↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Versions

PostgreSQL 15

Read the English manual

Supported · Recorded build 15.19 · 2026-08-13

First stable release
2022-10-13
Support end
2027-11-11
Indexed releases
20
Original release-note entries
1046

Manuals & provenance

PostgreSQL 15 English manual · 1171 loaded pages.

Manual loaded 2026-09-27T00:10:47.078613.

Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.

Upgrade considerations

Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.

Compatibility notes for 15.0 · Changes from the initial release through 15.19

Original migration guidance for 15.0

A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 19.6 for general information on migrating to new major releases.

Version 15 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:

Release history

Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.

ReleaseDate / snapshot cutoffAll changesBug fixesMigration entriesCVE mentions
15.19 2026-08-13 9036031
15.18 2026-05-14 431708
15.17 2026-02-26 5401
15.16 2026-02-12 401704
15.15 2025-11-13 543002
15.14 2025-08-14 541705
15.13 2025-05-08 381801
15.12 2025-02-20 1001
15.11 2025-02-13 482901
15.10 2024-11-21 8401
15.9 2024-11-14 461804
15.8 2024-08-08 492502
15.7 2024-05-09 522301
15.6 2024-02-08 602201
15.5 2023-11-09 602603
15.4 2023-08-10 472202
15.3 2023-05-11 834102
15.2 2023-02-09 583001
15.1 2022-11-10 261300
15.0 2022-10-13 1843311

Initial release changes

Original entries from 15.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.

184 of 184 original entries.

  • Remove PUBLIC creation permission on the public schema Security Migration

    Remove PUBLIC creation permission on the public schema (Noah Misch) §

    The new default is one of the secure schema usage patterns that Section 5.9.6 has recommended since the security release for CVE-2018-1058. The change applies to new database clusters and to newly-created databases in existing clusters. Upgrading a cluster or restoring a database dump will preserve public's existing permissions.

    For existing databases, especially those having multiple users, consider revoking CREATE permission on the public schema to adopt this new default. For new databases having no need to defend against insider threats, granting CREATE permission will yield the behavior of prior releases.

    Original release occurrence · 15.0/migration/001

  • Change the owner of the public schema to be the new pg_database_owner role Compatibility Migration

    Change the owner of the public schema to be the new pg_database_owner role (Noah Misch) §

    This allows each database's owner to have ownership privileges on the public schema within their database. Previously it was owned by the bootstrap superuser, so that non-superuser database owners could not do anything with it.

    This change applies to new database clusters and to newly-created databases in existing clusters. Upgrading a cluster or restoring a database dump will preserve public's existing ownership specification.

    Original release occurrence · 15.0/migration/002

  • Remove long-deprecated exclusive backup mode Compatibility Migration

    Remove long-deprecated exclusive backup mode (David Steele, Nathan Bossart) §

    If the database server stops abruptly while in this mode, the server could fail to start. The non-exclusive backup mode is considered superior for all purposes. Functions pg_start_backup()/pg_stop_backup() have been renamed to pg_backup_start()/pg_backup_stop(), and the functions pg_backup_start_time() and pg_is_in_backup() have been removed.

    Original release occurrence · 15.0/migration/003

  • Increase hash_mem_multiplier default to 2.0 Compatibility Migration

    Increase hash_mem_multiplier default to 2.0 (Peter Geoghegan) §

    This allows query hash operations to use more work_mem memory than other operations.

    Original release occurrence · 15.0/migration/004

  • Remove server-side language plpython2u and generic Python language plpythonu Compatibility Migration

    Remove server-side language plpython2u and generic Python language plpythonu (Andres Freund) §

    Python 2.x is no longer supported. While the original intent of plpythonu was that it could eventually refer to plpython3u, changing it now seems more likely to cause problems than solve them, so it's just been removed.

    Original release occurrence · 15.0/migration/005

  • Generate an error if array_to_tsvector() is passed an empty-string array element Compatibility Migration

    Generate an error if array_to_tsvector() is passed an empty-string array element (Jean-Christophe Arnu) §

    This is prohibited because lexemes should never be empty. Users of previous Postgres releases should verify that no empty lexemes are stored because they can lead to dump/restore failures and inconsistent results.

    Original release occurrence · 15.0/migration/006

  • Generate an error when chr() is supplied with a negative argument Compatibility Migration

    Generate an error when chr() is supplied with a negative argument (Peter Eisentraut) §

    Original release occurrence · 15.0/migration/007

  • Prevent CREATE OR REPLACE VIEW from changing the collation of an output column Compatibility Migration

    Prevent CREATE OR REPLACE VIEW from changing the collation of an output column (Tom Lane) §

    Original release occurrence · 15.0/migration/008

  • Disallow zero-length Unicode identifiers, e.g., U&"" Compatibility Migration

    Disallow zero-length Unicode identifiers, e.g., U&"" (Peter Eisentraut) §

    Non-Unicode zero-length identifiers were already disallowed.

    Original release occurrence · 15.0/migration/009

  • Prevent numeric literals from having non-numeric trailing characters Compatibility Migration

    Prevent numeric literals from having non-numeric trailing characters (Peter Eisentraut) §

    Previously, query text like 123abc would be interpreted as 123 followed by a separate token abc.

    Original release occurrence · 15.0/migration/010

  • Adjust JSON numeric literal processing to match the SQL/JSON-standard Compatibility Migration

    Adjust JSON numeric literal processing to match the SQL/JSON-standard (Peter Eisentraut) §

    This accepts numeric formats like .1 and 1., and disallows trailing junk after numeric literals, like 1.type().

    Original release occurrence · 15.0/migration/011

  • When interval input provides a fractional value for a unit greater than months, round to the nearest month Compatibility Migration

    When interval input provides a fractional value for a unit greater than months, round to the nearest month (Bruce Momjian) §

    For example, convert 1.99 years to 2 years, not 1 year 11 months as before.

    Original release occurrence · 15.0/migration/012

  • Improve consistency of interval parsing with trailing periods Compatibility Migration

    Improve consistency of interval parsing with trailing periods (Tom Lane) §

    Numbers with trailing periods were rejected on some platforms.

    Original release occurrence · 15.0/migration/013

  • Mark the interval output function as stable, not immutable, since it depends on IntervalStyle Compatibility Migration

    Mark the interval output function as stable, not immutable, since it depends on IntervalStyle (Tom Lane) §

    This will, for example, cause creation of indexes relying on the text output of interval values to fail.

    Original release occurrence · 15.0/migration/014

  • Detect integer overflow in interval justification functions Compatibility Migration

    Detect integer overflow in interval justification functions (Joe Koshakow) §

    The affected functions are justify_interval(), justify_hours(), and justify_days().

    Original release occurrence · 15.0/migration/015

  • Change the I/O format of type "char" for non-ASCII characters Compatibility Migration

    Change the I/O format of type "char" for non-ASCII characters (Tom Lane) §

    Bytes with the high bit set are now output as a backslash and three octal digits, to avoid encoding issues.

    Original release occurrence · 15.0/migration/016

  • Remove the default ADMIN OPTION privilege a login role has on its own role membership Compatibility Migration

    Remove the default ADMIN OPTION privilege a login role has on its own role membership (Robert Haas) §

    Previously, a login role could add/remove members of its own role, even without ADMIN OPTION privilege.

    Original release occurrence · 15.0/migration/017

  • Allow logical replication to run as the owner of the subscription Compatibility Migration

    Allow logical replication to run as the owner of the subscription (Mark Dilger) §

    Because row-level security policies are not checked, only superusers, roles with bypassrls, and table owners can replicate into tables with row-level security policies.

