PostgreSQL 15
Read the English manualSupported · Recorded build 15.19 · 2026-08-13
- First stable release
- 2022-10-13
- Support end
- 2027-11-11
- Indexed releases
- 20
- Original release-note entries
- 1046
Manuals & provenance
PostgreSQL 15 English manual · 1171 loaded pages.
Manual loaded 2026-09-27T00:10:47.078613.
Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.
Upgrade considerations
Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.
Compatibility notes for 15.0 · Changes from the initial release through 15.19
Original migration guidance for 15.0
A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 19.6 for general information on migrating to new major releases.
Version 15 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:
Release history
Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.
| Release | Date / snapshot cutoff | All changes | Bug fixes | Migration entries | CVE mentions |
|---|---|---|---|---|---|
| 15.19 | 2026-08-13 | 90 | 36 | 0 | 31 |
| 15.18 | 2026-05-14 | 43 | 17 | 0 | 8 |
| 15.17 | 2026-02-26 | 5 | 4 | 0 | 1 |
| 15.16 | 2026-02-12 | 40 | 17 | 0 | 4 |
| 15.15 | 2025-11-13 | 54 | 30 | 0 | 2 |
| 15.14 | 2025-08-14 | 54 | 17 | 0 | 5 |
| 15.13 | 2025-05-08 | 38 | 18 | 0 | 1 |
| 15.12 | 2025-02-20 | 1 | 0 | 0 | 1 |
| 15.11 | 2025-02-13 | 48 | 29 | 0 | 1 |
| 15.10 | 2024-11-21 | 8 | 4 | 0 | 1 |
| 15.9 | 2024-11-14 | 46 | 18 | 0 | 4 |
| 15.8 | 2024-08-08 | 49 | 25 | 0 | 2 |
| 15.7 | 2024-05-09 | 52 | 23 | 0 | 1 |
| 15.6 | 2024-02-08 | 60 | 22 | 0 | 1 |
| 15.5 | 2023-11-09 | 60 | 26 | 0 | 3 |
| 15.4 | 2023-08-10 | 47 | 22 | 0 | 2 |
| 15.3 | 2023-05-11 | 83 | 41 | 0 | 2 |
| 15.2 | 2023-02-09 | 58 | 30 | 0 | 1 |
| 15.1 | 2022-11-10 | 26 | 13 | 0 | 0 |
| 15.0 | 2022-10-13 | 184 | 3 | 31 | 1 |
Initial release changes
Original entries from 15.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.
184 of 184 original entries.
Remove PUBLIC creation permission on the public schema Security Migration
Remove
PUBLICcreation permission on thepublicschema (Noah Misch) §The new default is one of the secure schema usage patterns that Section 5.9.6 has recommended since the security release for CVE-2018-1058. The change applies to new database clusters and to newly-created databases in existing clusters. Upgrading a cluster or restoring a database dump will preserve
public's existing permissions.For existing databases, especially those having multiple users, consider revoking
CREATEpermission on thepublicschema to adopt this new default. For new databases having no need to defend against insider threats, grantingCREATEpermission will yield the behavior of prior releases.Original release occurrence ·
15.0/migration/001Change the owner of the public schema to be the new pg_database_owner role Compatibility Migration
Change the owner of the
publicschema to be the newpg_database_ownerrole (Noah Misch) §This allows each database's owner to have ownership privileges on the
publicschema within their database. Previously it was owned by the bootstrap superuser, so that non-superuser database owners could not do anything with it.This change applies to new database clusters and to newly-created databases in existing clusters. Upgrading a cluster or restoring a database dump will preserve
public's existing ownership specification.Original release occurrence ·
15.0/migration/002Remove long-deprecated exclusive backup mode Compatibility Migration
Remove long-deprecated exclusive backup mode (David Steele, Nathan Bossart) §
If the database server stops abruptly while in this mode, the server could fail to start. The non-exclusive backup mode is considered superior for all purposes. Functions
pg_start_backup()/pg_stop_backup()have been renamed topg_backup_start()/pg_backup_stop(), and the functionspg_backup_start_time()andpg_is_in_backup()have been removed.Original release occurrence ·
15.0/migration/003Increase hash_mem_multiplier default to 2.0 Compatibility Migration
Increase
hash_mem_multiplierdefault to 2.0 (Peter Geoghegan) §This allows query hash operations to use more
work_memmemory than other operations.Original release occurrence ·
15.0/migration/004Remove server-side language plpython2u and generic Python language plpythonu Compatibility Migration
Remove server-side language
plpython2uand generic Python languageplpythonu(Andres Freund) §Python 2.x is no longer supported. While the original intent of
plpythonuwas that it could eventually refer toplpython3u, changing it now seems more likely to cause problems than solve them, so it's just been removed.Original release occurrence ·
15.0/migration/005Generate an error if array_to_tsvector() is passed an empty-string array element Compatibility Migration
Generate an error if
array_to_tsvector()is passed an empty-string array element (Jean-Christophe Arnu) §This is prohibited because lexemes should never be empty. Users of previous Postgres releases should verify that no empty lexemes are stored because they can lead to dump/restore failures and inconsistent results.
Original release occurrence ·
15.0/migration/006Generate an error when chr() is supplied with a negative argument Compatibility Migration
Original release occurrence ·
15.0/migration/007Prevent CREATE OR REPLACE VIEW from changing the collation of an output column Compatibility Migration
Prevent
CREATE OR REPLACE VIEWfrom changing the collation of an output column (Tom Lane) §Original release occurrence ·
15.0/migration/008Disallow zero-length Unicode identifiers, e.g., U&"" Compatibility Migration
Disallow zero-length Unicode identifiers, e.g.,
U&""(Peter Eisentraut) §Non-Unicode zero-length identifiers were already disallowed.
Original release occurrence ·
15.0/migration/009Prevent numeric literals from having non-numeric trailing characters Compatibility Migration
Prevent numeric literals from having non-numeric trailing characters (Peter Eisentraut) §
Previously, query text like
123abcwould be interpreted as123followed by a separate tokenabc.Original release occurrence ·
15.0/migration/010Adjust JSON numeric literal processing to match the SQL/JSON-standard Compatibility Migration
Adjust JSON numeric literal processing to match the SQL/JSON-standard (Peter Eisentraut) §
This accepts numeric formats like
.1and1., and disallows trailing junk after numeric literals, like1.type().Original release occurrence ·
15.0/migration/011When interval input provides a fractional value for a unit greater than months, round to the nearest month Compatibility Migration
When
intervalinput provides a fractional value for a unit greater than months, round to the nearest month (Bruce Momjian) §For example, convert
1.99 yearsto2 years, not1 year 11 monthsas before.Original release occurrence ·
15.0/migration/012Improve consistency of interval parsing with trailing periods Compatibility Migration
Improve consistency of
intervalparsing with trailing periods (Tom Lane) §Numbers with trailing periods were rejected on some platforms.
Original release occurrence ·
15.0/migration/013Mark the interval output function as stable, not immutable, since it depends on IntervalStyle Compatibility Migration
Mark the
intervaloutput function as stable, not immutable, since it depends onIntervalStyle(Tom Lane) §This will, for example, cause creation of indexes relying on the text output of
intervalvalues to fail.Original release occurrence ·
15.0/migration/014Detect integer overflow in interval justification functions Compatibility Migration
Detect integer overflow in interval justification functions (Joe Koshakow) §
The affected functions are
justify_interval(),justify_hours(), andjustify_days().Original release occurrence ·
15.0/migration/015Change the I/O format of type "char" for non-ASCII characters Compatibility Migration
Change the I/O format of type
"char"for non-ASCII characters (Tom Lane) §Bytes with the high bit set are now output as a backslash and three octal digits, to avoid encoding issues.
