of the new index (Alexey Kondratov, Michael Paquier, Justin Pryzby) § §This is done by specifying a
TABLESPACEclause. A--tablespaceoption was also added to reindexdb to control this.Original release occurrence ·
14.0/changes/093Allow REINDEX to process all child tables or indexes of a partitioned relation Features
Allow
REINDEXto process all child tables or indexes of a partitioned relation (Justin Pryzby, Michael Paquier) §Original release occurrence ·
14.0/changes/094Allow index commands using CONCURRENTLY to avoid waiting for the completion of other operations using CONCURRENTLY Features
Allow index commands using
CONCURRENTLYto avoid waiting for the completion of other operations usingCONCURRENTLY(Álvaro Herrera) § § §Original release occurrence ·
14.0/changes/095Improve the performance of COPY FROM in binary mode Performance
Original release occurrence ·
14.0/changes/096Preserve SQL standard syntax for SQL-defined functions in view definitions Features
Preserve SQL standard syntax for SQL-defined functions in view definitions (Tom Lane) §
Previously, calls to SQL-standard functions such as
EXTRACT()were shown in plain function-call syntax. The original syntax is now preserved when displaying a view or rule.Original release occurrence ·
14.0/changes/097Add the SQL-standard clause GRANTED BY to GRANT and REVOKE Features
Original release occurrence ·
14.0/changes/098Add OR REPLACE option for CREATE TRIGGER Features
Add
OR REPLACEoption forCREATE TRIGGER(Takamichi Osumi) §This allows pre-existing triggers to be conditionally replaced.
Original release occurrence ·
14.0/changes/099Allow TRUNCATE to operate on foreign tables Features
Allow
TRUNCATEto operate on foreign tables (Kazutaka Onishi, Kohei KaiGai) §The postgres_fdw module also now supports this.
Original release occurrence ·
14.0/changes/100Allow publications to be more easily added to and removed from a subscription Features
Allow publications to be more easily added to and removed from a subscription (Japin Li) §
The new syntax is
ALTER SUBSCRIPTION ... ADD/DROP PUBLICATION. This avoids having to specify all publications to add/remove entries.Original release occurrence ·
14.0/changes/101Add primary keys, unique constraints, and foreign keys to system catalogs Features
Add primary keys, unique constraints, and foreign keys to system catalogs (Peter Eisentraut) § §
These changes help GUI tools analyze the system catalogs. The existing unique indexes of catalogs now have associated
UNIQUEorPRIMARY KEYconstraints. Foreign key relationships are not actually stored or implemented as constraints, but can be obtained for display from the function pg_get_catalog_foreign_keys().Original release occurrence ·
14.0/changes/102Allow CURRENT_ROLE every place CURRENT_USER is accepted Features
Allow
CURRENT_ROLEevery placeCURRENT_USERis accepted (Peter Eisentraut) §Original release occurrence ·
14.0/changes/103Allow extensions and built-in data types to implement subscripting Features
Allow extensions and built-in data types to implement subscripting (Dmitry Dolgov) §
Previously subscript handling was hard-coded into the server, so that subscripting could only be applied to array types. This change allows subscript notation to be used to extract or assign portions of a value of any type for which the concept makes sense.
Original release occurrence ·
14.0/changes/104Allow subscripting of JSONB Features
Allow subscripting of
JSONB(Dmitry Dolgov) § § §JSONBsubscripting can be used to extract and assign to portions ofJSONBdocuments.Original release occurrence ·
14.0/changes/105Add support for multirange data types Features
Add support for multirange data types (Paul Jungwirth, Alexander Korotkov) § § § §
These are like range data types, but they allow the specification of multiple, ordered, non-overlapping ranges. An associated multirange type is automatically created for every range type.
Original release occurrence ·
14.0/changes/106Add support for the stemming of languages Armenian, Basque, Catalan, Hindi, Serbian, and Yiddish Features
Add support for the stemming of languages Armenian, Basque, Catalan, Hindi, Serbian, and Yiddish (Peter Eisentraut) § § §
Original release occurrence ·
14.0/changes/107Allow tsearch data files to have unlimited line lengths Features
Allow tsearch data files to have unlimited line lengths (Tom Lane) §
The previous limit was 4K bytes. Also remove function
t_readline().Original release occurrence ·
14.0/changes/108Add support for Infinity and -Infinity values in the numeric data type Features
Add support for
Infinityand-Infinityvalues in the numeric data type (Tom Lane) §Floating-point data types already supported these.