    Original release occurrence · 15.0/migration/018

  • Prevent UPDATE and DELETE logical replication operations on tables where the subscription owner does not have SELECT permission on the table Compatibility Migration

    Prevent UPDATE and DELETE logical replication operations on tables where the subscription owner does not have SELECT permission on the table (Jeff Davis) §

    UPDATE and DELETE commands typically involve reading the table as well, so require the subscription owner to have table SELECT permission.

    Original release occurrence · 15.0/migration/019

  • When EXPLAIN references the session's temporary object schema, refer to it as pg_temp Compatibility Migration

    When EXPLAIN references the session's temporary object schema, refer to it as pg_temp (Amul Sul) §

    Previously the actual schema name was reported, leading to inconsistencies across sessions.

    Original release occurrence · 15.0/migration/020

  • Fix pg_statio_all_tables to sum values for the rare case of TOAST tables with multiple indexes Compatibility Migration

    Fix pg_statio_all_tables to sum values for the rare case of TOAST tables with multiple indexes (Andrei Zubkov) §

    Previously such cases would show one row for each index.

    Original release occurrence · 15.0/migration/021

  • Disallow setting custom options that match the name of an installed extension, but are not one of the extension's declared variables Compatibility Migration

    Disallow setting custom options that match the name of an installed extension, but are not one of the extension's declared variables (Florin Irion, Tom Lane) § § §

    This change causes any such pre-existing variables to be deleted during extension load, and then prevents new ones from being created later in the session. The intent is to prevent confusion about whether a variable is associated with an extension or not.

    Original release occurrence · 15.0/migration/022

  • Remove obsolete server variable stats_temp_directory Compatibility Migration

    Remove obsolete server variable stats_temp_directory (Andres Freund, Kyotaro Horiguchi) §

    Original release occurrence · 15.0/migration/023

  • Improve the algorithm used to compute random() Compatibility Migration

    Improve the algorithm used to compute random() (Fabien Coelho) § §

    This will cause random()'s results to differ from what was emitted by prior versions, even for the same seed value.

    Original release occurrence · 15.0/migration/024

  • libpq's PQsendQuery() function is no longer supported in pipeline mode Compatibility Migration

    libpq's PQsendQuery() function is no longer supported in pipeline mode (Álvaro Herrera) §

    Applications that are using that combination will need to be modified to use PQsendQueryParams() instead.

    Original release occurrence · 15.0/migration/025

  • On non-Windows platforms, consult the HOME environment variable to find the user's home directory Compatibility Migration

    On non-Windows platforms, consult the HOME environment variable to find the user's home directory (Anders Kaseorg) §

    If HOME is empty or unset, fall back to the previous method of checking the <pwd.h> database. This change affects libpq (for example, while looking up ~/.pgpass) as well as various client application programs.

    Original release occurrence · 15.0/migration/026

  • Remove pg_dump's --no-synchronized-snapshots option Compatibility Migration

    Remove pg_dump's --no-synchronized-snapshots option (Tom Lane) §

    All still-supported server versions support synchronized snapshots, so there's no longer a need for this option.

    Original release occurrence · 15.0/migration/027

  • After an error is detected in psql's --single-transaction mode, change the final COMMIT command to ROLLBACK only if ON_ERROR_STOP is set Compatibility Migration

    After an error is detected in psql's --single-transaction mode, change the final COMMIT command to ROLLBACK only if ON_ERROR_STOP is set (Michael Paquier) §

    Original release occurrence · 15.0/migration/028

  • Avoid unnecessary casting of constants in queries sent by postgres_fdw Compatibility Migration

    Avoid unnecessary casting of constants in queries sent by postgres_fdw (Dian Fay) §

    When column types are intentionally different between local and remote databases, such casts could cause errors.

    Original release occurrence · 15.0/migration/029

  • Remove xml2's xml_is_well_formed() function Compatibility Migration

    Remove xml2's xml_is_well_formed() function (Tom Lane) §

    This function has been implemented in the core backend since Postgres 9.1.

    Original release occurrence · 15.0/migration/030

  • Allow custom scan providers to indicate if they support projections Compatibility Migration

    Allow custom scan providers to indicate if they support projections (Sven Klemm) §

    The default is now that custom scan providers are assumed to not support projections; those that do will need to be updated for this release.

    Original release occurrence · 15.0/migration/031

  • Record and check the collation version of each database Features

    Record and check the collation version of each database (Peter Eisentraut) §

    This feature is designed to detect collation version changes to avoid index corruption. Function pg_database_collation_actual_version() reports the underlying operating system collation version, and ALTER DATABASE ... REFRESH sets the recorded database collation version to match the operating system collation version.

    Original release occurrence · 15.0/changes/001

  • Allow ICU collations to be set as the default for clusters and databases Features

    Allow ICU collations to be set as the default for clusters and databases (Peter Eisentraut) §

    Previously, only libc-based collations could be selected at the cluster and database levels. ICU collations could only be used via explicit COLLATE clauses.

    Original release occurrence · 15.0/changes/002

  • Add system view pg_ident_file_mappings to report pg_ident.conf information Features

    Add system view pg_ident_file_mappings to report pg_ident.conf information (Julien Rouhaud) §

    Original release occurrence · 15.0/changes/003

  • Improve planning time for queries referencing partitioned tables Features

    Improve planning time for queries referencing partitioned tables (David Rowley) §

    This change helps when only a few of many partitions are relevant.

    Original release occurrence · 15.0/changes/004

  • Allow ordered scans of partitions to avoid sorting in more cases Features

    Allow ordered scans of partitions to avoid sorting in more cases (David Rowley) §

    Previously, a partitioned table with a DEFAULT partition or a LIST partition containing multiple values could not be used for ordered partition scans. Now they can be used if such partitions are pruned during planning.

    Original release occurrence · 15.0/changes/005

  • Improve foreign key behavior of updates on partitioned tables that move rows between partitions Features

    Improve foreign key behavior of updates on partitioned tables that move rows between partitions (Amit Langote) §

    Previously, such updates ran a delete action on the source partition and an insert action on the target partition. PostgreSQL will now run an update action on the partition root, providing cleaner semantics.

    Original release occurrence · 15.0/changes/006

  • Allow CLUSTER on partitioned tables Features

    Allow CLUSTER on partitioned tables (Justin Pryzby) § §

    Original release occurrence · 15.0/changes/007

  • Fix ALTER TRIGGER RENAME on partitioned tables to properly rename triggers on all partitions Bug fixes

    Fix ALTER TRIGGER RENAME on partitioned tables to properly rename triggers on all partitions (Arne Roland, Álvaro Herrera) §

    Also prohibit cloned triggers from being renamed.

    Original release occurrence · 15.0/changes/008

  • Allow btree indexes on system and TOAST tables to efficiently store duplicates Features

    Allow btree indexes on system and TOAST tables to efficiently store duplicates (Peter Geoghegan) §

    Previously de-duplication was disabled for these types of indexes.

    Original release occurrence · 15.0/changes/009

  • Improve lookup performance of GiST indexes that were built using sorting Performance

    Improve lookup performance of GiST indexes that were built using sorting (Aliaksandr Kalenik, Sergei Shoulbakov, Andrey Borodin) §

    Original release occurrence · 15.0/changes/010

  • Allow unique constraints and indexes to treat NULL values as not distinct Features

    Allow unique constraints and indexes to treat NULL values as not distinct (Peter Eisentraut) §

    Previously NULL entries were always treated as distinct values, but this can now be changed by creating constraints and indexes using UNIQUE NULLS NOT DISTINCT.