Original release occurrence ·
15.0/migration/016Remove the default ADMIN OPTION privilege a login role has on its own role membership Compatibility Migration
Remove the default
ADMIN OPTIONprivilege a login role has on its own role membership (Robert Haas) §Previously, a login role could add/remove members of its own role, even without
ADMIN OPTIONprivilege.Original release occurrence ·
15.0/migration/017Allow logical replication to run as the owner of the subscription Compatibility Migration
Allow logical replication to run as the owner of the subscription (Mark Dilger) §
Because row-level security policies are not checked, only superusers, roles with
bypassrls, and table owners can replicate into tables with row-level security policies.Original release occurrence ·
15.0/migration/018Prevent UPDATE and DELETE logical replication operations on tables where the subscription owner does not have SELECT permission on the table Compatibility Migration
Prevent
UPDATEandDELETElogical replication operations on tables where the subscription owner does not haveSELECTpermission on the table (Jeff Davis) §UPDATEandDELETEcommands typically involve reading the table as well, so require the subscription owner to have tableSELECTpermission.Original release occurrence ·
15.0/migration/019When EXPLAIN references the session's temporary object schema, refer to it as pg_temp Compatibility Migration
When
EXPLAINreferences the session's temporary object schema, refer to it aspg_temp(Amul Sul) §Previously the actual schema name was reported, leading to inconsistencies across sessions.
Original release occurrence ·
15.0/migration/020Fix pg_statio_all_tables to sum values for the rare case of TOAST tables with multiple indexes Compatibility Migration
Fix
pg_statio_all_tablesto sum values for the rare case of TOAST tables with multiple indexes (Andrei Zubkov) §Previously such cases would show one row for each index.
Original release occurrence ·
15.0/migration/021Disallow setting custom options that match the name of an installed extension, but are not one of the extension's declared variables Compatibility Migration
Disallow setting custom options that match the name of an installed extension, but are not one of the extension's declared variables (Florin Irion, Tom Lane) § § §
This change causes any such pre-existing variables to be deleted during extension load, and then prevents new ones from being created later in the session. The intent is to prevent confusion about whether a variable is associated with an extension or not.
Original release occurrence ·
15.0/migration/022Remove obsolete server variable stats_temp_directory Compatibility Migration
Remove obsolete server variable
stats_temp_directory(Andres Freund, Kyotaro Horiguchi) §Original release occurrence ·
15.0/migration/023Improve the algorithm used to compute random() Compatibility Migration
Improve the algorithm used to compute
random()(Fabien Coelho) § §This will cause
random()'s results to differ from what was emitted by prior versions, even for the same seed value.Original release occurrence ·
15.0/migration/024libpq's PQsendQuery() function is no longer supported in pipeline mode Compatibility Migration
libpq's
PQsendQuery()function is no longer supported in pipeline mode (Álvaro Herrera) §Applications that are using that combination will need to be modified to use
PQsendQueryParams()instead.Original release occurrence ·
15.0/migration/025On non-Windows platforms, consult the HOME environment variable to find the user's home directory Compatibility Migration
On non-Windows platforms, consult the
HOMEenvironment variable to find the user's home directory (Anders Kaseorg) §If
HOMEis empty or unset, fall back to the previous method of checking the<pwd.h>database. This change affects libpq (for example, while looking up~/.pgpass) as well as various client application programs.Original release occurrence ·
15.0/migration/026Remove pg_dump's --no-synchronized-snapshots option Compatibility Migration
Remove pg_dump's
--no-synchronized-snapshotsoption (Tom Lane) §All still-supported server versions support synchronized snapshots, so there's no longer a need for this option.
Original release occurrence ·
15.0/migration/027After an error is detected in psql's --single-transaction mode, change the final COMMIT command to ROLLBACK only if ON_ERROR_STOP is set Compatibility Migration
After an error is detected in psql's
--single-transactionmode, change the finalCOMMITcommand toROLLBACKonly ifON_ERROR_STOPis set (Michael Paquier) §Original release occurrence ·
15.0/migration/028Avoid unnecessary casting of constants in queries sent by postgres_fdw Compatibility Migration
Avoid unnecessary casting of constants in queries sent by postgres_fdw (Dian Fay) §
When column types are intentionally different between local and remote databases, such casts could cause errors.
Original release occurrence ·
15.0/migration/029Remove xml2's xml_is_well_formed() function Compatibility Migration
Remove xml2's
xml_is_well_formed()function (Tom Lane) §This function has been implemented in the core backend since Postgres 9.1.
Original release occurrence ·
15.0/migration/030Allow custom scan providers to indicate if they support projections Compatibility Migration
Allow custom scan providers to indicate if they support projections (Sven Klemm) §
The default is now that custom scan providers are assumed to not support projections; those that do will need to be updated for this release.
Original release occurrence ·
15.0/migration/031Record and check the collation version of each database Features
Record and check the collation version of each database (Peter Eisentraut) §
This feature is designed to detect collation version changes to avoid index corruption. Function
pg_database_collation_actual_version()reports the underlying operating system collation version, andALTER DATABASE ... REFRESHsets the recorded database collation version to match the operating system collation version.Original release occurrence ·
15.0/changes/001Allow ICU collations to be set as the default for clusters and databases Features
Allow ICU collations to be set as the default for clusters and databases (Peter Eisentraut) §
Previously, only libc-based collations could be selected at the cluster and database levels. ICU collations could only be used via explicit
COLLATEclauses.Original release occurrence ·
15.0/changes/002Add system view pg_ident_file_mappings to report pg_ident.conf information Features
Add system view
pg_ident_file_mappingsto reportpg_ident.confinformation (Julien Rouhaud) §Original release occurrence ·
15.0/changes/003Improve planning time for queries referencing partitioned tables Features
Improve planning time for queries referencing partitioned tables (David Rowley) §
This change helps when only a few of many partitions are relevant.
Original release occurrence ·
15.0/changes/004Allow ordered scans of partitions to avoid sorting in more cases Features
Allow ordered scans of partitions to avoid sorting in more cases (David Rowley) §
Previously, a partitioned table with a
DEFAULTpartition or aLISTpartition containing multiple values could not be used for ordered partition scans. Now they can be used if such partitions are pruned during planning.Original release occurrence ·
15.0/changes/005Improve foreign key behavior of updates on partitioned tables that move rows between partitions Features
Improve foreign key behavior of updates on partitioned tables that move rows between partitions (Amit Langote) §
Previously, such updates ran a delete action on the source partition and an insert action on the target partition. PostgreSQL will now run an update action on the partition root, providing cleaner semantics.
Original release occurrence ·
15.0/changes/006Allow CLUSTER on partitioned tables Features
Original release occurrence ·
15.0/changes/007Fix ALTER TRIGGER RENAME on partitioned tables to properly rename triggers on all partitions Bug fixes
Fix
ALTER TRIGGER RENAMEon partitioned tables to properly rename triggers on all partitions (Arne Roland, Álvaro Herrera) §Also prohibit cloned triggers from being renamed.
Original release occurrence ·
15.0/changes/008Allow btree indexes on system and TOAST tables to efficiently store duplicates Features
Allow btree indexes on system and TOAST tables to efficiently store duplicates (Peter Geoghegan) §
Previously de-duplication was disabled for these types of indexes.