Original release occurrence ·
14.0/changes/109Add point operators <<| and |>> representing strictly above/below tests Features
Add point operators
<<|and|>>representing strictly above/below tests (Emre Hasegeli) §Previously these were called
>^and<^, but that naming is inconsistent with other geometric data types. The old names remain available, but may someday be removed.Original release occurrence ·
14.0/changes/110Add operators to add and subtract LSN and numeric (byte) values Features
Original release occurrence ·
14.0/changes/111Allow binary data transfer to be more forgiving of array and record OID mismatches Features
Allow binary data transfer to be more forgiving of array and record
OIDmismatches (Tom Lane) §Original release occurrence ·
14.0/changes/112Create composite array types for system catalogs Features
Create composite array types for system catalogs (Wenjing Zeng) §
User-defined relations have long had composite types associated with them, and also array types over those composite types. System catalogs now do as well. This change also fixes an inconsistency that creating a user-defined table in single-user mode would fail to create a composite array type.
Original release occurrence ·
14.0/changes/113Allow SQL-language functions and procedures to use SQL-standard function bodies Features
Allow SQL-language functions and procedures to use SQL-standard function bodies (Peter Eisentraut) §
Previously only string-literal function bodies were supported. When writing a function or procedure in SQL-standard syntax, the body is parsed immediately and stored as a parse tree. This allows better tracking of function dependencies, and can have security benefits.
Original release occurrence ·
14.0/changes/114Allow procedures to have OUT parameters Features
Allow procedures to have
OUTparameters (Peter Eisentraut) § §Original release occurrence ·
14.0/changes/115Allow some array functions to operate on a mix of compatible data types Features
Allow some array functions to operate on a mix of compatible data types (Tom Lane) §
The functions
array_append(),array_prepend(),array_cat(),array_position(),array_positions(),array_remove(),array_replace(), andwidth_bucket()now takeanycompatiblearrayinstead ofanyarrayarguments. This makes them less fussy about exact matches of argument types.Original release occurrence ·
14.0/changes/116Add SQL-standard trim_array() function Features
Add SQL-standard
trim_array()function (Vik Fearing) §This could already be done with array slices, but less easily.
Original release occurrence ·
14.0/changes/117Add bytea equivalents of ltrim() and rtrim() Features
Original release occurrence ·
14.0/changes/118Support negative indexes in split_part() Features
Support negative indexes in
split_part()(Nikhil Benesch) §Negative values start from the last field and count backward.
Original release occurrence ·
14.0/changes/119Add string_to_table() function to split a string on delimiters Features
Add
string_to_table()function to split a string on delimiters (Pavel Stehule) §This is similar to the
regexp_split_to_table()function.Original release occurrence ·
14.0/changes/120Add unistr() function to allow Unicode characters to be specified as backslash-hex escapes in strings Features
Add
unistr()function to allow Unicode characters to be specified as backslash-hex escapes in strings (Pavel Stehule) §This is similar to how Unicode can be specified in literal strings.
Original release occurrence ·
14.0/changes/121Add bit_xor() XOR aggregate function Features
Original release occurrence ·
14.0/changes/122Add function bit_count() to return the number of bits set in a bit or byte string Features
Add function
bit_count()to return the number of bits set in a bit or byte string (David Fetter) §Original release occurrence ·
14.0/changes/123Add date_bin() function Features
Add
date_bin()function (John Naylor) § §This function “bins” input timestamps, grouping them into intervals of a uniform length aligned with a specified origin.