    Original release occurrence · 15.0/changes/011

  • Allow the ^@ starts-with operator and the starts_with() function to use btree indexes if using the C collation Features

    Allow the ^@ starts-with operator and the starts_with() function to use btree indexes if using the C collation (Tom Lane) §

    Previously these could only use SP-GiST indexes.

    Original release occurrence · 15.0/changes/012

  • Allow extended statistics to record statistics for a parent with all its children Features

    Allow extended statistics to record statistics for a parent with all its children (Tomas Vondra, Justin Pryzby) §

    Regular statistics already tracked parent and parent-plus-all-children statistics separately.

    Original release occurrence · 15.0/changes/013

  • Add server variable recursive_worktable_factor to allow the user to specify the expected size of the working table of a recursive query Features

    Add server variable recursive_worktable_factor to allow the user to specify the expected size of the working table of a recursive query (Simon Riggs) §

    Original release occurrence · 15.0/changes/014

  • Allow hash lookup for NOT IN clauses with many constants Performance

    Allow hash lookup for NOT IN clauses with many constants (David Rowley, James Coleman) §

    Previously the code always sequentially scanned the list of values.

    Original release occurrence · 15.0/changes/015

  • Allow SELECT DISTINCT to be parallelized Performance

    Allow SELECT DISTINCT to be parallelized (David Rowley) §

    Original release occurrence · 15.0/changes/016

  • Speed up encoding validation of UTF-8 text by processing 16 bytes at a time Performance

    Speed up encoding validation of UTF-8 text by processing 16 bytes at a time (John Naylor, Heikki Linnakangas) §

    This will improve text-heavy operations like COPY FROM.

    Original release occurrence · 15.0/changes/017

  • Improve performance for sorts that exceed work_mem Performance

    Improve performance for sorts that exceed work_mem (Heikki Linnakangas) § §

    When the sort data no longer fits in work_mem, switch to a batch sorting algorithm that uses more output streams than before.

    Original release occurrence · 15.0/changes/018

  • Improve performance and reduce memory consumption of in-memory sorts Performance

    Improve performance and reduce memory consumption of in-memory sorts (Ronan Dunklau, David Rowley, Thomas Munro, John Naylor) § § §

    Original release occurrence · 15.0/changes/019

  • Allow WAL full page writes to use LZ4 and Zstandard compression Performance

    Allow WAL full page writes to use LZ4 and Zstandard compression (Andrey Borodin, Justin Pryzby) § §

    This is controlled by the wal_compression server setting.

    Original release occurrence · 15.0/changes/020

  • Add support for writing WAL using direct I/O on macOS Performance

    Add support for writing WAL using direct I/O on macOS (Thomas Munro) §

    This only works if max_wal_senders = 0 and wal_level = minimal.

    Original release occurrence · 15.0/changes/021

  • Allow vacuum to be more aggressive in setting the oldest frozen and multi transaction id Performance

    Allow vacuum to be more aggressive in setting the oldest frozen and multi transaction id (Peter Geoghegan) §

    Original release occurrence · 15.0/changes/022

  • Allow a query referencing multiple foreign tables to perform parallel foreign table scans in more cases Performance

    Allow a query referencing multiple foreign tables to perform parallel foreign table scans in more cases (Andrey Lepikhov, Etsuro Fujita) §

    Original release occurrence · 15.0/changes/023

  • Improve the performance of window functions that use row_number(), rank(), dense_rank() and count() Performance

    Improve the performance of window functions that use row_number(), rank(), dense_rank() and count() (David Rowley) §

    Original release occurrence · 15.0/changes/024

  • Improve the performance of spinlocks on high-core-count ARM64 systems Performance

    Improve the performance of spinlocks on high-core-count ARM64 systems (Geoffrey Blake) §

    Original release occurrence · 15.0/changes/025

  • Enable default logging of checkpoints and slow autovacuum operations Features

    Enable default logging of checkpoints and slow autovacuum operations (Bharath Rupireddy) §

    This changes the default of log_checkpoints to on and that of log_autovacuum_min_duration to 10 minutes. This will cause even an idle server to generate some log output, which might cause problems on resource-constrained servers without log file rotation. These defaults should be changed in such cases.

    Original release occurrence · 15.0/changes/026

  • Generate progress messages in the server log during slow server starts Features

    Generate progress messages in the server log during slow server starts (Nitin Jadhav, Robert Haas) § §

    The messages report the cause of the delay. The time interval for notification is controlled by the new server variable log_startup_progress_interval.

    Original release occurrence · 15.0/changes/027

  • Store cumulative statistics system data in shared memory Features

    Store cumulative statistics system data in shared memory (Kyotaro Horiguchi, Andres Freund, Melanie Plageman) § §

    Previously this data was sent to a statistics collector process via UDP packets, and could only be read by sessions after transferring it via the file system. There is no longer a separate statistics collector process.

    Original release occurrence · 15.0/changes/028

  • Add additional information to VACUUM VERBOSE and autovacuum logging messages Features

    Add additional information to VACUUM VERBOSE and autovacuum logging messages (Peter Geoghegan) § § §

    Original release occurrence · 15.0/changes/029

  • Add EXPLAIN (BUFFERS) output for temporary file block I/O Features

    Add EXPLAIN (BUFFERS) output for temporary file block I/O (Masahiko Sawada) §

    Original release occurrence · 15.0/changes/030

  • Allow log output in JSON format Features

    Allow log output in JSON format (Sehrope Sarkuni, Michael Paquier) §

    The new setting is log_destination = jsonlog.

    Original release occurrence · 15.0/changes/031

  • Allow pg_stat_reset_single_table_counters() to reset the counters of relations shared across all databases Features

    Allow pg_stat_reset_single_table_counters() to reset the counters of relations shared across all databases (Sadhuprasad Patro) §

    Original release occurrence · 15.0/changes/032

  • Add wait events for local shell commands Features

    Add wait events for local shell commands (Fujii Masao) §

    The new wait events are used when calling archive_command, archive_cleanup_command, restore_command and recovery_end_command.

    Original release occurrence · 15.0/changes/033

  • Allow table accesses done by a view to optionally be controlled by privileges of the view's caller Features

    Allow table accesses done by a view to optionally be controlled by privileges of the view's caller (Christoph Heiss) §

    Previously, view accesses were always treated as being done by the view's owner. That's still the default.

    Original release occurrence · 15.0/changes/034

  • Allow members of the pg_write_server_files predefined role to perform server-side base backups Features

    Allow members of the pg_write_server_files predefined role to perform server-side base backups (Dagfinn Ilmari Mannsåker) §

    Previously only superusers could perform such backups.

    Original release occurrence · 15.0/changes/035

  • Allow GRANT to grant permissions to change individual server variables via SET and ALTER SYSTEM Features

    Allow GRANT to grant permissions to change individual server variables via SET and ALTER SYSTEM (Mark Dilger) § §

    The new function has_parameter_privilege() reports on this privilege.

    Original release occurrence · 15.0/changes/036

  • Add predefined role pg_checkpoint that allows members to run CHECKPOINT Features

    Add predefined role pg_checkpoint that allows members to run CHECKPOINT (Jeff Davis) § §

    Previously checkpoints could only be run by superusers.

    Original release occurrence · 15.0/changes/037

  • Allow members of the pg_read_all_stats predefined role to access the views pg_backend_memory_contexts and pg_shmem_allocations Features

    Allow members of the pg_read_all_stats predefined role to access the views pg_backend_memory_contexts and pg_shmem_allocations (Bharath Rupireddy) §

    Previously these views could only be accessed by superusers.

    Original release occurrence · 15.0/changes/038

  • Allow GRANT to grant permissions on pg_log_backend_memory_contexts() Features

    Allow GRANT to grant permissions on pg_log_backend_memory_contexts() (Jeff Davis) §

    Previously this function could only be run by superusers.