Original release occurrence ·
15.0/changes/009Improve lookup performance of GiST indexes that were built using sorting Performance
Improve lookup performance of GiST indexes that were built using sorting (Aliaksandr Kalenik, Sergei Shoulbakov, Andrey Borodin) §
Original release occurrence ·
15.0/changes/010Allow unique constraints and indexes to treat NULL values as not distinct Features
Allow unique constraints and indexes to treat
NULLvalues as not distinct (Peter Eisentraut) §Previously
NULLentries were always treated as distinct values, but this can now be changed by creating constraints and indexes usingUNIQUE NULLS NOT DISTINCT.Original release occurrence ·
15.0/changes/011Allow the ^@ starts-with operator and the starts_with() function to use btree indexes if using the C collation Features
Allow the
^@starts-with operator and thestarts_with()function to use btree indexes if using the C collation (Tom Lane) §Previously these could only use SP-GiST indexes.
Original release occurrence ·
15.0/changes/012Allow extended statistics to record statistics for a parent with all its children Features
Allow extended statistics to record statistics for a parent with all its children (Tomas Vondra, Justin Pryzby) §
Regular statistics already tracked parent and parent-plus-all-children statistics separately.
Original release occurrence ·
15.0/changes/013Add server variable recursive_worktable_factor to allow the user to specify the expected size of the working table of a recursive query Features
Add server variable
recursive_worktable_factorto allow the user to specify the expected size of the working table of a recursive query (Simon Riggs) §Original release occurrence ·
15.0/changes/014Allow hash lookup for NOT IN clauses with many constants Performance
Allow hash lookup for
NOT INclauses with many constants (David Rowley, James Coleman) §Previously the code always sequentially scanned the list of values.
Original release occurrence ·
15.0/changes/015Allow SELECT DISTINCT to be parallelized Performance
Allow
SELECT DISTINCTto be parallelized (David Rowley) §Original release occurrence ·
15.0/changes/016Speed up encoding validation of UTF-8 text by processing 16 bytes at a time Performance
Speed up encoding validation of UTF-8 text by processing 16 bytes at a time (John Naylor, Heikki Linnakangas) §
This will improve text-heavy operations like
COPY FROM.Original release occurrence ·
15.0/changes/017Improve performance for sorts that exceed work_mem Performance
Improve performance for sorts that exceed
work_mem(Heikki Linnakangas) § §When the sort data no longer fits in
work_mem, switch to a batch sorting algorithm that uses more output streams than before.Original release occurrence ·
15.0/changes/018Improve performance and reduce memory consumption of in-memory sorts Performance
Improve performance and reduce memory consumption of in-memory sorts (Ronan Dunklau, David Rowley, Thomas Munro, John Naylor) § § §
Original release occurrence ·
15.0/changes/019Allow WAL full page writes to use LZ4 and Zstandard compression Performance
Allow WAL full page writes to use LZ4 and Zstandard compression (Andrey Borodin, Justin Pryzby) § §
This is controlled by the
wal_compressionserver setting.Original release occurrence ·
15.0/changes/020Add support for writing WAL using direct I/O on macOS Performance
Add support for writing WAL using direct I/O on macOS (Thomas Munro) §
This only works if
max_wal_senders = 0andwal_level = minimal.Original release occurrence ·
15.0/changes/021Allow vacuum to be more aggressive in setting the oldest frozen and multi transaction id Performance
Allow vacuum to be more aggressive in setting the oldest frozen and multi transaction id (Peter Geoghegan) §
Original release occurrence ·
15.0/changes/022Allow a query referencing multiple foreign tables to perform parallel foreign table scans in more cases Performance
Allow a query referencing multiple foreign tables to perform parallel foreign table scans in more cases (Andrey Lepikhov, Etsuro Fujita) §
Original release occurrence ·
15.0/changes/023Improve the performance of window functions that use row_number(), rank(), dense_rank() and count() Performance
Improve the performance of window functions that use
row_number(),rank(),dense_rank()andcount()(David Rowley) §Original release occurrence ·
15.0/changes/024Improve the performance of spinlocks on high-core-count ARM64 systems Performance
Improve the performance of spinlocks on high-core-count ARM64 systems (Geoffrey Blake) §
Original release occurrence ·
15.0/changes/025Enable default logging of checkpoints and slow autovacuum operations Features
Enable default logging of checkpoints and slow autovacuum operations (Bharath Rupireddy) §
This changes the default of
log_checkpointstoonand that oflog_autovacuum_min_durationto 10 minutes. This will cause even an idle server to generate some log output, which might cause problems on resource-constrained servers without log file rotation. These defaults should be changed in such cases.Original release occurrence ·
15.0/changes/026Generate progress messages in the server log during slow server starts Features
Generate progress messages in the server log during slow server starts (Nitin Jadhav, Robert Haas) § §
The messages report the cause of the delay. The time interval for notification is controlled by the new server variable
log_startup_progress_interval.Original release occurrence ·
15.0/changes/027Store cumulative statistics system data in shared memory Features
Store cumulative statistics system data in shared memory (Kyotaro Horiguchi, Andres Freund, Melanie Plageman) § §
Previously this data was sent to a statistics collector process via UDP packets, and could only be read by sessions after transferring it via the file system. There is no longer a separate statistics collector process.
Original release occurrence ·
15.0/changes/028Add additional information to VACUUM VERBOSE and autovacuum logging messages Features
Add additional information to
VACUUM VERBOSEand autovacuum logging messages (Peter Geoghegan) § § §Original release occurrence ·
15.0/changes/029Add EXPLAIN (BUFFERS) output for temporary file block I/O Features
Add
EXPLAIN (BUFFERS)output for temporary file block I/O (Masahiko Sawada) §Original release occurrence ·
15.0/changes/030Allow log output in JSON format Features
Allow log output in JSON format (Sehrope Sarkuni, Michael Paquier) §
The new setting is
log_destination = jsonlog.Original release occurrence ·
15.0/changes/031Allow pg_stat_reset_single_table_counters() to reset the counters of relations shared across all databases Features
Allow
pg_stat_reset_single_table_counters()to reset the counters of relations shared across all databases (Sadhuprasad Patro) §Original release occurrence ·
15.0/changes/032Add wait events for local shell commands Features
Add wait events for local shell commands (Fujii Masao) §
The new wait events are used when calling
archive_command,archive_cleanup_command,restore_commandandrecovery_end_command.Original release occurrence ·
15.0/changes/033Allow table accesses done by a view to optionally be controlled by privileges of the view's caller Features
Allow table accesses done by a view to optionally be controlled by privileges of the view's caller (Christoph Heiss) §
Previously, view accesses were always treated as being done by the view's owner. That's still the default.
Original release occurrence ·
15.0/changes/034Allow members of the pg_write_server_files predefined role to perform server-side base backups Features
Allow members of the
pg_write_server_filespredefined role to perform server-side base backups (Dagfinn Ilmari Mannsåker) §Previously only superusers could perform such backups.
Original release occurrence ·
15.0/changes/035Allow GRANT to grant permissions to change individual server variables via SET and ALTER SYSTEM Features
Allow
GRANTto grant permissions to change individual server variables viaSETandALTER SYSTEM(Mark Dilger) § §The new function
has_parameter_privilege()reports on this privilege.Original release occurrence ·
15.0/changes/036Add predefined role pg_checkpoint that allows members to run CHECKPOINT Features
Add predefined role
pg_checkpointthat allows members to runCHECKPOINT(Jeff Davis) § §Previously checkpoints could only be run by superusers.
Original release occurrence ·
15.0/changes/037Allow members of the pg_read_all_stats predefined role to access the views pg_backend_memory_contexts and pg_shmem_allocations Features
Allow members of the
pg_read_all_statspredefined role to access the viewspg_backend_memory_contextsandpg_shmem_allocations(Bharath Rupireddy) §Previously these views could only be accessed by superusers.
