PostgreSQL 16
Read the English manualSupported · Recorded build 16.15 · 2026-08-13
- First stable release
- 2023-09-14
- Support end
- 2028-11-09
- Indexed releases
- 16
- Original release-note entries
- 930
Manuals & provenance
PostgreSQL 16 English manual · 1172 loaded pages.
Manual loaded 2026-09-27T00:10:47.078613.
Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.
Upgrade considerations
Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.
Compatibility notes for 16.0 · Changes from the initial release through 16.15
Original migration guidance for 16.0
A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 19.6 for general information on migrating to new major releases.
Version 16 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:
Release history
Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.
| Release | Date / snapshot cutoff | All changes | Bug fixes | Migration entries | CVE mentions |
|---|---|---|---|---|---|
| 16.15 | 2026-08-13 | 98 | 42 | 0 | 31 |
| 16.14 | 2026-05-14 | 50 | 20 | 0 | 9 |
| 16.13 | 2026-02-26 | 6 | 5 | 0 | 1 |
| 16.12 | 2026-02-12 | 45 | 18 | 0 | 4 |
| 16.11 | 2025-11-13 | 59 | 32 | 0 | 2 |
| 16.10 | 2025-08-14 | 59 | 19 | 0 | 5 |
| 16.9 | 2025-05-08 | 48 | 19 | 0 | 1 |
| 16.8 | 2025-02-20 | 2 | 1 | 0 | 1 |
| 16.7 | 2025-02-13 | 55 | 31 | 0 | 1 |
| 16.6 | 2024-11-21 | 8 | 4 | 0 | 1 |
| 16.5 | 2024-11-14 | 54 | 25 | 0 | 4 |
| 16.4 | 2024-08-08 | 54 | 27 | 0 | 2 |
| 16.3 | 2024-05-09 | 57 | 27 | 0 | 1 |
| 16.2 | 2024-02-08 | 70 | 30 | 0 | 1 |
| 16.1 | 2023-11-09 | 59 | 28 | 0 | 3 |
| 16.0 | 2023-09-14 | 206 | 3 | 13 | 0 |
Initial release changes
Original entries from 16.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.
206 of 206 original entries.
Change assignment rules for PL/pgSQL bound cursor variables Compatibility Migration
Change assignment rules for PL/pgSQL bound cursor variables (Tom Lane) §
Previously, the string value of such variables was set to match the variable name during cursor assignment; now it will be assigned during
OPEN, and will not match the variable name. To restore the previous behavior, assign the desired portal name to the cursor variable beforeOPEN.Original release occurrence ·
16.0/migration/001Disallow NULLS NOT DISTINCT indexes for primary keys Compatibility Migration
Disallow
NULLS NOT DISTINCTindexes for primary keys (Daniel Gustafsson) §Original release occurrence ·
16.0/migration/002Change REINDEX DATABASE and reindexdb to not process indexes on system catalogs Compatibility Migration
Change
REINDEX DATABASEand reindexdb to not process indexes on system catalogs (Simon Riggs) § §Processing such indexes is still possible using
REINDEX SYSTEMandreindexdb --system.Original release occurrence ·
16.0/migration/003Tighten GENERATED expression restrictions on inherited and partitioned tables Compatibility Migration
Tighten
GENERATEDexpression restrictions on inherited and partitioned tables (Amit Langote, Tom Lane) §Columns of parent/partitioned and child/partition tables must all have the same generation status, though now the actual generation expressions can be different.
Original release occurrence ·
16.0/migration/004Remove pg_walinspect functions pg_get_wal_records_info_till_end_of_wal() and pg_get_wal_stats_till_end_of_wal() Compatibility Migration
Remove pg_walinspect functions
pg_get_wal_records_info_till_end_of_wal()andpg_get_wal_stats_till_end_of_wal()(Bharath Rupireddy) §Original release occurrence ·
16.0/migration/005Rename server variable force_parallel_mode to debug_parallel_query Compatibility Migration
Rename server variable
force_parallel_modetodebug_parallel_query(David Rowley) § §Original release occurrence ·
16.0/migration/006Remove the ability to create views manually with ON SELECT rules Compatibility Migration
Remove the ability to create views manually with
ON SELECTrules (Tom Lane) §Original release occurrence ·
16.0/migration/007Remove the server variable vacuum_defer_cleanup_age Compatibility Migration
Remove the server variable
vacuum_defer_cleanup_age(Andres Freund) §This has been unnecessary since
hot_standby_feedbackand replication slots were added.Original release occurrence ·
16.0/migration/008Remove server variable promote_trigger_file Compatibility Migration
Remove server variable
promote_trigger_file(Simon Riggs) §This was used to promote a standby to primary, but is now more easily accomplished with
pg_ctl promoteorpg_promote().Original release occurrence ·
16.0/migration/009Remove read-only server variables lc_collate and lc_ctype Compatibility Migration
Remove read-only server variables
lc_collateandlc_ctype(Peter Eisentraut) §Collations and locales can vary between databases so having them as read-only server variables was unhelpful.