    Original release occurrence · 15.0/changes/039

  • Add server variable shared_memory_size to report the size of allocated shared memory Features

    Add server variable shared_memory_size to report the size of allocated shared memory (Nathan Bossart) § §

    Original release occurrence · 15.0/changes/040

  • Add server variable shared_memory_size_in_huge_pages to report the number of huge memory pages required Features

    Add server variable shared_memory_size_in_huge_pages to report the number of huge memory pages required (Nathan Bossart) § §

    This is only supported on Linux.

    Original release occurrence · 15.0/changes/041

  • Honor server variable shared_preload_libraries in single-user mode Features

    Honor server variable shared_preload_libraries in single-user mode (Jeff Davis) §

    This change supports use of shared_preload_libraries to load custom access methods and WAL resource managers, which would be essential for database access even in single-user mode.

    Original release occurrence · 15.0/changes/042

  • On Solaris, make the default setting of dynamic_shared_memory_type be sysv Features

    On Solaris, make the default setting of dynamic_shared_memory_type be sysv (Thomas Munro) §

    The previous default choice, posix, can result in spurious failures on this platform.

    Original release occurrence · 15.0/changes/043

  • Allow postgres -C to properly report runtime-computed values Features

    Allow postgres -C to properly report runtime-computed values (Nathan Bossart) §

    Previously runtime-computed values data_checksums, wal_segment_size, and data_directory_mode would report values that would not be accurate on the running server. However, this does not work on a running server.

    Original release occurrence · 15.0/changes/044

  • Add support for LZ4 and Zstandard compression of server-side base backups Features

    Add support for LZ4 and Zstandard compression of server-side base backups (Jeevan Ladhe, Robert Haas) § § §

    Original release occurrence · 15.0/changes/045

  • Run the checkpointer and bgwriter processes during crash recovery Features

    Run the checkpointer and bgwriter processes during crash recovery (Thomas Munro) §

    This helps to speed up long crash recoveries.

    Original release occurrence · 15.0/changes/046

  • Allow WAL processing to pre-fetch needed file contents Features

    Allow WAL processing to pre-fetch needed file contents (Thomas Munro) §

    This is controlled by the server variable recovery_prefetch.

    Original release occurrence · 15.0/changes/047

  • Allow archiving via loadable modules Features

    Allow archiving via loadable modules (Nathan Bossart) §

    Previously, archiving was only done by calling shell commands. The new server variable archive_library can be set to specify a library to be called for archiving.

    Original release occurrence · 15.0/changes/048

  • No longer require IDENTIFY_SYSTEM to be run before START_REPLICATION Features

    No longer require IDENTIFY_SYSTEM to be run before START_REPLICATION (Jeff Davis) §

    Original release occurrence · 15.0/changes/049

  • Allow publication of all tables in a schema Features

    Allow publication of all tables in a schema (Vignesh C, Hou Zhijie, Amit Kapila) § § §

    For example, this syntax is now supported: CREATE PUBLICATION pub1 FOR TABLES IN SCHEMA s1,s2. ALTER PUBLICATION supports a similar syntax. Tables added later to the listed schemas will also be replicated.

    Original release occurrence · 15.0/changes/050

  • Allow publication content to be filtered using a WHERE clause Features

    Allow publication content to be filtered using a WHERE clause (Hou Zhijie, Euler Taveira, Peter Smith, Ajin Cherian, Tomas Vondra, Amit Kapila) § § §

    Rows not satisfying the WHERE clause are not published.

    Original release occurrence · 15.0/changes/051

  • Allow publication content to be restricted to specific columns Features

    Allow publication content to be restricted to specific columns (Tomas Vondra, Álvaro Herrera, Rahila Syed) §

    Original release occurrence · 15.0/changes/052

  • Allow skipping of transactions on a subscriber using ALTER SUBSCRIPTION ... SKIP Features

    Allow skipping of transactions on a subscriber using ALTER SUBSCRIPTION ... SKIP (Masahiko Sawada) §

    Original release occurrence · 15.0/changes/053

  • Add support for prepared (two-phase) transactions to logical replication Features

    Add support for prepared (two-phase) transactions to logical replication (Peter Smith, Ajin Cherian, Amit Kapila, Nikhil Sontakke, Stas Kelvich) § § §

    The new CREATE_REPLICATION_SLOT option is called TWO_PHASE. pg_recvlogical now supports a new --two-phase option during slot creation.

    Original release occurrence · 15.0/changes/054

  • Prevent logical replication of empty transactions Features

    Prevent logical replication of empty transactions (Ajin Cherian, Hou Zhijie, Euler Taveira) §

    Previously, publishers would send empty transactions to subscribers if subscribed tables were not modified.

    Original release occurrence · 15.0/changes/055

  • Add SQL functions to monitor the directory contents of logical replication slots Features

    Add SQL functions to monitor the directory contents of logical replication slots (Bharath Rupireddy) §

    The new functions are pg_ls_logicalsnapdir(), pg_ls_logicalmapdir(), and pg_ls_replslotdir(). They can be run by members of the predefined pg_monitor role.

    Original release occurrence · 15.0/changes/056

  • Allow subscribers to stop the application of logical replication changes on error Features

    Allow subscribers to stop the application of logical replication changes on error (Osumi Takamichi, Mark Dilger) §

    This is enabled with the subscriber option disable_on_error and avoids possible infinite error loops during stream application.

    Original release occurrence · 15.0/changes/057

  • Adjust subscriber server variables to match the publisher so datetime and float8 values are interpreted consistently Features

    Adjust subscriber server variables to match the publisher so datetime and float8 values are interpreted consistently (Japin Li) §

    Some publishers might be relying on inconsistent behavior.

    Original release occurrence · 15.0/changes/058

  • Add system view pg_stat_subscription_stats to report on subscriber activity Features

    Add system view pg_stat_subscription_stats to report on subscriber activity (Masahiko Sawada) § §

    The new function pg_stat_reset_subscription_stats() allows resetting these statistics counters.

    Original release occurrence · 15.0/changes/059

  • Suppress duplicate entries in the pg_publication_tables system view Features

    Suppress duplicate entries in the pg_publication_tables system view (Hou Zhijie) §

    In some cases a partition could appear more than once.

    Original release occurrence · 15.0/changes/060

  • Add SQL MERGE command to adjust one table to match another Features

    Add SQL MERGE command to adjust one table to match another (Simon Riggs, Pavan Deolasee, Álvaro Herrera, Amit Langote) §

    This is similar to INSERT ... ON CONFLICT but more batch-oriented.

    Original release occurrence · 15.0/changes/061

  • Add support for HEADER option in COPY text format Features

    Add support for HEADER option in COPY text format (Rémi Lapeyre) § §

    The new option causes the column names to be output, and optionally verified on input.

    Original release occurrence · 15.0/changes/062

  • Add new WAL-logged method for database creation Features

    Add new WAL-logged method for database creation (Dilip Kumar) §

    This is the new default method for copying the template database, as it avoids the need for checkpoints during database creation. However, it might be slow if the template database is large, so the old method is still available.

    Original release occurrence · 15.0/changes/063

  • Allow CREATE DATABASE to set the database OID Features

    Allow CREATE DATABASE to set the database OID (Shruthi Gowda, Antonin Houska) §

    Original release occurrence · 15.0/changes/064

  • Prevent DROP DATABASE, DROP TABLESPACE, and ALTER DATABASE SET TABLESPACE from occasionally failing during concurrent use on Windows Features

    Prevent DROP DATABASE, DROP TABLESPACE, and ALTER DATABASE SET TABLESPACE from occasionally failing during concurrent use on Windows (Thomas Munro) §

    Original release occurrence · 15.0/changes/065

  • Allow foreign key ON DELETE SET actions to affect only specified columns Features

    Allow foreign key ON DELETE SET actions to affect only specified columns (Paul Martinez) §

    Previously, all of the columns in the foreign key were always affected.