Original release occurrence ·
15.0/changes/038Allow GRANT to grant permissions on pg_log_backend_memory_contexts() Features
Allow
GRANTto grant permissions onpg_log_backend_memory_contexts()(Jeff Davis) §Previously this function could only be run by superusers.
Original release occurrence ·
15.0/changes/039Add server variable shared_memory_size to report the size of allocated shared memory Features
Add server variable
shared_memory_sizeto report the size of allocated shared memory (Nathan Bossart) § §Original release occurrence ·
15.0/changes/040Add server variable shared_memory_size_in_huge_pages to report the number of huge memory pages required Features
Add server variable
shared_memory_size_in_huge_pagesto report the number of huge memory pages required (Nathan Bossart) § §This is only supported on Linux.
Original release occurrence ·
15.0/changes/041Honor server variable shared_preload_libraries in single-user mode Features
Honor server variable
shared_preload_librariesin single-user mode (Jeff Davis) §This change supports use of
shared_preload_librariesto load custom access methods and WAL resource managers, which would be essential for database access even in single-user mode.Original release occurrence ·
15.0/changes/042On Solaris, make the default setting of dynamic_shared_memory_type be sysv Features
On Solaris, make the default setting of
dynamic_shared_memory_typebesysv(Thomas Munro) §The previous default choice,
posix, can result in spurious failures on this platform.Original release occurrence ·
15.0/changes/043Allow postgres -C to properly report runtime-computed values Features
Allow
postgres -Cto properly report runtime-computed values (Nathan Bossart) §Previously runtime-computed values
data_checksums,wal_segment_size, anddata_directory_modewould report values that would not be accurate on the running server. However, this does not work on a running server.Original release occurrence ·
15.0/changes/044Add support for LZ4 and Zstandard compression of server-side base backups Features
Add support for LZ4 and Zstandard compression of server-side base backups (Jeevan Ladhe, Robert Haas) § § §
Original release occurrence ·
15.0/changes/045Run the checkpointer and bgwriter processes during crash recovery Features
Run the checkpointer and bgwriter processes during crash recovery (Thomas Munro) §
This helps to speed up long crash recoveries.
Original release occurrence ·
15.0/changes/046Allow WAL processing to pre-fetch needed file contents Features
Allow WAL processing to pre-fetch needed file contents (Thomas Munro) §
This is controlled by the server variable
recovery_prefetch.Original release occurrence ·
15.0/changes/047Allow archiving via loadable modules Features
Allow archiving via loadable modules (Nathan Bossart) §
Previously, archiving was only done by calling shell commands. The new server variable
archive_librarycan be set to specify a library to be called for archiving.Original release occurrence ·
15.0/changes/048No longer require IDENTIFY_SYSTEM to be run before START_REPLICATION Features
No longer require
IDENTIFY_SYSTEMto be run beforeSTART_REPLICATION(Jeff Davis) §Original release occurrence ·
15.0/changes/049Allow publication of all tables in a schema Features
Allow publication of all tables in a schema (Vignesh C, Hou Zhijie, Amit Kapila) § § §
For example, this syntax is now supported:
CREATE PUBLICATION pub1 FOR TABLES IN SCHEMA s1,s2.ALTER PUBLICATIONsupports a similar syntax. Tables added later to the listed schemas will also be replicated.Original release occurrence ·
15.0/changes/050Allow publication content to be filtered using a WHERE clause Features
Allow publication content to be filtered using a
WHEREclause (Hou Zhijie, Euler Taveira, Peter Smith, Ajin Cherian, Tomas Vondra, Amit Kapila) § § §Rows not satisfying the
WHEREclause are not published.Original release occurrence ·
15.0/changes/051Allow publication content to be restricted to specific columns Features
Allow publication content to be restricted to specific columns (Tomas Vondra, Álvaro Herrera, Rahila Syed) §
Original release occurrence ·
15.0/changes/052Allow skipping of transactions on a subscriber using ALTER SUBSCRIPTION ... SKIP Features
Allow skipping of transactions on a subscriber using
ALTER SUBSCRIPTION ... SKIP(Masahiko Sawada) §Original release occurrence ·
15.0/changes/053Add support for prepared (two-phase) transactions to logical replication Features
Add support for prepared (two-phase) transactions to logical replication (Peter Smith, Ajin Cherian, Amit Kapila, Nikhil Sontakke, Stas Kelvich) § § §
The new
CREATE_REPLICATION_SLOToption is calledTWO_PHASE. pg_recvlogical now supports a new--two-phaseoption during slot creation.Original release occurrence ·
15.0/changes/054Prevent logical replication of empty transactions Features
Prevent logical replication of empty transactions (Ajin Cherian, Hou Zhijie, Euler Taveira) §
Previously, publishers would send empty transactions to subscribers if subscribed tables were not modified.
Original release occurrence ·
15.0/changes/055Add SQL functions to monitor the directory contents of logical replication slots Features
Add SQL functions to monitor the directory contents of logical replication slots (Bharath Rupireddy) §
The new functions are
pg_ls_logicalsnapdir(),pg_ls_logicalmapdir(), andpg_ls_replslotdir(). They can be run by members of the predefinedpg_monitorrole.Original release occurrence ·
15.0/changes/056Allow subscribers to stop the application of logical replication changes on error Features
Allow subscribers to stop the application of logical replication changes on error (Osumi Takamichi, Mark Dilger) §
This is enabled with the subscriber option
disable_on_errorand avoids possible infinite error loops during stream application.Original release occurrence ·
15.0/changes/057Adjust subscriber server variables to match the publisher so datetime and float8 values are interpreted consistently Features
Adjust subscriber server variables to match the publisher so datetime and float8 values are interpreted consistently (Japin Li) §
Some publishers might be relying on inconsistent behavior.
Original release occurrence ·
15.0/changes/058Add system view pg_stat_subscription_stats to report on subscriber activity Features
Add system view
pg_stat_subscription_statsto report on subscriber activity (Masahiko Sawada) § §The new function
pg_stat_reset_subscription_stats()allows resetting these statistics counters.Original release occurrence ·
15.0/changes/059Suppress duplicate entries in the pg_publication_tables system view Features
Suppress duplicate entries in the
pg_publication_tablessystem view (Hou Zhijie) §In some cases a partition could appear more than once.
Original release occurrence ·
15.0/changes/060Add SQL MERGE command to adjust one table to match another Features
Add SQL
MERGEcommand to adjust one table to match another (Simon Riggs, Pavan Deolasee, Álvaro Herrera, Amit Langote) §This is similar to
INSERT ... ON CONFLICTbut more batch-oriented.Original release occurrence ·
15.0/changes/061Add support for HEADER option in COPY text format Features
Add support for
HEADERoption inCOPYtext format (Rémi Lapeyre) § §The new option causes the column names to be output, and optionally verified on input.
Original release occurrence ·
15.0/changes/062Add new WAL-logged method for database creation Features
Add new WAL-logged method for database creation (Dilip Kumar) §
This is the new default method for copying the template database, as it avoids the need for checkpoints during database creation. However, it might be slow if the template database is large, so the old method is still available.
Original release occurrence ·
15.0/changes/063Allow CREATE DATABASE to set the database OID Features
Allow
CREATE DATABASEto set the database OID (Shruthi Gowda, Antonin Houska) §Original release occurrence ·
15.0/changes/064Prevent DROP DATABASE, DROP TABLESPACE, and ALTER DATABASE SET TABLESPACE from occasionally failing during concurrent use on Windows Features
Prevent
DROP DATABASE,DROP TABLESPACE, andALTER DATABASE SET TABLESPACEfrom occasionally failing during concurrent use on Windows (Thomas Munro) §Original release occurrence ·
15.0/changes/065Allow foreign key ON DELETE SET actions to affect only specified columns Features
Allow foreign key
ON DELETE SETactions to affect only specified columns (Paul Martinez) §Previously, all of the columns in the foreign key were always affected.