Original release occurrence ·
16.0/migration/010Role inheritance now controls the default inheritance status of member roles added during GRANT Compatibility Migration
Role inheritance now controls the default inheritance status of member roles added during
GRANT(Robert Haas) §The role's default inheritance behavior can be overridden with the new
GRANT ... WITH INHERITclause. This allows inheritance of some roles and not others because the members' inheritance status is set atGRANTtime. Previously the inheritance status of member roles was controlled only by the role's inheritance status, and changes to a role's inheritance status affected all previous and future member roles.Original release occurrence ·
16.0/migration/011Restrict the privileges of CREATEROLE and its ability to modify other roles Compatibility Migration
Restrict the privileges of
CREATEROLEand its ability to modify other roles (Robert Haas) § §Previously roles with
CREATEROLEprivileges could change many aspects of any non-superuser role. Such changes, including adding members, now require the role requesting the change to haveADMIN OPTIONpermission. For example, they can now change theCREATEDB,REPLICATION, andBYPASSRLSproperties only if they also have those permissions.Original release occurrence ·
16.0/migration/012Remove symbolic links for the postmaster binary Compatibility Migration
Remove symbolic links for the postmaster binary (Peter Eisentraut) §
Original release occurrence ·
16.0/migration/013Allow incremental sorts in more cases, including DISTINCT Features
Original release occurrence ·
16.0/changes/001Add the ability for aggregates having ORDER BY or DISTINCT to use pre-sorted data Features
Add the ability for aggregates having
ORDER BYorDISTINCTto use pre-sorted data (David Rowley) § § §The new server variable
enable_presorted_aggregatecan be used to disable this.Original release occurrence ·
16.0/changes/002Allow memoize atop a UNION ALL Features
Allow memoize atop a
UNION ALL(Richard Guo) §Original release occurrence ·
16.0/changes/003Allow anti-joins to be performed with the non-nullable input as the inner relation Features
Allow anti-joins to be performed with the non-nullable input as the inner relation (Richard Guo) §
Original release occurrence ·
16.0/changes/004Allow parallelization of FULL and internal right OUTER hash joins Features
Allow parallelization of
FULLand internal rightOUTERhash joins (Melanie Plageman, Thomas Munro) §Original release occurrence ·
16.0/changes/005Improve the accuracy of GIN index access optimizer costs Features
Original release occurrence ·
16.0/changes/006Allow more efficient addition of heap and index pages Performance
Original release occurrence ·
16.0/changes/007During non-freeze operations, perform page freezing where appropriate Performance
During non-freeze operations, perform page freezing where appropriate (Peter Geoghegan) § § §
This makes full-table freeze vacuums less necessary.
Original release occurrence ·
16.0/changes/008Allow window functions to use the faster ROWS mode internally when RANGE mode is active but unnecessary Performance
Allow window functions to use the faster
ROWSmode internally whenRANGEmode is active but unnecessary (David Rowley) §Original release occurrence ·
16.0/changes/009Allow optimization of always-increasing window functions ntile(), cume_dist() and percent_rank() Performance
Allow optimization of always-increasing window functions
ntile(),cume_dist()andpercent_rank()(David Rowley) §Original release occurrence ·
16.0/changes/010Allow aggregate functions string_agg() and array_agg() to be parallelized Performance
Allow aggregate functions
string_agg()andarray_agg()to be parallelized (David Rowley) §Original release occurrence ·
16.0/changes/011Improve performance by caching RANGE and LIST partition lookups Performance
Improve performance by caching
RANGEandLISTpartition lookups (Amit Langote, Hou Zhijie, David Rowley) §Original release occurrence ·
16.0/changes/012Allow control of the shared buffer usage by vacuum and analyze Performance
Allow control of the shared buffer usage by vacuum and analyze (Melanie Plageman) § § §
The
VACUUM/ANALYZEoption isBUFFER_USAGE_LIMIT, and the vacuumdb option is--buffer-usage-limit. The default value is set by server variablevacuum_buffer_usage_limit, which also controls autovacuum.Original release occurrence ·