    Original release occurrence · 15.0/changes/066

  • Allow ALTER TABLE to modify a table's ACCESS METHOD Features

    Allow ALTER TABLE to modify a table's ACCESS METHOD (Justin Pryzby, Jeff Davis) §

    Original release occurrence · 15.0/changes/067

  • Properly call object access hooks when ALTER TABLE causes table rewrites Features

    Properly call object access hooks when ALTER TABLE causes table rewrites (Michael Paquier) §

    Original release occurrence · 15.0/changes/068

  • Allow creation of unlogged sequences Features

    Allow creation of unlogged sequences (Peter Eisentraut) §

    Original release occurrence · 15.0/changes/069

  • Track dependencies on individual columns in the results of functions returning composite types Features

    Track dependencies on individual columns in the results of functions returning composite types (Tom Lane) §

    Previously, if a view or rule contained a reference to a specific column within the result of a composite-returning function, that was not noted as a dependency; the view or rule was only considered to depend on the composite type as a whole. This meant that dropping the individual column would be allowed, causing problems in later use of the view or rule. The column-level dependency is now also noted, so that dropping such a column will be rejected unless the view is changed or dropped.

    Original release occurrence · 15.0/changes/070

  • Allow the scale of a numeric value to be negative, or greater than its precision Features

    Allow the scale of a numeric value to be negative, or greater than its precision (Dean Rasheed, Tom Lane) §

    This allows rounding of values to the left of the decimal point, e.g., '1234'::numeric(4, -2) returns 1200.

    Original release occurrence · 15.0/changes/071

  • Improve overflow detection when casting values to interval Features

    Improve overflow detection when casting values to interval (Joe Koshakow) §

    Original release occurrence · 15.0/changes/072

  • Change the I/O format of type "char" for non-ASCII characters Features

    Change the I/O format of type "char" for non-ASCII characters (Tom Lane) §

    Original release occurrence · 15.0/changes/073

  • Update the display width information of modern Unicode characters, like emojis Features

    Update the display width information of modern Unicode characters, like emojis (Jacob Champion) § §

    Also update from Unicode 5.0 to 14.0.0. There is now an automated way to keep Postgres updated with Unicode releases.

    Original release occurrence · 15.0/changes/074

  • Add multirange input to range_agg() Features

    Add multirange input to range_agg() (Paul Jungwirth) §

    Original release occurrence · 15.0/changes/075

  • Add MIN() and MAX() aggregates for the xid8 data type Features

    Add MIN() and MAX() aggregates for the xid8 data type (Ken Kato) §

    Original release occurrence · 15.0/changes/076

  • Add regular expression functions for compatibility with other relational systems Features

    Add regular expression functions for compatibility with other relational systems (Gilles Darold, Tom Lane) §

    The new functions are regexp_count(), regexp_instr(), regexp_like(), and regexp_substr(). Some new optional arguments were also added to regexp_replace().

    Original release occurrence · 15.0/changes/077

  • Add the ability to compute the distance between polygons Features

    Add the ability to compute the distance between polygons (Tom Lane) §

    Original release occurrence · 15.0/changes/078

  • Add to_char() format codes of, tzh, and tzm Features

    Add to_char() format codes of, tzh, and tzm (Nitin Jadhav) §

    The upper-case equivalents of these were already supported.

    Original release occurrence · 15.0/changes/079

  • When applying AT TIME ZONE to a time with time zone value, use the transaction start time rather than wall clock time to determine whether DST applies Features

    When applying AT TIME ZONE to a time with time zone value, use the transaction start time rather than wall clock time to determine whether DST applies (Aleksander Alekseev, Tom Lane) §

    This allows the conversion to be considered stable rather than volatile, and it saves a kernel call per invocation.

    Original release occurrence · 15.0/changes/080

  • Ignore NULL array elements in ts_delete() and setweight() functions with array arguments Features

    Ignore NULL array elements in ts_delete() and setweight() functions with array arguments (Jean-Christophe Arnu) §

    These functions effectively ignore empty-string array elements (since those could never match a valid lexeme). It seems consistent to let them ignore NULL elements too, instead of failing.

    Original release occurrence · 15.0/changes/081

  • Add support for petabyte units to pg_size_pretty() and pg_size_bytes() Features

    Add support for petabyte units to pg_size_pretty() and pg_size_bytes() (David Christensen) §

    Original release occurrence · 15.0/changes/082

  • Change pg_event_trigger_ddl_commands() to output references to other sessions' temporary schemas using the actual schema name Features

    Change pg_event_trigger_ddl_commands() to output references to other sessions' temporary schemas using the actual schema name (Tom Lane) §

    Previously this function reported all temporary schemas as pg_temp, but it's misleading to use that for any but the current session's temporary schema.

    Original release occurrence · 15.0/changes/083

  • Fix enforcement of PL/pgSQL variable CONSTANT markings Bug fixes

    Fix enforcement of PL/pgSQL variable CONSTANT markings (Tom Lane) §

    Previously, a variable could be used as a CALL output parameter or refcursor OPEN variable despite being marked CONSTANT.

    Original release occurrence · 15.0/changes/084

  • Allow IP address matching against a server certificate's Subject Alternative Name Features

    Allow IP address matching against a server certificate's Subject Alternative Name (Jacob Champion) §

    Original release occurrence · 15.0/changes/085

  • Allow PQsslAttribute() to report the SSL library type without requiring a libpq connection Features

    Allow PQsslAttribute() to report the SSL library type without requiring a libpq connection (Jacob Champion) §

    Original release occurrence · 15.0/changes/086

  • Change query cancellations sent by the client to use the same TCP settings as normal client connections Features

    Change query cancellations sent by the client to use the same TCP settings as normal client connections (Jelte Fennema) §

    This allows configured TCP timeouts to apply to query cancel connections.

    Original release occurrence · 15.0/changes/087

  • Prevent libpq event callback failures from forcing an error result Features

    Prevent libpq event callback failures from forcing an error result (Tom Lane) § §

    Original release occurrence · 15.0/changes/088

  • Allow pgbench to retry after serialization and deadlock failures Features

    Allow pgbench to retry after serialization and deadlock failures (Yugo Nagata, Marina Polyakova) §

    Original release occurrence · 15.0/changes/089

  • Improve performance of psql's \copy command, by sending data in larger chunks Performance

    Improve performance of psql's \copy command, by sending data in larger chunks (Heikki Linnakangas) §

    Original release occurrence · 15.0/changes/090

  • Add \dconfig command to report server variables Features

    Add \dconfig command to report server variables (Mark Dilger, Tom Lane) § § §

    This is similar to the server-side SHOW command, but it can process patterns to show multiple variables conveniently.

    Original release occurrence · 15.0/changes/091

  • Add \getenv command to assign the value of an environment variable to a psql variable Features

    Add \getenv command to assign the value of an environment variable to a psql variable (Tom Lane) §

    Original release occurrence · 15.0/changes/092

  • Add + option to the \lo_list and \dl commands to show large-object privileges Features

    Add + option to the \lo_list and \dl commands to show large-object privileges (Pavel Luzanov) §

    Original release occurrence · 15.0/changes/093

  • Add a pager option for the \watch command Features

    Add a pager option for the \watch command (Pavel Stehule, Thomas Munro) §

    This is only supported on Unix and is controlled by the PSQL_WATCH_PAGER environment variable.