Original release occurrence ·
15.0/changes/066Allow ALTER TABLE to modify a table's ACCESS METHOD Features
Allow
ALTER TABLEto modify a table'sACCESS METHOD(Justin Pryzby, Jeff Davis) §Original release occurrence ·
15.0/changes/067Properly call object access hooks when ALTER TABLE causes table rewrites Features
Properly call object access hooks when
ALTER TABLEcauses table rewrites (Michael Paquier) §Original release occurrence ·
15.0/changes/068Allow creation of unlogged sequences Features
Original release occurrence ·
15.0/changes/069Track dependencies on individual columns in the results of functions returning composite types Features
Track dependencies on individual columns in the results of functions returning composite types (Tom Lane) §
Previously, if a view or rule contained a reference to a specific column within the result of a composite-returning function, that was not noted as a dependency; the view or rule was only considered to depend on the composite type as a whole. This meant that dropping the individual column would be allowed, causing problems in later use of the view or rule. The column-level dependency is now also noted, so that dropping such a column will be rejected unless the view is changed or dropped.
Original release occurrence ·
15.0/changes/070Allow the scale of a numeric value to be negative, or greater than its precision Features
Allow the scale of a
numericvalue to be negative, or greater than its precision (Dean Rasheed, Tom Lane) §This allows rounding of values to the left of the decimal point, e.g.,
'1234'::numeric(4, -2)returns 1200.Original release occurrence ·
15.0/changes/071Improve overflow detection when casting values to interval Features
Original release occurrence ·
15.0/changes/072Change the I/O format of type "char" for non-ASCII characters Features
Change the I/O format of type
"char"for non-ASCII characters (Tom Lane) §Original release occurrence ·
15.0/changes/073Update the display width information of modern Unicode characters, like emojis Features
Update the display width information of modern Unicode characters, like emojis (Jacob Champion) § §
Also update from Unicode 5.0 to 14.0.0. There is now an automated way to keep Postgres updated with Unicode releases.
Original release occurrence ·
15.0/changes/074Add multirange input to range_agg() Features
Add multirange input to
range_agg()(Paul Jungwirth) §Original release occurrence ·
15.0/changes/075Add MIN() and MAX() aggregates for the xid8 data type Features
Original release occurrence ·
15.0/changes/076Add regular expression functions for compatibility with other relational systems Features
Add regular expression functions for compatibility with other relational systems (Gilles Darold, Tom Lane) §
The new functions are
regexp_count(),regexp_instr(),regexp_like(), andregexp_substr(). Some new optional arguments were also added toregexp_replace().Original release occurrence ·
15.0/changes/077Add the ability to compute the distance between polygons Features
Original release occurrence ·
15.0/changes/078Add to_char() format codes of, tzh, and tzm Features
Add
to_char()format codesof,tzh, andtzm(Nitin Jadhav) §The upper-case equivalents of these were already supported.
Original release occurrence ·
15.0/changes/079When applying AT TIME ZONE to a time with time zone value, use the transaction start time rather than wall clock time to determine whether DST applies Features
When applying
AT TIME ZONEto atime with time zonevalue, use the transaction start time rather than wall clock time to determine whether DST applies (Aleksander Alekseev, Tom Lane) §This allows the conversion to be considered stable rather than volatile, and it saves a kernel call per invocation.
Original release occurrence ·
15.0/changes/080Ignore NULL array elements in ts_delete() and setweight() functions with array arguments Features
Ignore NULL array elements in
ts_delete()andsetweight()functions with array arguments (Jean-Christophe Arnu) §These functions effectively ignore empty-string array elements (since those could never match a valid lexeme). It seems consistent to let them ignore NULL elements too, instead of failing.
Original release occurrence ·
15.0/changes/081Add support for petabyte units to pg_size_pretty() and pg_size_bytes() Features
Add support for petabyte units to
pg_size_pretty()andpg_size_bytes()(David Christensen) §Original release occurrence ·
15.0/changes/082Change pg_event_trigger_ddl_commands() to output references to other sessions' temporary schemas using the actual schema name Features
Change
pg_event_trigger_ddl_commands()to output references to other sessions' temporary schemas using the actual schema name (Tom Lane) §Previously this function reported all temporary schemas as
pg_temp, but it's misleading to use that for any but the current session's temporary schema.Original release occurrence ·
15.0/changes/083Fix enforcement of PL/pgSQL variable CONSTANT markings Bug fixes
Fix enforcement of PL/pgSQL variable
CONSTANTmarkings (Tom Lane) §Previously, a variable could be used as a
CALLoutput parameter or refcursorOPENvariable despite being markedCONSTANT.Original release occurrence ·
15.0/changes/084Allow IP address matching against a server certificate's Subject Alternative Name Features
Allow IP address matching against a server certificate's Subject Alternative Name (Jacob Champion) §
Original release occurrence ·
15.0/changes/085Allow PQsslAttribute() to report the SSL library type without requiring a libpq connection Features
Allow
PQsslAttribute()to report the SSL library type without requiring a libpq connection (Jacob Champion) §Original release occurrence ·
15.0/changes/086Change query cancellations sent by the client to use the same TCP settings as normal client connections Features
Change query cancellations sent by the client to use the same TCP settings as normal client connections (Jelte Fennema) §
This allows configured TCP timeouts to apply to query cancel connections.
Original release occurrence ·
15.0/changes/087Prevent libpq event callback failures from forcing an error result Features
Original release occurrence ·
15.0/changes/088Allow pgbench to retry after serialization and deadlock failures Features
Original release occurrence ·
15.0/changes/089Improve performance of psql's \copy command, by sending data in larger chunks Performance
Improve performance of psql's
\copycommand, by sending data in larger chunks (Heikki Linnakangas) §Original release occurrence ·
15.0/changes/090Add \dconfig command to report server variables Features
Add
\dconfigcommand to report server variables (Mark Dilger, Tom Lane) § § §This is similar to the server-side
SHOWcommand, but it can process patterns to show multiple variables conveniently.Original release occurrence ·
15.0/changes/091Add \getenv command to assign the value of an environment variable to a psql variable Features
Add
\getenvcommand to assign the value of an environment variable to a psql variable (Tom Lane) §Original release occurrence ·
15.0/changes/092Add + option to the \lo_list and \dl commands to show large-object privileges Features
Add
+option to the\lo_listand\dlcommands to show large-object privileges (Pavel Luzanov) §Original release occurrence ·
15.0/changes/093Add a pager option for the \watch command Features
Add a pager option for the
\watchcommand (Pavel Stehule, Thomas Munro) §This is only supported on Unix and is controlled by the
PSQL_WATCH_PAGERenvironment variable.Original release occurrence ·
15.0/changes/094Make psql include intra-query double-hyphen comments in queries sent to the server Features
Make psql include intra-query double-hyphen comments in queries sent to the server (Tom Lane, Greg Nancarrow) § §
Previously such comments were removed from the query before being sent. Double-hyphen comments that are before any query text are not sent, and are not recorded as separate psql history entries.
Original release occurrence ·
15.0/changes/095Adjust psql so that Readline's meta-# command will insert a double-hyphen comment marker Features
Adjust psql so that Readline's meta-
#command will insert a double-hyphen comment marker (Tom Lane) §Previously a pound marker was inserted, unless the user had taken the trouble to configure a non-default comment marker.