Original release occurrence ·
14.0/changes/124Allow make_timestamp()/make_timestamptz() to accept negative years Features
Allow
make_timestamp()/make_timestamptz()to accept negative years (Peter Eisentraut) §Negative values are interpreted as
BCyears.Original release occurrence ·
14.0/changes/125Add newer regular expression substring() syntax Features
Add newer regular expression
substring()syntax (Peter Eisentraut) §The new SQL-standard syntax is
SUBSTRING(text SIMILAR pattern ESCAPE escapechar). The previous standard syntax wasSUBSTRING(text FROM pattern FOR escapechar), which is still accepted by PostgreSQL.Original release occurrence ·
14.0/changes/126Allow complemented character class escapes \D, \S, and \W within regular expression brackets Features
Allow complemented character class escapes \D,
\S, and\Wwithin regular expression brackets (Tom Lane) §Original release occurrence ·
14.0/changes/127Add [[:word:]] as a regular expression character class, equivalent to \w Features
Add
[[:word:]]as a regular expression character class, equivalent to\w(Tom Lane) §Original release occurrence ·
14.0/changes/128Allow more flexible data types for default values of lead() and lag() window functions Features
Allow more flexible data types for default values of
lead()andlag()window functions (Vik Fearing) §Original release occurrence ·
14.0/changes/129Make non-zero floating-point values divided by infinity return zero Features
Make non-zero floating-point values divided by infinity return zero (Kyotaro Horiguchi) §
Previously such operations produced underflow errors.
Original release occurrence ·
14.0/changes/130Make floating-point division of NaN by zero return NaN Features
Make floating-point division of NaN by zero return NaN (Tom Lane) §
Previously this returned an error.
Original release occurrence ·
14.0/changes/131Cause exp() and power() for negative-infinity exponents to return zero Features
Cause
exp()andpower()for negative-infinity exponents to return zero (Tom Lane) § § §Previously they often returned underflow errors.
Original release occurrence ·
14.0/changes/132Improve the accuracy of geometric computations involving infinity Features
Improve the accuracy of geometric computations involving infinity (Tom Lane) §
Original release occurrence ·
14.0/changes/133Mark built-in type coercion functions as leakproof where possible Features
Mark built-in type coercion functions as leakproof where possible (Tom Lane) §
This allows more use of functions that require type conversion in security-sensitive situations.
Original release occurrence ·
14.0/changes/134Change pg_describe_object(), pg_identify_object(), and pg_identify_object_as_address() to always report helpful error messages for non-existent objects Features
Change
pg_describe_object(),pg_identify_object(), andpg_identify_object_as_address()to always report helpful error messages for non-existent objects (Michael Paquier) §Original release occurrence ·
14.0/changes/135Improve PL/pgSQL's expression and assignment parsing Features
Improve PL/pgSQL's expression and assignment parsing (Tom Lane) §
This change allows assignment to array slices and nested record fields.
Original release occurrence ·
14.0/changes/136Allow plpgsql's RETURN QUERY to execute its query using parallelism Features
Allow plpgsql's
RETURN QUERYto execute its query using parallelism (Tom Lane) §Original release occurrence ·
14.0/changes/137Improve performance of repeated CALLs within plpgsql procedures Performance
Original release occurrence ·
14.0/changes/138Add pipeline mode to libpq Features
Add pipeline mode to libpq (Craig Ringer, Matthieu Garrigues, Álvaro Herrera) §
This allows multiple queries to be sent, only waiting for completion when a specific synchronization message is sent.
Original release occurrence ·
14.0/changes/139Enhance libpq's target_session_attrs parameter options Features
Enhance libpq's
target_session_attrsparameter options (Haribabu Kommi, Greg Nancarrow, Vignesh C, Tom Lane) § §The new options are
read-only,primary,standby, andprefer-standby.Original release occurrence ·
14.0/changes/140Improve the output format of libpq's PQtrace() Features
Original release occurrence ·
14.0/changes/141Allow an ECPG SQL identifier to be linked to a specific connection Features
Allow an ECPG SQL identifier to be linked to a specific connection (Hayato Kuroda) §
This is done via
DECLARE ... STATEMENT.Original release occurrence ·
14.0/changes/142Allow vacuumdb to skip index cleanup and truncation Features
Allow vacuumdb to skip index cleanup and truncation (Nathan Bossart) §
The options are
--no-index-cleanupand--no-truncate.Original release occurrence ·
14.0/changes/143Allow pg_dump to dump only certain extensions Features
Allow pg_dump to dump only certain extensions (Guillaume Lelarge) §
This is controlled by option
--extension.Original release occurrence ·
14.0/changes/144Add pgbench permute() function to randomly shuffle values Features
Add pgbench
permute()function to randomly shuffle values (Fabien Coelho, Hironobu Suzuki, Dean Rasheed) §Original release occurrence ·
14.0/changes/145Include disconnection times in the reconnection overhead measured by pgbench with -C Features
Include disconnection times in the reconnection overhead measured by pgbench with
-C(Yugo Nagata) §Original release occurrence ·
14.0/changes/146Allow multiple verbose option specifications (-v) to increase the logging verbosity Features
Allow multiple verbose option specifications (
-v) to increase the logging verbosity (Tom Lane) §This behavior is supported by pg_dump, pg_dumpall, and pg_restore.