    Original release occurrence · 15.0/changes/094

  • Make psql include intra-query double-hyphen comments in queries sent to the server Features

    Make psql include intra-query double-hyphen comments in queries sent to the server (Tom Lane, Greg Nancarrow) § §

    Previously such comments were removed from the query before being sent. Double-hyphen comments that are before any query text are not sent, and are not recorded as separate psql history entries.

    Original release occurrence · 15.0/changes/095

  • Adjust psql so that Readline's meta-# command will insert a double-hyphen comment marker Features

    Adjust psql so that Readline's meta-# command will insert a double-hyphen comment marker (Tom Lane) §

    Previously a pound marker was inserted, unless the user had taken the trouble to configure a non-default comment marker.

    Original release occurrence · 15.0/changes/096

  • Make psql output all results when multiple queries are passed to the server at once Features

    Make psql output all results when multiple queries are passed to the server at once (Fabien Coelho) §

    Previously, only the last query result was displayed. The old behavior can be restored by setting the SHOW_ALL_RESULTS psql variable to off.

    Original release occurrence · 15.0/changes/097

  • After an error is detected in --single-transaction mode, change the final COMMIT command to ROLLBACK only if ON_ERROR_STOP is set Features

    After an error is detected in --single-transaction mode, change the final COMMIT command to ROLLBACK only if ON_ERROR_STOP is set (Michael Paquier) §

    Previously, detection of an error in a -c command or -f script file would lead to issuing ROLLBACK at the end, regardless of the value of ON_ERROR_STOP.

    Original release occurrence · 15.0/changes/098

  • Improve psql's tab completion Features

    Improve psql's tab completion (Shinya Kato, Dagfinn Ilmari Mannsåker, Peter Smith, Koyu Tanigawa, Ken Kato, David Fetter, Haiying Tang, Peter Eisentraut, Álvaro Herrera, Tom Lane, Masahiko Sawada) § § § § § § § § § § § § § § § § § § § §

    Original release occurrence · 15.0/changes/099

  • Limit support of psql's backslash commands to servers running PostgreSQL 9.2 or later Features

    Limit support of psql's backslash commands to servers running PostgreSQL 9.2 or later (Tom Lane) §

    Remove code that was only used when running with an older server. Commands that do not require any version-specific adjustments compared to 9.2 will still work.

    Original release occurrence · 15.0/changes/100

  • Make pg_dump dump public schema ownership changes and security labels Features

    Make pg_dump dump public schema ownership changes and security labels (Noah Misch) § §

    Original release occurrence · 15.0/changes/101

  • Improve performance of dumping databases with many objects Performance

    Improve performance of dumping databases with many objects (Tom Lane) § § §

    This will also improve the performance of pg_upgrade.

    Original release occurrence · 15.0/changes/102

  • Improve parallel pg_dump's performance for tables with large TOAST tables Performance

    Improve parallel pg_dump's performance for tables with large TOAST tables (Tom Lane) §

    Original release occurrence · 15.0/changes/103

  • Add dump/restore option --no-table-access-method to force restore to only use the default table access method Features

    Add dump/restore option --no-table-access-method to force restore to only use the default table access method (Justin Pryzby) §

    Original release occurrence · 15.0/changes/104

  • Limit support of pg_dump and pg_dumpall to servers running PostgreSQL 9.2 or later Features

    Limit support of pg_dump and pg_dumpall to servers running PostgreSQL 9.2 or later (Tom Lane) §

    Original release occurrence · 15.0/changes/105

  • Add new pg_basebackup option --target to control the base backup location Features

    Add new pg_basebackup option --target to control the base backup location (Robert Haas) §

    The new options are server to write the backup locally and blackhole to discard the backup (for testing).

    Original release occurrence · 15.0/changes/106

  • Allow pg_basebackup to do server-side gzip, LZ4, and Zstandard compression and client-side LZ4 and Zstandard compression of base backup files Features

    Allow pg_basebackup to do server-side gzip, LZ4, and Zstandard compression and client-side LZ4 and Zstandard compression of base backup files (Dipesh Pandit, Jeevan Ladhe) § § §

    Client-side gzip compression was already supported.

    Original release occurrence · 15.0/changes/107

  • Allow pg_basebackup to compress on the server side and decompress on the client side before storage Features

    Allow pg_basebackup to compress on the server side and decompress on the client side before storage (Dipesh Pandit) §

    This is accomplished by specifying compression on the server side and plain output format.

    Original release occurrence · 15.0/changes/108

  • Allow pg_basebackup's --compress option to control the compression location (server or client), compression method, and compression options Features

    Allow pg_basebackup's --compress option to control the compression location (server or client), compression method, and compression options (Michael Paquier, Robert Haas) § § §

    Original release occurrence · 15.0/changes/109

  • Add the LZ4 compression method to pg_receivewal Features

    Add the LZ4 compression method to pg_receivewal (Georgios Kokolatos) § §

    This is enabled via --compress=lz4 and requires binaries to be built using --with-lz4.

    Original release occurrence · 15.0/changes/110

  • Add additional capabilities to pg_receivewal's --compress option Features

    Add additional capabilities to pg_receivewal's --compress option (Georgios Kokolatos) §

    Original release occurrence · 15.0/changes/111

  • Improve pg_receivewal's ability to restart at the proper WAL location Features

    Improve pg_receivewal's ability to restart at the proper WAL location (Ronan Dunklau) §

    Previously, pg_receivewal would start based on the WAL file stored in the local archive directory, or at the sending server's current WAL flush location. With this change, if the sending server is running Postgres 15 or later, the local archive directory is empty, and a replication slot is specified, the replication slot's restart point will be used.

    Original release occurrence · 15.0/changes/112

  • Add pg_rewind option --config-file to simplify use when server configuration files are stored outside the data directory Features

    Add pg_rewind option --config-file to simplify use when server configuration files are stored outside the data directory (Gunnar Bluth) §

    Original release occurrence · 15.0/changes/113

  • Store pg_upgrade's log and temporary files in a subdirectory of the new cluster called pg_upgrade_output.d Features

    Store pg_upgrade's log and temporary files in a subdirectory of the new cluster called pg_upgrade_output.d (Justin Pryzby) § § §

    Previously such files were left in the current directory, requiring manual cleanup. Now they are automatically removed on successful completion of pg_upgrade.

    Original release occurrence · 15.0/changes/114

  • Disable default status reporting during pg_upgrade operation if the output is not a terminal Features

    Disable default status reporting during pg_upgrade operation if the output is not a terminal (Andres Freund) §

    The status reporting output can be enabled for non-tty usage by using --verbose.

    Original release occurrence · 15.0/changes/115

  • Make pg_upgrade report all databases with invalid connection settings Features

    Make pg_upgrade report all databases with invalid connection settings (Jeevan Ladhe) §

    Previously only the first database with an invalid connection setting was reported.

    Original release occurrence · 15.0/changes/116

  • Make pg_upgrade preserve tablespace and database OIDs, as well as relation relfilenode numbers Features

    Make pg_upgrade preserve tablespace and database OIDs, as well as relation relfilenode numbers (Shruthi Gowda, Antonin Houska) § § §

    Original release occurrence · 15.0/changes/117

  • Add a --no-sync option to pg_upgrade Features

    Add a --no-sync option to pg_upgrade (Michael Paquier) §

    This is recommended only for testing.