16.0/changes/013Support wal_sync_method=fdatasync on Windows Performance
Support
wal_sync_method=fdatasyncon Windows (Thomas Munro) §Original release occurrence ·
16.0/changes/014Allow HOT updates if only BRIN-indexed columns are updated Performance
Allow HOT updates if only
BRIN-indexed columns are updated (Matthias van de Meent, Josef Simanek, Tomas Vondra) §Original release occurrence ·
16.0/changes/015Improve the speed of updating the process title Performance
Improve the speed of updating the process title (David Rowley) §
Original release occurrence ·
16.0/changes/016Allow xid/subxid searches and ASCII string detection to use vector operations Performance
Allow
xid/subxidsearches and ASCII string detection to use vector operations (Nathan Bossart, John Naylor) § § § §ASCII detection is particularly useful for
COPY FROM. Vector operations are also used for some C array searches.Original release occurrence ·
16.0/changes/017Reduce overhead of memory allocations Performance
Reduce overhead of memory allocations (Andres Freund, David Rowley) §
Original release occurrence ·
16.0/changes/018Add system view pg_stat_io view to track I/O statistics Features
Original release occurrence ·
16.0/changes/019Record statistics on the last sequential and index scans on tables Features
Record statistics on the last sequential and index scans on tables (Dave Page) §
This information appears in
pg_stat_*_tablesandpg_stat_*_indexes.Original release occurrence ·
16.0/changes/020Record statistics on the occurrence of updated rows moving to new pages Features
Record statistics on the occurrence of updated rows moving to new pages (Corey Huinker) §
The
pg_stat_*_tablescolumn isn_tup_newpage_upd.Original release occurrence ·
16.0/changes/021Add speculative lock information to the pg_locks system view Features
Add speculative lock information to the
pg_lockssystem view (Masahiko Sawada, Noriyoshi Shinoda) §The transaction id is displayed in the
transactionidcolumn and the speculative insertion token is displayed in theobjidcolumn.Original release occurrence ·
16.0/changes/022Add the display of prepared statement result types to the pg_prepared_statements view Features
Add the display of prepared statement result types to the
pg_prepared_statementsview (Dagfinn Ilmari Mannsåker) § §Original release occurrence ·
16.0/changes/023Create subscription statistics entries at subscription creation time so stats_reset is accurate Features
Create subscription statistics entries at subscription creation time so
stats_resetis accurate (Andres Freund) §Previously entries were created only when the first statistics were reported.
Original release occurrence ·
16.0/changes/024Correct the I/O accounting for temp relation writes shown in pg_stat_database Bug fixes
Correct the I/O accounting for temp relation writes shown in
pg_stat_database(Melanie Plageman) §Original release occurrence ·
16.0/changes/025Add function pg_stat_get_backend_subxact() to report on a session's subtransaction cache Features
Add function
pg_stat_get_backend_subxact()to report on a session's subtransaction cache (Dilip Kumar) §Original release occurrence ·
16.0/changes/026Have pg_stat_get_backend_idset(), pg_stat_get_backend_activity(), and related functions use the unchanging backend id Features
Have
pg_stat_get_backend_idset(),pg_stat_get_backend_activity(), and related functions use the unchanging backend id (Nathan Bossart) §Previously the index values might change during the lifetime of the session.
Original release occurrence ·
16.0/changes/027Report stand-alone backends with a special backend type Features
Report stand-alone backends with a special backend type (Melanie Plageman) §
Original release occurrence ·
16.0/changes/028Add wait event SpinDelay to report spinlock sleep delays Features
Original release occurrence ·
16.0/changes/029Create new wait event DSMAllocate to indicate waiting for dynamic shared memory allocation Features
Create new wait event
DSMAllocateto indicate waiting for dynamic shared memory allocation (Thomas Munro) §Previously this type of wait was reported as
DSMFillZeroWrite, which was also used bymmap()allocations.Original release occurrence ·
16.0/changes/030Add the database name to the process title of logical WAL senders Features
Add the database name to the process title of logical WAL senders (Tatsuhiro Nakamori) §
Physical WAL senders do not display a database name.