Original release occurrence ·
14.0/changes/147Allow psql's \df and \do commands to specify function and operator argument types Features
Allow psql's
\dfand\docommands to specify function and operator argument types (Greg Sabino Mullane, Tom Lane) §This helps reduce the number of matches printed for overloaded names.
Original release occurrence ·
14.0/changes/148Add an access method column to psql's \d[i|m|t]+ output Features
Add an access method column to psql's
\d[i|m|t]+output (Georgios Kokolatos) §Original release occurrence ·
14.0/changes/149Allow psql's \dt and \di to show TOAST tables and their indexes Features
Allow psql's
\dtand\dito show TOAST tables and their indexes (Justin Pryzby) §Original release occurrence ·
14.0/changes/150Add psql command \dX to list extended statistics objects Features
Add psql command
\dXto list extended statistics objects (Tatsuro Yamada) §Original release occurrence ·
14.0/changes/151Fix psql's \dT to understand array syntax and backend grammar aliases, like int for integer Bug fixes
Fix psql's
\dTto understand array syntax and backend grammar aliases, likeintforinteger(Greg Sabino Mullane, Tom Lane) §Original release occurrence ·
14.0/changes/152When editing the previous query or a file with psql's \e, or using \ef and \ev, ignore the results if the editor exits without saving Features
When editing the previous query or a file with psql's
\e, or using\efand\ev, ignore the results if the editor exits without saving (Laurenz Albe) §Previously, such edits would load the previous query into the query buffer, and typically execute it immediately. This was deemed to be probably not what the user wants.
Original release occurrence ·
14.0/changes/153Add command-line utility pg_amcheck to simplify running contrib/amcheck tests on many relations Features
Add command-line utility pg_amcheck to simplify running
contrib/amchecktests on many relations (Mark Dilger) §Original release occurrence ·
14.0/changes/155Add --no-instructions option to initdb Features
Add
--no-instructionsoption to initdb (Magnus Hagander) §This suppresses the server startup instructions that are normally printed.
Original release occurrence ·
14.0/changes/156Stop pg_upgrade from creating analyze_new_cluster script Features
Stop pg_upgrade from creating
analyze_new_clusterscript (Magnus Hagander) §Instead, give comparable vacuumdb instructions.
Original release occurrence ·
14.0/changes/157Remove support for the postmaster -o option Features
Remove support for the postmaster
-ooption (Magnus Hagander) §This option was unnecessary since all passed options could already be specified directly.
Original release occurrence ·
14.0/changes/158Rename "Default Roles" to "Predefined Roles" Features
Rename "Default Roles" to "Predefined Roles" (Bruce Momjian, Stephen Frost) §
Original release occurrence ·
14.0/changes/159Add documentation for the factorial() function Features
Add documentation for the
factorial()function (Peter Eisentraut) §With the removal of the ! operator in this release,
factorial()is the only built-in way to compute a factorial.Original release occurrence ·
14.0/changes/160Add configure option --with-ssl={openssl} to allow future choice of the SSL library to use Features
Add configure option
--with-ssl={openssl}to allow future choice of the SSL library to use (Daniel Gustafsson, Michael Paquier) §The spelling
--with-opensslis kept for compatibility.Original release occurrence ·
14.0/changes/161Add support for abstract Unix-domain sockets Features
Add support for abstract Unix-domain sockets (Peter Eisentraut) §
This is currently supported on Linux and Windows.