    Original release occurrence · 15.0/changes/118

  • Limit support of pg_upgrade to old servers running PostgreSQL 9.2 or later Features

    Limit support of pg_upgrade to old servers running PostgreSQL 9.2 or later (Tom Lane) §

    Original release occurrence · 15.0/changes/119

  • Allow pg_waldump output to be filtered by relation file node, block number, fork number, and full page images Features

    Allow pg_waldump output to be filtered by relation file node, block number, fork number, and full page images (David Christensen, Thomas Munro) § §

    Original release occurrence · 15.0/changes/120

  • Make pg_waldump report statistics before an interrupted exit Features

    Make pg_waldump report statistics before an interrupted exit (Bharath Rupireddy) §

    For example, issuing a control-C in a terminal running pg_waldump --stats --follow will report the current statistics before exiting. This does not work on Windows.

    Original release occurrence · 15.0/changes/121

  • Improve descriptions of some transaction WAL records reported by pg_waldump Features

    Improve descriptions of some transaction WAL records reported by pg_waldump (Masahiko Sawada, Michael Paquier) §

    Original release occurrence · 15.0/changes/122

  • Allow pg_waldump to dump information about multiple resource managers Features

    Allow pg_waldump to dump information about multiple resource managers (Heikki Linnakangas) §

    This is enabled by specifying the --rmgr option multiple times.

    Original release occurrence · 15.0/changes/123

  • Add documentation for pg_encoding_to_char() and pg_char_to_encoding() Features

    Add documentation for pg_encoding_to_char() and pg_char_to_encoding() (Ian Lawrence Barwick) §

    Original release occurrence · 15.0/changes/124

  • Document the ^@ starts-with operator Features

    Document the ^@ starts-with operator (Tom Lane) §

    Original release occurrence · 15.0/changes/125

  • Add support for continuous integration testing using cirrus-ci Features

    Add support for continuous integration testing using cirrus-ci (Andres Freund, Thomas Munro, Melanie Plageman) §

    Original release occurrence · 15.0/changes/126

  • Add configure option --with-zstd to enable Zstandard builds Features

    Add configure option --with-zstd to enable Zstandard builds (Jeevan Ladhe, Robert Haas, Michael Paquier) §

    Original release occurrence · 15.0/changes/127

  • Add an ABI identifier field to the magic block in loadable libraries, allowing non-community PostgreSQL distributions to identify libraries that are not compatible with other builds Features

    Add an ABI identifier field to the magic block in loadable libraries, allowing non-community PostgreSQL distributions to identify libraries that are not compatible with other builds (Peter Eisentraut) §

    An ABI field mismatch will generate an error at load time.

    Original release occurrence · 15.0/changes/128

  • Create a new pg_type.typcategory value for "char" Features

    Create a new pg_type.typcategory value for "char" (Tom Lane) §

    Some other internal-use-only types have also been assigned to this category.

    Original release occurrence · 15.0/changes/129

  • Add new protocol message TARGET to specify a new COPY method to be used for base backups Features

    Add new protocol message TARGET to specify a new COPY method to be used for base backups (Robert Haas) §

    pg_basebackup now uses this method.

    Original release occurrence · 15.0/changes/130

  • Add new protocol message COMPRESSION and COMPRESSION_DETAIL to specify the compression method and options Features

    Add new protocol message COMPRESSION and COMPRESSION_DETAIL to specify the compression method and options (Robert Haas) § §

    Original release occurrence · 15.0/changes/131

  • Remove server support for old BASE_BACKUP command syntax and base backup protocol Features

    Remove server support for old BASE_BACKUP command syntax and base backup protocol (Robert Haas) § §

    Original release occurrence · 15.0/changes/132

  • Add support for extensions to set custom backup targets Features

    Add support for extensions to set custom backup targets (Robert Haas) §

    Original release occurrence · 15.0/changes/133

  • Allow extensions to define custom WAL resource managers Features

    Allow extensions to define custom WAL resource managers (Jeff Davis) §

    Original release occurrence · 15.0/changes/134

  • Add function pg_settings_get_flags() to get the flags of server variables Features

    Add function pg_settings_get_flags() to get the flags of server variables (Justin Pryzby) §

    Original release occurrence · 15.0/changes/135

  • On Windows, export all the server's global variables using PGDLLIMPORT markers Features

    On Windows, export all the server's global variables using PGDLLIMPORT markers (Robert Haas) §

    Previously, only specific variables were accessible to extensions on Windows.

    Original release occurrence · 15.0/changes/136

  • Require GNU make version 3.81 or later to build PostgreSQL Features

    Require GNU make version 3.81 or later to build PostgreSQL (Tom Lane) §

    Original release occurrence · 15.0/changes/137

  • Require OpenSSL to build the pgcrypto extension Features

    Require OpenSSL to build the pgcrypto extension (Peter Eisentraut) §

    Original release occurrence · 15.0/changes/138

  • Require Perl version 5.8.3 or later Features

    Require Perl version 5.8.3 or later (Dagfinn Ilmari Mannsåker) §

    Original release occurrence · 15.0/changes/139

  • Require Python version 3.2 or later Features

    Require Python version 3.2 or later (Andres Freund) §

    Original release occurrence · 15.0/changes/140

  • Allow amcheck to check sequences Features

    Allow amcheck to check sequences (Mark Dilger) §

    Original release occurrence · 15.0/changes/141

  • Improve amcheck sanity checks for TOAST tables Features

    Improve amcheck sanity checks for TOAST tables (Mark Dilger) §

    Original release occurrence · 15.0/changes/142

  • Add new module basebackup_to_shell as an example of a custom backup target Features

    Add new module basebackup_to_shell as an example of a custom backup target (Robert Haas) § §

    Original release occurrence · 15.0/changes/143

  • Add new module basic_archive as an example of performing archiving via a library Features

    Add new module basic_archive as an example of performing archiving via a library (Nathan Bossart) §

    Original release occurrence · 15.0/changes/144

  • Allow btree_gist indexes on boolean columns Features

    Allow btree_gist indexes on boolean columns (Emre Hasegeli) § § §

    These can be used for exclusion constraints.

    Original release occurrence · 15.0/changes/145

  • Fix pageinspect's page_header() to handle 32-kilobyte page sizes Bug fixes

    Fix pageinspect's page_header() to handle 32-kilobyte page sizes (Quan Zongliang) §

    Previously, improper negative values could be returned in certain cases.

    Original release occurrence · 15.0/changes/146

  • Add counters for temporary file block I/O to pg_stat_statements Features

    Add counters for temporary file block I/O to pg_stat_statements (Masahiko Sawada) §

    Original release occurrence · 15.0/changes/147

  • Add JIT counters to pg_stat_statements Features

    Add JIT counters to pg_stat_statements (Magnus Hagander) §

    Original release occurrence · 15.0/changes/148

  • Add new module pg_walinspect Features

    Add new module pg_walinspect (Bharath Rupireddy) §

    This gives SQL-level output similar to pg_waldump.

    Original release occurrence · 15.0/changes/149

  • Indicate the permissive/enforcing state in sepgsql log messages Features

    Indicate the permissive/enforcing state in sepgsql log messages (Dave Page) §

    Original release occurrence · 15.0/changes/150

  • Allow postgres_fdw to push down CASE expressions Features

    Allow postgres_fdw to push down CASE expressions (Alexander Pyhalov) §

    Original release occurrence · 15.0/changes/151

  • Add server variable postgres_fdw.application_name to control the application name of postgres_fdw connections Features

    Add server variable postgres_fdw.application_name to control the application name of postgres_fdw connections (Hayato Kuroda) § § §

    Previously the remote session's application_name could only be set on the remote server or via a postgres_fdw connection specification. postgres_fdw.application_name supports some escape sequences for customization, making it easier to tell such connections apart on the remote server.