Original release occurrence ·
16.0/changes/031Add checkpoint and REDO LSN information to log_checkpoints messages Features
Add checkpoint and
REDO LSNinformation tolog_checkpointsmessages (Bharath Rupireddy, Kyotaro Horiguchi) §Original release occurrence ·
16.0/changes/032Provide additional details during client certificate failures Features
Provide additional details during client certificate failures (Jacob Champion) §
Original release occurrence ·
16.0/changes/033Add predefined role pg_create_subscription with permission to create subscriptions Features
Add predefined role
pg_create_subscriptionwith permission to create subscriptions (Robert Haas) §Original release occurrence ·
16.0/changes/034Allow subscriptions to not require passwords Features
Allow subscriptions to not require passwords (Robert Haas) § § §
This is accomplished with the option
password_required=false.Original release occurrence ·
16.0/changes/035Simplify permissions for LOCK TABLE Features
Simplify permissions for
LOCK TABLE(Jeff Davis) §Previously a user's ability to perform
LOCK TABLEat various lock levels was limited to the lock levels required by the commands they had permission to execute on the table. For example, someone withUPDATEpermission could perform all lock levels exceptACCESS SHARE, even though it was a lesser lock level. Now users can issue lesser lock levels if they already have permission for greater lock levels.Original release occurrence ·
16.0/changes/036Allow ALTER GROUP group_name ADD USER user_name to be performed with ADMIN OPTION Features
Allow
ALTER GROUP group_name ADD USER user_nameto be performed withADMIN OPTION(Robert Haas) §Previously
CREATEROLEpermission was required.Original release occurrence ·
16.0/changes/037Allow GRANT to use WITH ADMIN TRUE/FALSE syntax Features
Allow
GRANTto useWITH ADMIN TRUE/FALSEsyntax (Robert Haas) §Previously only the
WITH ADMIN OPTIONsyntax was supported.Original release occurrence ·
16.0/changes/038Allow roles that create other roles to automatically inherit the new role's rights or the ability to SET ROLE to the new role Features
Allow roles that create other roles to automatically inherit the new role's rights or the ability to
SET ROLEto the new role (Robert Haas, Shi Yu) § §This is controlled by server variable
createrole_self_grant.Original release occurrence ·
16.0/changes/039Prevent users from changing the default privileges of non-inherited roles Features
Prevent users from changing the default privileges of non-inherited roles (Robert Haas) §
This is now only allowed for inherited roles.
Original release occurrence ·
16.0/changes/040When granting role membership, require the granted-by role to be a role that has appropriate permissions Features
When granting role membership, require the granted-by role to be a role that has appropriate permissions (Robert Haas) §
This is a requirement even when a non-bootstrap superuser is granting role membership.
Original release occurrence ·
16.0/changes/041Allow non-superusers to grant permissions using a granted-by user that is not the current user Features
Allow non-superusers to grant permissions using a granted-by user that is not the current user (Robert Haas) §
The current user still must have sufficient permissions given by the specified granted-by user.
Original release occurrence ·
16.0/changes/042Add GRANT to control permission to use SET ROLE Features
Add
GRANTto control permission to useSET ROLE(Robert Haas) §This is controlled by a new
GRANT ... SEToption.Original release occurrence ·
16.0/changes/043Add dependency tracking to roles which have granted privileges Features
Add dependency tracking to roles which have granted privileges (Robert Haas) §
For example, removing
ADMIN OPTIONwill fail if there are privileges using that option;CASCADEmust be used to revoke dependent permissions.Original release occurrence ·
16.0/changes/044Add dependency tracking of grantors for GRANT records Features
Add dependency tracking of grantors for
GRANTrecords (Robert Haas) §This guarantees that
pg_auth_members.grantorvalues are always valid.Original release occurrence ·
16.0/changes/045Allow multiple role membership records Features
Allow multiple role membership records (Robert Haas) § §
Previously a new membership grant would remove a previous matching membership grant, even if other aspects of the grant did not match.
Original release occurrence ·
16.0/changes/046Prevent removal of superuser privileges for the bootstrap user Features
Prevent removal of superuser privileges for the bootstrap user (Robert Haas) §
Restoring such users could lead to errors.
Original release occurrence ·
16.0/changes/047Allow makeaclitem() to accept multiple privilege names Features
Allow
makeaclitem()to accept multiple privilege names (Robins Tharakan) §Previously only a single privilege name, like
SELECT, was accepted.Original release occurrence ·
16.0/changes/048Add support for Kerberos credential delegation Features
Add support for Kerberos credential delegation (Stephen Frost) § § § §
This is enabled with server variable
gss_accept_delegationand libpq connection parametergssdelegation.Original release occurrence ·
16.0/changes/049Allow the SCRAM iteration count to be set with server variable scram_iterations Features
Allow the SCRAM iteration count to be set with server variable
scram_iterations(Daniel Gustafsson) §Original release occurrence ·
16.0/changes/050Improve performance of server variable management Performance
Original release occurrence ·
16.0/changes/051Tighten restrictions on which server variables can be reset Features
Tighten restrictions on which server variables can be reset (Masahiko Sawada) §
Previously, while certain variables, like
transaction_isolation, were not affected byRESET ALL, they could be individually reset in inappropriate situations.Original release occurrence ·
16.0/changes/052Move various postgresql.conf items into new categories Features
Move various
postgresql.confitems into new categories (Shinya Kato) §This also affects the categories displayed in the
pg_settingsview.Original release occurrence ·
16.0/changes/053Prevent configuration file recursion beyond 10 levels Features
Prevent configuration file recursion beyond 10 levels (Julien Rouhaud) §
Original release occurrence ·
16.0/changes/054Allow autovacuum to more frequently honor changes to delay settings Features
Allow autovacuum to more frequently honor changes to delay settings (Melanie Plageman) § §
Rather than honor changes only at the start of each relation, honor them at the start of each block.