Original release occurrence ·
14.0/changes/162Allow Windows to properly handle files larger than four gigabytes Features
Allow Windows to properly handle files larger than four gigabytes (Juan José Santamaría Flecha) §
For example this allows
COPY,WAL files, and relation segment files to be larger than four gigabytes.Original release occurrence ·
14.0/changes/163Add server parameter debug_discard_caches to control cache flushing for test purposes Features
Add server parameter debug_discard_caches to control cache flushing for test purposes (Craig Ringer) § § §
Previously this behavior could only be set at compile time. To invoke it during initdb, use the new option
--discard-caches.Original release occurrence ·
14.0/changes/164Various improvements in valgrind error detection ability Features
Original release occurrence ·
14.0/changes/165Add a test module for the regular expression package Features
Add a test module for the regular expression package (Tom Lane) §
Original release occurrence ·
14.0/changes/166Add support for LLVM version 12 Features
Add support for LLVM version 12 (Andres Freund) §
Original release occurrence ·
14.0/changes/167Change SHA1, SHA2, and MD5 hash computations to use the OpenSSL EVP API Features
Change SHA1, SHA2, and MD5 hash computations to use the OpenSSL EVP API (Michael Paquier) § § § §
This is more modern and supports FIPS mode.
Original release occurrence ·
14.0/changes/168Remove separate build-time control over the choice of random number generator Features
Remove separate build-time control over the choice of random number generator (Daniel Gustafsson) §
This is now always determined by the choice of SSL library.
Original release occurrence ·
14.0/changes/169Add direct conversion routines between EUC_TW and Big5 encodings Features
Add direct conversion routines between EUC_TW and Big5 encodings (Heikki Linnakangas) §
Original release occurrence ·
14.0/changes/170Add collation version support for FreeBSD Features
Add collation version support for FreeBSD (Thomas Munro) §
Original release occurrence ·
14.0/changes/171Add amadjustmembers to the index access method API Features
Add
amadjustmembersto the index access method API (Tom Lane) §This allows an index access method to provide validity checking during creation of a new operator class or family.
Original release occurrence ·
14.0/changes/172Provide feature-test macros in libpq-fe.h for recently-added libpq features Features
Provide feature-test macros in
libpq-fe.hfor recently-added libpq features (Tom Lane, Álvaro Herrera) §Historically, applications have usually used compile-time checks of
PG_VERSION_NUMto test whether a feature is available. But that's normally the server version, which might not be a good guide to libpq's version.libpq-fe.hnow offers#definesymbols denoting application-visible features added in v14; the intent is to keep adding symbols for such features in future versions.Original release occurrence ·
14.0/changes/173Allow subscripting of hstore values Features
Original release occurrence ·
14.0/changes/174Allow GiST/GIN pg_trgm indexes to do equality lookups Features
Allow GiST/GIN pg_trgm indexes to do equality lookups (Julien Rouhaud) §
This is similar to
LIKEexcept no wildcards are honored.Original release occurrence ·
14.0/changes/175Allow the cube data type to be transferred in binary mode Features
Original release occurrence ·
14.0/changes/176Allow pgstattuple_approx() to report on TOAST tables Features
Allow
pgstattuple_approx()to report on TOAST tables (Peter Eisentraut) §Original release occurrence ·
14.0/changes/177Add contrib module pg_surgery which allows changes to row visibility Features
Add contrib module pg_surgery which allows changes to row visibility (Ashutosh Sharma) §
This is useful for correcting database corruption.
Original release occurrence ·
14.0/changes/178Add contrib module old_snapshot to report the XID/time mapping used by an active old_snapshot_threshold Features
Add contrib module old_snapshot to report the
XID/time mapping used by an active old_snapshot_threshold (Robert Haas) §Original release occurrence ·
14.0/changes/179Allow amcheck to also check heap pages Features
Allow amcheck to also check heap pages (Mark Dilger) §
Previously it only checked B-Tree index pages.