Original release occurrence ·
15.0/changes/096Make psql output all results when multiple queries are passed to the server at once Features
Make psql output all results when multiple queries are passed to the server at once (Fabien Coelho) §
Previously, only the last query result was displayed. The old behavior can be restored by setting the
SHOW_ALL_RESULTSpsql variable tooff.Original release occurrence ·
15.0/changes/097After an error is detected in --single-transaction mode, change the final COMMIT command to ROLLBACK only if ON_ERROR_STOP is set Features
After an error is detected in
--single-transactionmode, change the finalCOMMITcommand toROLLBACKonly ifON_ERROR_STOPis set (Michael Paquier) §Previously, detection of an error in a
-ccommand or-fscript file would lead to issuingROLLBACKat the end, regardless of the value ofON_ERROR_STOP.Original release occurrence ·
15.0/changes/098Improve psql's tab completion Features
Improve psql's tab completion (Shinya Kato, Dagfinn Ilmari Mannsåker, Peter Smith, Koyu Tanigawa, Ken Kato, David Fetter, Haiying Tang, Peter Eisentraut, Álvaro Herrera, Tom Lane, Masahiko Sawada) § § § § § § § § § § § § § § § § § § § §
Original release occurrence ·
15.0/changes/099Limit support of psql's backslash commands to servers running PostgreSQL 9.2 or later Features
Limit support of psql's backslash commands to servers running PostgreSQL 9.2 or later (Tom Lane) §
Remove code that was only used when running with an older server. Commands that do not require any version-specific adjustments compared to 9.2 will still work.
Original release occurrence ·
15.0/changes/100Make pg_dump dump public schema ownership changes and security labels Features
Original release occurrence ·
15.0/changes/101Improve performance of dumping databases with many objects Performance
Improve performance of dumping databases with many objects (Tom Lane) § § §
This will also improve the performance of pg_upgrade.
Original release occurrence ·
15.0/changes/102Improve parallel pg_dump's performance for tables with large TOAST tables Performance
Improve parallel pg_dump's performance for tables with large TOAST tables (Tom Lane) §
Original release occurrence ·
15.0/changes/103Add dump/restore option --no-table-access-method to force restore to only use the default table access method Features
Add dump/restore option
--no-table-access-methodto force restore to only use the default table access method (Justin Pryzby) §Original release occurrence ·
15.0/changes/104Limit support of pg_dump and pg_dumpall to servers running PostgreSQL 9.2 or later Features
Limit support of pg_dump and pg_dumpall to servers running PostgreSQL 9.2 or later (Tom Lane) §
Original release occurrence ·
15.0/changes/105Add new pg_basebackup option --target to control the base backup location Features
Add new pg_basebackup option
--targetto control the base backup location (Robert Haas) §The new options are
serverto write the backup locally andblackholeto discard the backup (for testing).Original release occurrence ·
15.0/changes/106Allow pg_basebackup to do server-side gzip, LZ4, and Zstandard compression and client-side LZ4 and Zstandard compression of base backup files Features
Allow pg_basebackup to do server-side gzip, LZ4, and Zstandard compression and client-side LZ4 and Zstandard compression of base backup files (Dipesh Pandit, Jeevan Ladhe) § § §
Client-side
gzipcompression was already supported.Original release occurrence ·
15.0/changes/107Allow pg_basebackup to compress on the server side and decompress on the client side before storage Features
Allow pg_basebackup to compress on the server side and decompress on the client side before storage (Dipesh Pandit) §
This is accomplished by specifying compression on the server side and plain output format.
Original release occurrence ·
15.0/changes/108Allow pg_basebackup's --compress option to control the compression location (server or client), compression method, and compression options Features
Allow pg_basebackup's
--compressoption to control the compression location (server or client), compression method, and compression options (Michael Paquier, Robert Haas) § § §Original release occurrence ·
15.0/changes/109Add the LZ4 compression method to pg_receivewal Features
Add the LZ4 compression method to pg_receivewal (Georgios Kokolatos) § §
This is enabled via
--compress=lz4and requires binaries to be built using--with-lz4.Original release occurrence ·
15.0/changes/110Add additional capabilities to pg_receivewal's --compress option Features
Add additional capabilities to pg_receivewal's
--compressoption (Georgios Kokolatos) §Original release occurrence ·
15.0/changes/111Improve pg_receivewal's ability to restart at the proper WAL location Features
Improve pg_receivewal's ability to restart at the proper WAL location (Ronan Dunklau) §
Previously, pg_receivewal would start based on the WAL file stored in the local archive directory, or at the sending server's current WAL flush location. With this change, if the sending server is running Postgres 15 or later, the local archive directory is empty, and a replication slot is specified, the replication slot's restart point will be used.
Original release occurrence ·
15.0/changes/112Add pg_rewind option --config-file to simplify use when server configuration files are stored outside the data directory Features
Add pg_rewind option
--config-fileto simplify use when server configuration files are stored outside the data directory (Gunnar Bluth) §Original release occurrence ·
15.0/changes/113Store pg_upgrade's log and temporary files in a subdirectory of the new cluster called pg_upgrade_output.d Features
Store pg_upgrade's log and temporary files in a subdirectory of the new cluster called
pg_upgrade_output.d(Justin Pryzby) § § §Previously such files were left in the current directory, requiring manual cleanup. Now they are automatically removed on successful completion of pg_upgrade.
Original release occurrence ·
15.0/changes/114Disable default status reporting during pg_upgrade operation if the output is not a terminal Features
Disable default status reporting during pg_upgrade operation if the output is not a terminal (Andres Freund) §
The status reporting output can be enabled for non-tty usage by using
--verbose.Original release occurrence ·
15.0/changes/115Make pg_upgrade report all databases with invalid connection settings Features
Make pg_upgrade report all databases with invalid connection settings (Jeevan Ladhe) §
Previously only the first database with an invalid connection setting was reported.
Original release occurrence ·
15.0/changes/116Make pg_upgrade preserve tablespace and database OIDs, as well as relation relfilenode numbers Features
Make pg_upgrade preserve tablespace and database OIDs, as well as relation relfilenode numbers (Shruthi Gowda, Antonin Houska) § § §
Original release occurrence ·
15.0/changes/117Add a --no-sync option to pg_upgrade Features
Add a
--no-syncoption to pg_upgrade (Michael Paquier) §This is recommended only for testing.
Original release occurrence ·
15.0/changes/118Limit support of pg_upgrade to old servers running PostgreSQL 9.2 or later Features
Limit support of pg_upgrade to old servers running PostgreSQL 9.2 or later (Tom Lane) §
Original release occurrence ·
15.0/changes/119Allow pg_waldump output to be filtered by relation file node, block number, fork number, and full page images Features
Allow pg_waldump output to be filtered by relation file node, block number, fork number, and full page images (David Christensen, Thomas Munro) § §
Original release occurrence ·
15.0/changes/120Make pg_waldump report statistics before an interrupted exit Features
Make pg_waldump report statistics before an interrupted exit (Bharath Rupireddy) §
For example, issuing a control-C in a terminal running
pg_waldump --stats --followwill report the current statistics before exiting. This does not work on Windows.Original release occurrence ·
15.0/changes/121Improve descriptions of some transaction WAL records reported by pg_waldump Features
Improve descriptions of some transaction WAL records reported by pg_waldump (Masahiko Sawada, Michael Paquier) §
Original release occurrence ·
15.0/changes/122Allow pg_waldump to dump information about multiple resource managers Features
Allow pg_waldump to dump information about multiple resource managers (Heikki Linnakangas) §
This is enabled by specifying the
--rmgroption multiple times.Original release occurrence ·
15.0/changes/123Add documentation for pg_encoding_to_char() and pg_char_to_encoding() Features
Add documentation for
pg_encoding_to_char()andpg_char_to_encoding()(Ian Lawrence Barwick) §Original release occurrence ·
15.0/changes/124Document the ^@ starts-with operator Features
Original release occurrence ·
15.0/changes/125Add support for continuous integration testing using cirrus-ci Features
Add support for continuous integration testing using cirrus-ci (Andres Freund, Thomas Munro, Melanie Plageman) §
Original release occurrence ·
15.0/changes/126Add configure option --with-zstd to enable Zstandard builds Features
Add configure option
--with-zstdto enable Zstandard builds (Jeevan Ladhe, Robert Haas, Michael Paquier) §Original release occurrence ·
15.0/changes/127Add an ABI identifier field to the magic block in loadable libraries, allowing non-community PostgreSQL distributions to identify libraries that are not compatible with other builds Features
Add an ABI identifier field to the magic block in loadable libraries, allowing non-community PostgreSQL distributions to identify libraries that are not compatible with other builds (Peter Eisentraut) §
An ABI field mismatch will generate an error at load time.