Original release occurrence ·
16.0/changes/055Remove restrictions that archive files be durably renamed Features
Remove restrictions that archive files be durably renamed (Nathan Bossart) § §
The
archive_commandcommand is now more likely to be called with already-archived files after a crash.Original release occurrence ·
16.0/changes/056Prevent archive_library and archive_command from being set at the same time Features
Prevent
archive_libraryandarchive_commandfrom being set at the same time (Nathan Bossart) §Previously
archive_librarywould overridearchive_command.Original release occurrence ·
16.0/changes/057Allow the postmaster to terminate children with an abort signal Features
Allow the postmaster to terminate children with an abort signal (Tom Lane) §
This allows collection of a core dump for a stuck child process. This is controlled by
send_abort_for_crashandsend_abort_for_kill. The postmaster's-Tswitch is now the same as settingsend_abort_for_crash.Original release occurrence ·
16.0/changes/058Remove the non-functional postmaster -n option Features
Remove the non-functional postmaster
-noption (Tom Lane) §Original release occurrence ·
16.0/changes/059Allow the server to reserve backend slots for roles with pg_use_reserved_connections membership Features
Allow the server to reserve backend slots for roles with
pg_use_reserved_connectionsmembership (Nathan Bossart) §The number of reserved slots is set by server variable
reserved_connections.Original release occurrence ·
16.0/changes/060Allow huge pages to work on newer versions of Windows 10 Features
Allow huge pages to work on newer versions of Windows 10 (Thomas Munro) §
This adds the special handling required to enable huge pages on newer versions of Windows 10.
Original release occurrence ·
16.0/changes/061Add debug_io_direct setting for developer usage Features
Add
debug_io_directsetting for developer usage (Thomas Munro, Andres Freund, Bharath Rupireddy) § §While primarily for developers,
wal_sync_method=open_sync/open_datasynchas been modified to not use direct I/O withwal_level=minimal; this is now enabled withdebug_io_direct=wal.Original release occurrence ·
16.0/changes/062Add function pg_split_walfile_name() to report the segment and timeline values of WAL file names Features
Add function
pg_split_walfile_name()to report the segment and timeline values of WAL file names (Bharath Rupireddy) § §Original release occurrence ·
16.0/changes/063Add support for regular expression matching on database and role entries in pg_hba.conf Features
Add support for regular expression matching on database and role entries in
pg_hba.conf(Bertrand Drouvot) §Regular expression patterns are prefixed with a slash. Database and role names that begin with slashes need to be double-quoted if referenced in
pg_hba.conf.Original release occurrence ·
16.0/changes/064Improve user-column handling of pg_ident.conf to match pg_hba.conf Features
Improve user-column handling of
pg_ident.confto matchpg_hba.conf(Jelte Fennema) §Specifically, add support for
all, role membership with+, and regular expressions with a leading slash. Any user name that matches these patterns must be double-quoted.Original release occurrence ·
16.0/changes/065Allow include files in pg_hba.conf and pg_ident.conf Features
Allow include files in
pg_hba.confandpg_ident.conf(Julien Rouhaud) §These are controlled by
include,include_if_exists, andinclude_dir. System viewspg_hba_file_rulesandpg_ident_file_mappingsnow display the file name.Original release occurrence ·
16.0/changes/066Allow pg_hba.conf tokens to be of unlimited length Features
Allow
pg_hba.conftokens to be of unlimited length (Tom Lane) §Original release occurrence ·
16.0/changes/067Add rule and map numbers to the system view pg_hba_file_rules Features
Add rule and map numbers to the system view
pg_hba_file_rules(Julien Rouhaud) §Original release occurrence ·
16.0/changes/068Determine the default encoding from the locale when using ICU Features
Determine the default encoding from the locale when using ICU (Jeff Davis) §
Previously the default was always
UTF-8.Original release occurrence ·
16.0/changes/069Have CREATE DATABASE and CREATE COLLATION's LOCALE options, and initdb and createdb --locale options, control non-libc collation providers Features
Have
CREATE DATABASEandCREATE COLLATION'sLOCALEoptions, and initdb and createdb--localeoptions, control non-libc collation providers (Jeff Davis)Previously they only controlled libc providers.
Original release occurrence ·
16.0/changes/070Add predefined collations unicode and ucs_basic Features
Add predefined collations
unicodeanducs_basic(Peter Eisentraut) §This only works if ICU support is enabled.
Original release occurrence ·
16.0/changes/071Allow custom ICU collation rules to be created Features
Allow custom ICU collation rules to be created (Peter Eisentraut) §
This is done using
CREATE COLLATION's newRULESclause, as well as new options forCREATE DATABASE, createdb, and initdb.Original release occurrence ·
16.0/changes/072Allow Windows to import system locales automatically Features
Allow Windows to import system locales automatically (Juan José Santamaría Flecha) §
Previously, only ICU locales could be imported on Windows.