Original release occurrence ·
14.0/changes/180Allow pageinspect to inspect GiST indexes Features
Allow pageinspect to inspect GiST indexes (Andrey Borodin, Heikki Linnakangas) § §
Original release occurrence ·
14.0/changes/181Change pageinspect block numbers to be bigints Features
Original release occurrence ·
14.0/changes/182Mark btree_gist functions as parallel safe Features
Mark btree_gist functions as parallel safe (Steven Winfield) §
Original release occurrence ·
14.0/changes/183Move query hash computation from pg_stat_statements to the core server Features
Move query hash computation from pg_stat_statements to the core server (Julien Rouhaud) §
The new server parameter compute_query_id's default of
autowill automatically enable query id computation when this extension is loaded.Original release occurrence ·
14.0/changes/184Cause pg_stat_statements to track top and nested statements separately Features
Cause pg_stat_statements to track top and nested statements separately (Julien Rohaud) §
Previously, when tracking all statements, identical top and nested statements were tracked as a single entry; but it seems more useful to separate such usages.
Original release occurrence ·
14.0/changes/185Add row counts for utility commands to pg_stat_statements Features
Add row counts for utility commands to pg_stat_statements (Fujii Masao, Katsuragi Yuta, Seino Yuki) § §
Original release occurrence ·
14.0/changes/186Add pg_stat_statements_info system view to show pg_stat_statements activity Features
Add
pg_stat_statements_infosystem view to show pg_stat_statements activity (Katsuragi Yuta, Yuki Seino, Naoki Nakamichi) § §Original release occurrence ·
14.0/changes/187Allow postgres_fdw to INSERT rows in bulk Features
Original release occurrence ·
14.0/changes/188Allow postgres_fdw to import table partitions if specified by IMPORT FOREIGN SCHEMA ... LIMIT TO Features
Allow postgres_fdw to import table partitions if specified by
IMPORT FOREIGN SCHEMA ... LIMIT TO(Matthias van de Meent) §By default, only the root of a partitioned table is imported.
Original release occurrence ·
14.0/changes/189Add postgres_fdw function postgres_fdw_get_connections() to report open foreign server connections Features
Add postgres_fdw function
postgres_fdw_get_connections()to report open foreign server connections (Bharath Rupireddy) §Original release occurrence ·
14.0/changes/190Allow control over whether foreign servers keep connections open after transaction completion Features
Allow control over whether foreign servers keep connections open after transaction completion (Bharath Rupireddy) §
This is controlled by
keep_connectionsand defaults to on.Original release occurrence ·
14.0/changes/191Allow postgres_fdw to reestablish foreign server connections if necessary Features
Allow postgres_fdw to reestablish foreign server connections if necessary (Bharath Rupireddy) § §
Previously foreign server restarts could cause foreign table access errors.
Original release occurrence ·
14.0/changes/192Add postgres_fdw functions to discard cached connections Features
Add postgres_fdw functions to discard cached connections (Bharath Rupireddy) §
Original release occurrence ·
14.0/changes/193
Security evidence
67 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.
CVE-2026-6637 · PostgreSQL refint allows stack buffer overflow and SQL injection CVSS 8.8
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 14.23. Component: contrib module.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6479 · PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion CVSS 7.5
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 14.23. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2026-6478 · PostgreSQL discloses MD5-hashed passwords via covert timing channel CVSS 6.5
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 14.23. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-6477 · PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory CVSS 8.8
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 14.23. Component: client.
Official affected-branch entry: 14.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6475 · PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice CVSS 8.8
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 14.23. Component: client.
Official affected-branch entry: 14.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6474 · PostgreSQL timeofday() can disclose portions of server memory CVSS 4.3
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 14.23. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-6473 · PostgreSQL server undersizes allocations, via integer wraparound CVSS 8.8
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 14.23. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
- 14.24: Fix integer overflows in memory-allocation calculations in PL/Perl and PL/Tcl
- 14.23: Fix assorted integer overflows in memory-allocation calculations
- 14.23: Reject over-length options in ts_headline()
- 14.23: Guard against field overflow within contrib/intarray's query_int type and contrib/ltree's ltxtquery type
- 14.23: Guard against overly long values of contrib/ltree's lquery type
CVE-2026-6472 · PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege CVSS 5.4
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 14.23. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-6471 · PostgreSQL logical decoding can dlopen arbitrary file CVSS 7.2
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6470 · PostgreSQL fails to check type USAGE privilege CVSS 4.3
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2026-6469 · PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership CVSS 3.8
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Release-note mentions:
CVE-2026-6464 · PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands CVSS 8.1
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: client.