    Original release occurrence · 15.0/changes/152

  • Allow parallel commit on postgres_fdw servers Features

    Allow parallel commit on postgres_fdw servers (Etsuro Fujita) §

    This is enabled with the CREATE SERVER option parallel_commit.

    Original release occurrence · 15.0/changes/153

Security evidence

65 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.

CVE-2026-6637 · PostgreSQL refint allows stack buffer overflow and SQL injection CVSS 8.8

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 15.18. Component: contrib module.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6479 · PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion CVSS 7.5

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 15.18. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2026-6478 · PostgreSQL discloses MD5-hashed passwords via covert timing channel CVSS 6.5

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 15.18. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-6477 · PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory CVSS 8.8

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 15.18. Component: client.

Official affected-branch entry: 15.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6475 · PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice CVSS 8.8

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 15.18. Component: client.

Official affected-branch entry: 15.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6474 · PostgreSQL timeofday() can disclose portions of server memory CVSS 4.3

Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 15.18. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-6473 · PostgreSQL server undersizes allocations, via integer wraparound CVSS 8.8

Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 15.18. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6472 · PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege CVSS 5.4

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 15.18. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-6471 · PostgreSQL logical decoding can dlopen arbitrary file CVSS 7.2

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6470 · PostgreSQL fails to check type USAGE privilege CVSS 4.3

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2026-6469 · PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership CVSS 3.8

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

Release-note mentions:

CVE-2026-6464 · PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands CVSS 8.1

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: client.

Official affected-branch entry: 15.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2006 · PostgreSQL missing validation of multibyte character length executes arbitrary code CVSS 8.8

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 15.16. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2005 · PostgreSQL pgcrypto heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 15.16. Component: contrib module.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2004 · PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code CVSS 8.8

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 15.16. Component: contrib module.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2003 · PostgreSQL oidvector discloses a few bytes of memory CVSS 4.3

Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 15.16. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-19385 · PostgreSQL pg_dump heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: client.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-18408 · PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client CVSS 8.8

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: client.

Official affected-branch entry: 15.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-18024 · PostgreSQL ascii() function reads past end of buffer CVSS 4.3

Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-16241 · PostgreSQL ECPG integer underflow can crash the client CVSS 3.8

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: client.

Official affected-branch entry: 15.

AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

Release-note mentions:

CVE-2026-16239 · PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-16238 · PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-15742 · PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: contrib module.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-15741 · PostgreSQL expression deparse allows SQL injection via EXTRACT argument CVSS 8.8

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14681 · PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL CVSS 4.2

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14680 · PostgreSQL type confusion via "internal" arguments CVSS 8.8

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14679 · PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory CVSS 8.2

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Release-note mentions:

CVE-2026-14678 · PostgreSQL pg_trgm picksplit reads past end of buffer CVSS 4.3

Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: contrib module.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-14677 · PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14676 · PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

No fixed version for this branch is recorded. Component: contrib module.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14673 · PostgreSQL amcheck does not clear untrusted search path CVSS 3.8

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

Fixed in this branch: 15.19. Component: contrib module.

Official affected-branch entry: 15.

AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14672 · PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle CVSS 5.3

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-14671 · PostgreSQL refint plan cache type confusion executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: contrib module.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14670 · PostgreSQL plperl tied object heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14669 · PostgreSQL to_char heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14668 · PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read CVSS 8.1

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Release-note mentions:

CVE-2026-14666 · PostgreSQL row security caching disregards role modifications CVSS 4.2

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14664 · PostgreSQL regexp heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14663 · PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext CVSS 6.5

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: contrib module.

Official affected-branch entry: 15.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14662 · PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 15.19. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8715 · PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server CVSS 8.8

Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.

Fixed in this branch: 15.14. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client CVSS 8.8

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

Fixed in this branch: 15.14. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8713 · PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table CVSS 3.1

PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

Fixed in this branch: 15.14. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2025-4207 · PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation CVSS 5.9

Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.

Fixed in this branch: 15.13. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound CVSS 5.9

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Fixed in this branch: 15.15. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege CVSS 3.1

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Fixed in this branch: 15.15. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2025-1094 · PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation CVSS 8.1

Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.

Fixed in this branch: 15.11. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-7348 · PostgreSQL relation replacement during pg_dump executes arbitrary SQL CVSS 8.8

Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected. The PostgreSQL project thanks Noah Misch for reporting this problem.

Fixed in this branch: 15.8. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-4317 · Restrict visibility of "pg_stats_ext" and "pg_stats_ext_exprs" entries to the table owner CVSS 3.1

Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes, which are provided as a convenience in the below section. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected. This fix only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after this fix is applied. If you have a current PostgreSQL installation and are concerned about this issue, please use the following remediation steps to fix the issue: From the above URLs, you can click the URL that says "raw" to download a version that you can copy and paste. Be sure to use the script appropriate to your PostgreSQL major version. If you do not see this file, either your version is not vulnerable (only PostgreSQL 14, 15, and 16 are affected) or your minor version is too old to have the fix. \i /usr/share/postgresql/fix-CVE-2024-4317.sql ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; After executing the fix-CVE-2024-4317.sql script in template0 and template1 , you should revoke the ability for template0 to accept connections. You can do this with the following command: ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; The PostgreSQL project thanks Lukas Fittl for reporting this problem.

Fixed in this branch: 15.7. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code CVSS 8.8

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.

Fixed in this branch: 15.9. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID CVSS 4.2

Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 15.9. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle CVSS 3.1

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 15.9. Component: client.

Official affected-branch entry: 15.

AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes CVSS 4.2

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

Fixed in this branch: 15.9. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2024-0985 · PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL CVSS 8.0

UPDATE (June 19, 2024) : Added v16 as impacted. Updated description to clarify the attack vector. Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view.

Fixed in this branch: 15.6. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes CVSS 2.2

Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.

Fixed in this branch: 15.5. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2023-5869 · Buffer overrun from integer overflow in array modification CVSS 8.8

While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.

Fixed in this branch: 15.5. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-5868 · Memory disclosure in aggregate function calls CVSS 4.3

Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.

Fixed in this branch: 15.5. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2023-39418 · MERGE fails to enforce UPDATE or SELECT row security policies CVSS 3.1

PostgreSQL 15 introduced the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT . If UPDATE and SELECT policies forbid some row that INSERT policies do not forbid, a user could store such rows. Subsequent consequences are application-dependent. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Dean Rasheed for reporting this problem.

Fixed in this branch: 15.4. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection CVSS 7.5

An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.

Fixed in this branch: 15.4. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-2455 · Row security policies disregard user ID changes after inlining CVSS 4.2

While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.

Fixed in this branch: 15.3. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes CVSS 7.2

This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.

Fixed in this branch: 15.3. Component: core server.

Official affected-branch entry: 15.

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2022-41862 · Client memory disclosure when connecting, with Kerberos, to modified server CVSS 3.7

A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. When a libpq client application has a Kerberos credential cache and doesn't explicitly disable option gssencmode , a server can cause libpq to over-read and report an error message containing uninitialized bytes from and following its receive buffer. If libpq's caller somehow makes that message accessible to the attacker, this achieves a disclosure of the over-read bytes. We have not confirmed or ruled out viability of attacks that arrange for a crash or for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 15.2. Component: client.

Official affected-branch entry: 15.

AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications CVSS 8.8

No fixed version for this branch is recorded. Component: client.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2012-0868 · Line breaks in object names can be exploited to execute arbitrary SQL when reloading a pg_dump file.

No fixed version for this branch is recorded.

Release-note mentions:

Export this branch as JSON · Compare any two indexed releases