Original release occurrence ·
16.0/changes/073Allow logical decoding on standbys Features
Allow logical decoding on standbys (Bertrand Drouvot, Andres Freund, Amit Khandekar) § § §
Snapshot WAL records are required for logical slot creation but cannot be created on standbys. To avoid delays, the new function
pg_log_standby_snapshot()allows creation of such records.Original release occurrence ·
16.0/changes/074Add server variable to control how logical decoding publishers transfer changes and how subscribers apply them Features
Add server variable to control how logical decoding publishers transfer changes and how subscribers apply them (Shi Yu) § § §
The variable is
debug_logical_replication_streaming.Original release occurrence ·
16.0/changes/075Allow logical replication initial table synchronization to copy rows in binary format Features
Allow logical replication initial table synchronization to copy rows in binary format (Melih Mutlu) §
This is only possible for subscriptions marked as binary.
Original release occurrence ·
16.0/changes/076Allow parallel application of logical replication Features
Allow parallel application of logical replication (Hou Zhijie, Wang Wei, Amit Kapila) § § §
The
CREATE SUBSCRIPTIONSTREAMINGoption now supportsparallelto enable application of large transactions by parallel workers. The number of parallel workers is controlled by the new server variablemax_parallel_apply_workers_per_subscription. Wait eventsLogicalParallelApplyMain,LogicalParallelApplyStateChange, andLogicalApplySendDatawere also added. Columnleader_pidwas added to system viewpg_stat_subscriptionto track parallel activity.Original release occurrence ·
16.0/changes/077Improve performance for logical replication apply without a primary key Performance
Improve performance for logical replication apply without a primary key (Onder Kalaci, Amit Kapila) §
Specifically,
REPLICA IDENTITY FULLcan now use btree indexes rather than sequentially scanning the table to find matches.Original release occurrence ·
16.0/changes/078Allow logical replication subscribers to process only changes that have no origin Features
Allow logical replication subscribers to process only changes that have no origin (Vignesh C, Amit Kapila) § §
This can be used to avoid replication loops. This is controlled by the new
CREATE SUBSCRIPTION ... ORIGINoption.Original release occurrence ·
16.0/changes/079Perform logical replication SELECT and DML actions as the table owner Features
Perform logical replication
SELECTand DML actions as the table owner (Robert Haas) § §This improves security and now requires subscription owners to be either superusers or to have
SET ROLEpermission on all roles owning tables in the replication set. The previous behavior of performing all operations as the subscription owner can be enabled with the subscriptionrun_as_owneroption.Original release occurrence ·
16.0/changes/080Have wal_retrieve_retry_interval operate on a per-subscription basis Features
Have
wal_retrieve_retry_intervaloperate on a per-subscription basis (Nathan Bossart) §Previously the retry time was applied globally. This also adds wait events >
LogicalRepLauncherDSAandLogicalRepLauncherHash.Original release occurrence ·
16.0/changes/081Add EXPLAIN option GENERIC_PLAN to display the generic plan for a parameterized query Features
Add
EXPLAINoptionGENERIC_PLANto display the generic plan for a parameterized query (Laurenz Albe) §Original release occurrence ·
16.0/changes/082Allow a COPY FROM value to map to a column's DEFAULT Features
Original release occurrence ·
16.0/changes/083Allow COPY into foreign tables to add rows in batches Features
Allow
COPYinto foreign tables to add rows in batches (Andrey Lepikhov, Etsuro Fujita) §This is controlled by the postgres_fdw option
batch_size.Original release occurrence ·
16.0/changes/084Allow the STORAGE type to be specified by CREATE TABLE Features
Allow the
STORAGEtype to be specified byCREATE TABLE(Teodor Sigaev, Aleksander Alekseev) § §Previously only
ALTER TABLEcould control this.Original release occurrence ·
16.0/changes/085Allow truncate triggers on foreign tables Features
Allow truncate triggers on foreign tables (Yugo Nagata) §
Original release occurrence ·
16.0/changes/086Add VACUUM options to skip or update all frozen statistics Features
Add
VACUUMoptions to skip or update all frozen statistics (Tom Lane, Nathan Bossart) §The options are
SKIP_DATABASE_STATSandONLY_DATABASE_STATS.Original release occurrence ·
16.0/changes/088Change REINDEX DATABASE and REINDEX SYSTEM to no longer require an argument Features
Change
REINDEX DATABASEandREINDEX SYSTEMto no longer require an argument (Simon Riggs) § §Previously the database name had to be specified.