Official affected-branch entry: 14.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2006 · PostgreSQL missing validation of multibyte character length executes arbitrary code CVSS 8.8
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 14.21. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2005 · PostgreSQL pgcrypto heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 14.21. Component: contrib module.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2004 · PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code CVSS 8.8
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 14.21. Component: contrib module.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2003 · PostgreSQL oidvector discloses a few bytes of memory CVSS 4.3
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 14.21. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-19385 · PostgreSQL pg_dump heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: client.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-18408 · PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: client.
Official affected-branch entry: 14.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-18024 · PostgreSQL ascii() function reads past end of buffer CVSS 4.3
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-16241 · PostgreSQL ECPG integer underflow can crash the client CVSS 3.8
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: client.
Official affected-branch entry: 14.
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Release-note mentions:
CVE-2026-16239 · PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code CVSS 8.8
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-16238 · PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code CVSS 8.8
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-15742 · PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound CVSS 8.8
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: contrib module.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-15741 · PostgreSQL expression deparse allows SQL injection via EXTRACT argument CVSS 8.8
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14681 · PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL CVSS 4.2
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14680 · PostgreSQL type confusion via "internal" arguments CVSS 8.8
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14679 · PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory CVSS 8.2
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Release-note mentions:
CVE-2026-14678 · PostgreSQL pg_trgm picksplit reads past end of buffer CVSS 4.3
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: contrib module.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-14677 · PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound CVSS 8.8
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14676 · PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
No fixed version for this branch is recorded. Component: contrib module.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14673 · PostgreSQL amcheck does not clear untrusted search path CVSS 3.8
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.
Fixed in this branch: 14.24. Component: contrib module.
Official affected-branch entry: 14.
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14672 · PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle CVSS 5.3
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-14671 · PostgreSQL refint plan cache type confusion executes arbitrary code CVSS 8.8
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: contrib module.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14670 · PostgreSQL plperl tied object heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14669 · PostgreSQL to_char heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14668 · PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read CVSS 8.1
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Release-note mentions:
CVE-2026-14666 · PostgreSQL row security caching disregards role modifications CVSS 4.2
Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14664 · PostgreSQL regexp heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14663 · PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext CVSS 6.5
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: contrib module.
Official affected-branch entry: 14.
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14662 · PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound CVSS 8.8
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 14.24. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2025-8715 · PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server CVSS 8.8
Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.
Fixed in this branch: 14.19. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
Fixed in this branch: 14.19. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2025-8713 · PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table CVSS 3.1
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
Fixed in this branch: 14.19. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2025-4207 · PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation CVSS 5.9
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
Fixed in this branch: 14.18. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound CVSS 5.9
Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
Fixed in this branch: 14.20. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege CVSS 3.1
Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
Fixed in this branch: 14.20. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2025-1094 · PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation CVSS 8.1
Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.
Fixed in this branch: 14.16. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-7348 · PostgreSQL relation replacement during pg_dump executes arbitrary SQL CVSS 8.8
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected. The PostgreSQL project thanks Noah Misch for reporting this problem.
Fixed in this branch: 14.13. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-4317 · Restrict visibility of "pg_stats_ext" and "pg_stats_ext_exprs" entries to the table owner CVSS 3.1
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes, which are provided as a convenience in the below section. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected. This fix only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after this fix is applied. If you have a current PostgreSQL installation and are concerned about this issue, please use the following remediation steps to fix the issue: From the above URLs, you can click the URL that says "raw" to download a version that you can copy and paste. Be sure to use the script appropriate to your PostgreSQL major version. If you do not see this file, either your version is not vulnerable (only PostgreSQL 14, 15, and 16 are affected) or your minor version is too old to have the fix. \i /usr/share/postgresql/fix-CVE-2024-4317.sql ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; After executing the fix-CVE-2024-4317.sql script in template0 and template1 , you should revoke the ability for template0 to accept connections. You can do this with the following command: ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; The PostgreSQL project thanks Lukas Fittl for reporting this problem.
Fixed in this branch: 14.12. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code CVSS 8.8
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.
Fixed in this branch: 14.14. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID CVSS 4.2
Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 14.14. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle CVSS 3.1
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 14.14. Component: client.