Original release occurrence ·
15.0/changes/128Create a new pg_type.typcategory value for "char" Features
Create a new
pg_type.typcategoryvalue for"char"(Tom Lane) §Some other internal-use-only types have also been assigned to this category.
Original release occurrence ·
15.0/changes/129Add new protocol message TARGET to specify a new COPY method to be used for base backups Features
Add new protocol message
TARGETto specify a newCOPYmethod to be used for base backups (Robert Haas) §pg_basebackup now uses this method.
Original release occurrence ·
15.0/changes/130Add new protocol message COMPRESSION and COMPRESSION_DETAIL to specify the compression method and options Features
Add new protocol message
COMPRESSIONandCOMPRESSION_DETAILto specify the compression method and options (Robert Haas) § §Original release occurrence ·
15.0/changes/131Remove server support for old BASE_BACKUP command syntax and base backup protocol Features
Original release occurrence ·
15.0/changes/132Add support for extensions to set custom backup targets Features
Add support for extensions to set custom backup targets (Robert Haas) §
Original release occurrence ·
15.0/changes/133Allow extensions to define custom WAL resource managers Features
Allow extensions to define custom WAL resource managers (Jeff Davis) §
Original release occurrence ·
15.0/changes/134Add function pg_settings_get_flags() to get the flags of server variables Features
Add function
pg_settings_get_flags()to get the flags of server variables (Justin Pryzby) §Original release occurrence ·
15.0/changes/135On Windows, export all the server's global variables using PGDLLIMPORT markers Features
On Windows, export all the server's global variables using
PGDLLIMPORTmarkers (Robert Haas) §Previously, only specific variables were accessible to extensions on Windows.
Original release occurrence ·
15.0/changes/136Require GNU make version 3.81 or later to build PostgreSQL Features
Require GNU make version 3.81 or later to build PostgreSQL (Tom Lane) §
Original release occurrence ·
15.0/changes/137Require OpenSSL to build the pgcrypto extension Features
Original release occurrence ·
15.0/changes/138Require Perl version 5.8.3 or later Features
Require Perl version 5.8.3 or later (Dagfinn Ilmari Mannsåker) §
Original release occurrence ·
15.0/changes/139Require Python version 3.2 or later Features
Require Python version 3.2 or later (Andres Freund) §
Original release occurrence ·
15.0/changes/140Allow amcheck to check sequences Features
Original release occurrence ·
15.0/changes/141Improve amcheck sanity checks for TOAST tables Features
Improve amcheck sanity checks for TOAST tables (Mark Dilger) §
Original release occurrence ·
15.0/changes/142Add new module basebackup_to_shell as an example of a custom backup target Features
Add new module basebackup_to_shell as an example of a custom backup target (Robert Haas) § §
Original release occurrence ·
15.0/changes/143Add new module basic_archive as an example of performing archiving via a library Features
Add new module basic_archive as an example of performing archiving via a library (Nathan Bossart) §
Original release occurrence ·
15.0/changes/144Allow btree_gist indexes on boolean columns Features
Allow btree_gist indexes on boolean columns (Emre Hasegeli) § § §
These can be used for exclusion constraints.
Original release occurrence ·
15.0/changes/145Fix pageinspect's page_header() to handle 32-kilobyte page sizes Bug fixes
Fix pageinspect's
page_header()to handle 32-kilobyte page sizes (Quan Zongliang) §Previously, improper negative values could be returned in certain cases.
Original release occurrence ·
15.0/changes/146Add counters for temporary file block I/O to pg_stat_statements Features
Add counters for temporary file block I/O to pg_stat_statements (Masahiko Sawada) §
Original release occurrence ·
15.0/changes/147Add JIT counters to pg_stat_statements Features
Add JIT counters to pg_stat_statements (Magnus Hagander) §
Original release occurrence ·
15.0/changes/148Add new module pg_walinspect Features
Add new module pg_walinspect (Bharath Rupireddy) §
This gives SQL-level output similar to pg_waldump.
Original release occurrence ·
15.0/changes/149Indicate the permissive/enforcing state in sepgsql log messages Features
Original release occurrence ·
15.0/changes/150Allow postgres_fdw to push down CASE expressions Features
Allow postgres_fdw to push down
CASEexpressions (Alexander Pyhalov) §Original release occurrence ·
15.0/changes/151Add server variable postgres_fdw.application_name to control the application name of postgres_fdw connections Features
Add server variable
postgres_fdw.application_nameto control the application name of postgres_fdw connections (Hayato Kuroda) § § §Previously the remote session's
application_namecould only be set on the remote server or via a postgres_fdw connection specification.postgres_fdw.application_namesupports some escape sequences for customization, making it easier to tell such connections apart on the remote server.Original release occurrence ·
15.0/changes/152Allow parallel commit on postgres_fdw servers Features
Allow parallel commit on postgres_fdw servers (Etsuro Fujita) §
This is enabled with the
CREATE SERVERoptionparallel_commit.Original release occurrence ·
15.0/changes/153
Security evidence
65 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.
CVE-2026-6637 · PostgreSQL refint allows stack buffer overflow and SQL injection CVSS 8.8
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 15.18. Component: contrib module.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6479 · PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion CVSS 7.5
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 15.18. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2026-6478 · PostgreSQL discloses MD5-hashed passwords via covert timing channel CVSS 6.5
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 15.18. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-6477 · PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory CVSS 8.8
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 15.18. Component: client.
Official affected-branch entry: 15.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6475 · PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice CVSS 8.8
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 15.18. Component: client.
Official affected-branch entry: 15.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6474 · PostgreSQL timeofday() can disclose portions of server memory CVSS 4.3
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 15.18. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-6473 · PostgreSQL server undersizes allocations, via integer wraparound CVSS 8.8
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 15.18. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
- 15.19: Fix integer overflows in memory-allocation calculations in PL/Perl and PL/Tcl
- 15.18: Fix assorted integer overflows in memory-allocation calculations
- 15.18: Reject over-length options in ts_headline()
- 15.18: Guard against field overflow within contrib/intarray's query_int type and contrib/ltree's ltxtquery type
- 15.18: Guard against overly long values of contrib/ltree's lquery type
CVE-2026-6472 · PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege CVSS 5.4
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 15.18. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-6471 · PostgreSQL logical decoding can dlopen arbitrary file CVSS 7.2
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6470 · PostgreSQL fails to check type USAGE privilege CVSS 4.3
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2026-6469 · PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership CVSS 3.8
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Release-note mentions:
CVE-2026-6464 · PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands CVSS 8.1
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: client.