Original release occurrence ·
16.0/changes/089Allow CREATE STATISTICS to generate a statistics name if none is specified Features
Allow
CREATE STATISTICSto generate a statistics name if none is specified (Simon Riggs) §Original release occurrence ·
16.0/changes/090Allow non-decimal integer literals Features
Allow non-decimal integer literals (Peter Eisentraut) §
For example,
0x42F,0o273, and0b100101.Original release occurrence ·
16.0/changes/091Allow NUMERIC to process hexadecimal, octal, and binary integers of any size Features
Allow
NUMERICto process hexadecimal, octal, and binary integers of any size (Dean Rasheed) §Previously only unquoted eight-byte integers were supported with these non-decimal bases.
Original release occurrence ·
16.0/changes/092Allow underscores in integer and numeric constants Features
Allow underscores in integer and numeric constants (Peter Eisentraut, Dean Rasheed) §
This can improve readability for long strings of digits.
Original release occurrence ·
16.0/changes/093Accept the spelling +infinity in datetime input Features
Accept the spelling
+infinityin datetime input (Vik Fearing) §Original release occurrence ·
16.0/changes/094Prevent the specification of epoch and infinity together with other fields in datetime strings Features
Prevent the specification of
epochandinfinitytogether with other fields in datetime strings (Joseph Koshakow) §Original release occurrence ·
16.0/changes/095Remove undocumented support for date input in the form YyearMmonthDday Features
Remove undocumented support for date input in the form
Y(Joseph Koshakow) §yearMmonthDdayOriginal release occurrence ·
16.0/changes/096Add functions pg_input_is_valid() and pg_input_error_info() to check for type conversion errors Features
Add functions
pg_input_is_valid()andpg_input_error_info()to check for type conversion errors (Tom Lane) § §Original release occurrence ·
16.0/changes/097Allow subqueries in the FROM clause to omit aliases Features
Allow subqueries in the
FROMclause to omit aliases (Dean Rasheed) §Original release occurrence ·
16.0/changes/098Add support for enhanced numeric literals in SQL/JSON paths Features
Add support for enhanced numeric literals in SQL/JSON paths (Peter Eisentraut) §
For example, allow hexadecimal, octal, and binary integers and underscores between digits.
Original release occurrence ·
16.0/changes/099Add SQL/JSON constructors Features
Add SQL/JSON constructors (Nikita Glukhov, Teodor Sigaev, Oleg Bartunov, Alexander Korotkov, Amit Langote) §
The new functions
JSON_ARRAY(),JSON_ARRAYAGG(),JSON_OBJECT(), andJSON_OBJECTAGG()are part of the SQL standard.Original release occurrence ·
16.0/changes/100Add SQL/JSON object checks Features
Add SQL/JSON object checks (Nikita Glukhov, Teodor Sigaev, Oleg Bartunov, Alexander Korotkov, Amit Langote, Andrew Dunstan) §
The
IS JSONchecks include checks for values, arrays, objects, scalars, and unique keys.Original release occurrence ·
16.0/changes/101Allow JSON string parsing to use vector operations Features
Allow JSON string parsing to use vector operations (John Naylor) §
Original release occurrence ·
16.0/changes/102Improve the handling of full text highlighting function ts_headline() for OR and NOT expressions Features
Improve the handling of full text highlighting function
ts_headline()forORandNOTexpressions (Tom Lane) §Original release occurrence ·
16.0/changes/103Add functions to add, subtract, and generate timestamptz values in a specified time zone Features
Add functions to add, subtract, and generate
timestamptzvalues in a specified time zone (Przemyslaw Sztoch, Gurjeet Singh) §The functions are
date_add(),date_subtract(), andgenerate_series().Original release occurrence ·
16.0/changes/104Change date_trunc(unit, timestamptz, time_zone) to be an immutable function Features
Change
date_trunc(unit, timestamptz, time_zone)to be an immutable function (Przemyslaw Sztoch) §This allows the creation of expression indexes using this function.
Original release occurrence ·
16.0/changes/105Add server variable SYSTEM_USER Features
Add server variable
SYSTEM_USER(Bertrand Drouvot) §This reports the authentication method and its authenticated user.