Official affected-branch entry: 14.
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes CVSS 4.2
Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
Fixed in this branch: 14.14. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2024-0985 · PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL CVSS 8.0
UPDATE (June 19, 2024) : Added v16 as impacted. Updated description to clarify the attack vector. Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view.
Fixed in this branch: 14.11. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes CVSS 2.2
Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.
Fixed in this branch: 14.10. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2023-5869 · Buffer overrun from integer overflow in array modification CVSS 8.8
While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.
Fixed in this branch: 14.10. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-5868 · Memory disclosure in aggregate function calls CVSS 4.3
Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.
Fixed in this branch: 14.10. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection CVSS 7.5
An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.
Fixed in this branch: 14.9. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-2455 · Row security policies disregard user ID changes after inlining CVSS 4.2
While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.
Fixed in this branch: 14.8. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes CVSS 7.2
This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
Fixed in this branch: 14.8. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2022-41862 · Client memory disclosure when connecting, with Kerberos, to modified server CVSS 3.7
A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. When a libpq client application has a Kerberos credential cache and doesn't explicitly disable option gssencmode , a server can cause libpq to over-read and report an error message containing uninitialized bytes from and following its receive buffer. If libpq's caller somehow makes that message accessible to the attacker, this achieves a disclosure of the over-read bytes. We have not confirmed or ruled out viability of attacks that arrange for a crash or for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 14.7. Component: client.
Official affected-branch entry: 14.
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2022-2625 · Extension scripts replace objects not belonging to the extension CVSS 7.1
Some extensions use CREATE OR REPLACE or CREATE IF NOT EXISTS commands. Some don't adhere to the documented rule to target only objects known to be extension members already. An attack requires permission to create non-temporary objects in at least one schema, ability to lure or wait for an administrator to create or update an affected extension in that schema, and ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS . Given all three prerequisites, the attacker can run arbitrary code as the victim role, which may be a superuser. Known-affected extensions include both PostgreSQL-bundled and non-bundled extensions. PostgreSQL is blocking this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Sven Klemm for reporting this problem.
Fixed in this branch: 14.5. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2022-1552 · Autovacuum, REINDEX, and others omit "security restricted operation" sandbox CVSS 8.8
Autovacuum, REINDEX , CREATE INDEX , REFRESH MATERIALIZED VIEW , CLUSTER , and pg_amcheck made incomplete efforts to operate safely when a privileged user is maintaining another user's objects. Those commands activated relevant protections too late or not at all. An attacker having permission to create non-temp objects in at least one schema could execute arbitrary SQL functions under a superuser identity. While promptly updating PostgreSQL is the best remediation for most users, a user unable to do that can work around the vulnerability by disabling autovacuum, not manually running the above commands, and not restoring from output of the pg_dump command. Performance may degrade quickly under this workaround. VACUUM is safe, and all commands are fine when a trusted user owns the target object. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
Fixed in this branch: 14.3. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2021-23222 · libpq processes unencrypted bytes from man-in-the-middle CVSS 3.7
A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certificate verification and encryption. If more preconditions hold, the attacker can exfiltrate the client's password or other confidential data that might be transmitted early in a session. The attacker must have a way to trick the client's intended server into making the confidential data accessible to the attacker. A known implementation having that property is a PostgreSQL configuration vulnerable to CVE-2021-23214 . As with any exploitation of CVE-2021-23214 , the server must be using trust authentication with a clientcert requirement or using cert authentication. To disclose a password, the client must be in possession of a password, which is atypical when using an authentication configuration vulnerable to CVE-2021-23214 . The attacker must have some other way to access the server to retrieve the exfiltrated data (a valid, unprivileged login account would be sufficient). The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 14.1. Component: client.
Official affected-branch entry: 14.
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2021-23214 · Server processes unencrypted bytes from man-in-the-middle CVSS 8.1
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. This is similar to CVE-2011-0411 (different product). The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 14.1. Component: core server.
Official affected-branch entry: 14.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2012-0868 · Line breaks in object names can be exploited to execute arbitrary SQL when reloading a pg_dump file.
No fixed version for this branch is recorded.
Release-note mentions:
Export this branch as JSON · Compare any two indexed releases