Official affected-branch entry: 15.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2006 · PostgreSQL missing validation of multibyte character length executes arbitrary code CVSS 8.8
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 15.16. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2005 · PostgreSQL pgcrypto heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 15.16. Component: contrib module.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2004 · PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code CVSS 8.8
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 15.16. Component: contrib module.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2003 · PostgreSQL oidvector discloses a few bytes of memory CVSS 4.3
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 15.16. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-19385 · PostgreSQL pg_dump heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: client.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-18408 · PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: client.
Official affected-branch entry: 15.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-18024 · PostgreSQL ascii() function reads past end of buffer CVSS 4.3
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-16241 · PostgreSQL ECPG integer underflow can crash the client CVSS 3.8
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: client.
Official affected-branch entry: 15.
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Release-note mentions:
CVE-2026-16239 · PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code CVSS 8.8
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-16238 · PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code CVSS 8.8
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-15742 · PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound CVSS 8.8
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: contrib module.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-15741 · PostgreSQL expression deparse allows SQL injection via EXTRACT argument CVSS 8.8
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14681 · PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL CVSS 4.2
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14680 · PostgreSQL type confusion via "internal" arguments CVSS 8.8
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14679 · PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory CVSS 8.2
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Release-note mentions:
CVE-2026-14678 · PostgreSQL pg_trgm picksplit reads past end of buffer CVSS 4.3
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: contrib module.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-14677 · PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound CVSS 8.8
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14676 · PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
No fixed version for this branch is recorded. Component: contrib module.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14673 · PostgreSQL amcheck does not clear untrusted search path CVSS 3.8
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.
Fixed in this branch: 15.19. Component: contrib module.
Official affected-branch entry: 15.
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14672 · PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle CVSS 5.3
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-14671 · PostgreSQL refint plan cache type confusion executes arbitrary code CVSS 8.8
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: contrib module.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14670 · PostgreSQL plperl tied object heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14669 · PostgreSQL to_char heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14668 · PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read CVSS 8.1
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Release-note mentions:
CVE-2026-14666 · PostgreSQL row security caching disregards role modifications CVSS 4.2
Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14664 · PostgreSQL regexp heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14663 · PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext CVSS 6.5
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: contrib module.
Official affected-branch entry: 15.
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14662 · PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound CVSS 8.8
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 15.19. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2025-8715 · PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server CVSS 8.8
Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.
Fixed in this branch: 15.14. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
Fixed in this branch: 15.14. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2025-8713 · PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table CVSS 3.1
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
Fixed in this branch: 15.14. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2025-4207 · PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation CVSS 5.9
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
Fixed in this branch: 15.13. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound CVSS 5.9
Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
Fixed in this branch: 15.15. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege CVSS 3.1
Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
Fixed in this branch: 15.15. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2025-1094 · PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation CVSS 8.1
Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.
Fixed in this branch: 15.11. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-7348 · PostgreSQL relation replacement during pg_dump executes arbitrary SQL CVSS 8.8
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected. The PostgreSQL project thanks Noah Misch for reporting this problem.
Fixed in this branch: 15.8. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-4317 · Restrict visibility of "pg_stats_ext" and "pg_stats_ext_exprs" entries to the table owner CVSS 3.1
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes, which are provided as a convenience in the below section. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected. This fix only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after this fix is applied. If you have a current PostgreSQL installation and are concerned about this issue, please use the following remediation steps to fix the issue: From the above URLs, you can click the URL that says "raw" to download a version that you can copy and paste. Be sure to use the script appropriate to your PostgreSQL major version. If you do not see this file, either your version is not vulnerable (only PostgreSQL 14, 15, and 16 are affected) or your minor version is too old to have the fix. \i /usr/share/postgresql/fix-CVE-2024-4317.sql ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; After executing the fix-CVE-2024-4317.sql script in template0 and template1 , you should revoke the ability for template0 to accept connections. You can do this with the following command: ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; The PostgreSQL project thanks Lukas Fittl for reporting this problem.
Fixed in this branch: 15.7. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code CVSS 8.8
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.
Fixed in this branch: 15.9. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID CVSS 4.2
Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 15.9. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle CVSS 3.1
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 15.9. Component: client.
Official affected-branch entry: 15.
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes CVSS 4.2
Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
Fixed in this branch: 15.9. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2024-0985 · PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL CVSS 8.0
UPDATE (June 19, 2024) : Added v16 as impacted. Updated description to clarify the attack vector. Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view.
Fixed in this branch: 15.6. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes CVSS 2.2
Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.
Fixed in this branch: 15.5. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2023-5869 · Buffer overrun from integer overflow in array modification CVSS 8.8
While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.
Fixed in this branch: 15.5. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-5868 · Memory disclosure in aggregate function calls CVSS 4.3
Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.
Fixed in this branch: 15.5. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2023-39418 · MERGE fails to enforce UPDATE or SELECT row security policies CVSS 3.1
PostgreSQL 15 introduced the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT . If UPDATE and SELECT policies forbid some row that INSERT policies do not forbid, a user could store such rows. Subsequent consequences are application-dependent. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Dean Rasheed for reporting this problem.
Fixed in this branch: 15.4. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2023-39417 · Extension script @substitutions@ within quoting allow SQL injection CVSS 7.5
An extension script is vulnerable if it uses @extowner@ , @extschema@ , or @extschema:...@ inside a quoting construct (dollar quoting, '' , or "" ). No bundled extension is vulnerable. Vulnerable uses do appear in a documentation example and in non-bundled extensions. Hence, the attack prerequisite is an administrator having installed files of a vulnerable, trusted, non-bundled extension. Subject to that prerequisite, this enables an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. PostgreSQL will block this attack in the core server, so there's no need to modify individual extensions. The PostgreSQL project thanks Micah Gates, Valerie Woolard, Tim Carey-Smith, and Christoph Berg for reporting this problem.
Fixed in this branch: 15.4. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-2455 · Row security policies disregard user ID changes after inlining CVSS 4.2
While CVE-2016-2193 fixed most interaction between row security and user ID changes, it missed a scenario involving function inlining. This leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLE s. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. The PostgreSQL project thanks Wolfgang Walther for reporting this problem.
Fixed in this branch: 15.3. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2023-2454 · CREATE SCHEMA ... schema_element defeats protective search_path changes CVSS 7.2
This enabled an attacker having database-level CREATE privilege to execute arbitrary code as the bootstrap superuser. Database owners have that right by default, and explicit grants may extend it to other users. The PostgreSQL project thanks Alexander Lakhin for reporting this problem.
Fixed in this branch: 15.3. Component: core server.
Official affected-branch entry: 15.
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2022-41862 · Client memory disclosure when connecting, with Kerberos, to modified server CVSS 3.7
A modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. When a libpq client application has a Kerberos credential cache and doesn't explicitly disable option gssencmode , a server can cause libpq to over-read and report an error message containing uninitialized bytes from and following its receive buffer. If libpq's caller somehow makes that message accessible to the attacker, this achieves a disclosure of the over-read bytes. We have not confirmed or ruled out viability of attacks that arrange for a crash or for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 15.2. Component: client.
Official affected-branch entry: 15.
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2018-1058 · Uncontrolled search path element in pg_dump and other client applications CVSS 8.8
No fixed version for this branch is recorded. Component: client.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2012-0868 · Line breaks in object names can be exploited to execute arbitrary SQL when reloading a pg_dump file.
No fixed version for this branch is recorded.
Release-note mentions:
Export this branch as JSON · Compare any two indexed releases