Original release occurrence ·
16.0/changes/106Add functions array_sample() and array_shuffle() Features
Add functions
array_sample()andarray_shuffle()(Martin Kalcher) §Original release occurrence ·
16.0/changes/107Add aggregate function ANY_VALUE() which returns any value from a set Features
Add aggregate function
ANY_VALUE()which returns any value from a set (Vik Fearing) §Original release occurrence ·
16.0/changes/108Add function random_normal() to supply normally-distributed random numbers Features
Add function
random_normal()to supply normally-distributed random numbers (Paul Ramsey) §Original release occurrence ·
16.0/changes/109Add error function erf() and its complement erfc() Features
Original release occurrence ·
16.0/changes/110Improve the accuracy of numeric power() for integer exponents Features
Original release occurrence ·
16.0/changes/111Add XMLSERIALIZE() option INDENT to pretty-print its output Features
Add
XMLSERIALIZE()optionINDENTto pretty-print its output (Jim Jones) §Original release occurrence ·
16.0/changes/112Change pg_collation_actual_version() to return a reasonable value for the default collation Features
Change
pg_collation_actual_version()to return a reasonable value for the default collation (Jeff Davis) §Previously it returned
NULL.Original release occurrence ·
16.0/changes/113Allow pg_read_file() and pg_read_binary_file() to ignore missing files Features
Allow
pg_read_file()andpg_read_binary_file()to ignore missing files (Kyotaro Horiguchi) §Original release occurrence ·
16.0/changes/114Add byte specification (B) to pg_size_bytes() Features
Add byte specification (
B) topg_size_bytes()(Peter Eisentraut) §Original release occurrence ·
16.0/changes/115Allow to_reg* functions to accept numeric OIDs as input Features
Original release occurrence ·
16.0/changes/116Add the ability to get the current function's OID in PL/pgSQL Features
Add the ability to get the current function's OID in PL/pgSQL (Pavel Stehule) §
This is accomplished with
GET DIAGNOSTICS variable = PG_ROUTINE_OID.Original release occurrence ·
16.0/changes/117Add libpq connection option require_auth to specify a list of acceptable authentication methods Features
Add libpq connection option
require_authto specify a list of acceptable authentication methods (Jacob Champion) §This can also be used to disallow certain authentication methods.
Original release occurrence ·
16.0/changes/118Allow multiple libpq-specified hosts to be randomly selected Features
Allow multiple libpq-specified hosts to be randomly selected (Jelte Fennema) § §
This is enabled with
load_balance_hosts=randomand can be used for load balancing.Original release occurrence ·
16.0/changes/119Add libpq option sslcertmode to control transmission of the client certificate Features
Add libpq option
sslcertmodeto control transmission of the client certificate (Jacob Champion) §The option values are
disable,allow, andrequire.Original release occurrence ·
16.0/changes/120Allow libpq to use the system certificate pool for certificate verification Features
Allow libpq to use the system certificate pool for certificate verification (Jacob Champion, Thomas Habets) §
This is enabled with
sslrootcert=system, which also enablessslmode=verify-full.Original release occurrence ·
16.0/changes/121Allow ECPG variable declarations to use typedef names that match unreserved SQL keywords Features
Allow
ECPGvariable declarations to use typedef names that match unreserved SQL keywords (Tom Lane) §This change does prevent keywords which match C typedef names from being processed as keywords in later
EXEC SQLblocks.Original release occurrence ·
16.0/changes/122Allow psql to control the maximum width of header lines in expanded format Features
Allow psql to control the maximum width of header lines in expanded format (Platon Pronko) §
This is controlled by
xheader_width.Original release occurrence ·
16.0/changes/123Add psql command \drg to show role membership details Features
Add psql command
\drgto show role membership details (Pavel Luzanov) § §The
Member ofoutput column has been removed from\duand\dgbecause this new command displays this information in more detail.Original release occurrence ·
16.0/changes/124Allow psql's access privilege commands to show system objects Features
Original release occurrence ·
16.0/changes/125Add FOREIGN designation to psql \d+ for foreign table children and partitions Features
Add
FOREIGNdesignation to psql\d+for foreign table children and partitions (Ian Lawrence Barwick) §Original release occurrence ·
16.0/changes/126Prevent \df+ from showing function source code Features
Prevent
\df+from showing function source code (Isaac Morland) §Function bodies are more easily viewed with
\sf.Original release occurrence ·
16.0/changes/127Allow psql to submit queries using the extended query protocol Features
Allow psql to submit queries using the extended query protocol (Peter Eisentraut) §
Passing arguments to such queries is done using the new psql
\bindcommand.Original release occurrence ·
16.0/changes/128Allow psql \watch to limit the number of executions Features
Allow psql
\watchto limit the number of executions (Andrey Borodin) §The
\watchoptions can now be named when specified.Original release occurrence ·
16.0/changes/129Detect invalid values for psql \watch, and allow zero to specify no delay Features
Original release occurrence ·
16.0/changes/130Allow psql scripts to obtain the exit status of shell commands and queries Features
Allow psql scripts to obtain the exit status of shell commands and queries (Corey Huinker, Tom Lane) § §
The new psql control variables are
SHELL_ERRORandSHELL_EXIT_CODE.Original release occurrence ·
16.0/changes/131Add pg_dump control of dumping child tables and partitions Features
Add pg_dump control of dumping child tables and partitions (Gilles Darold) §
The new options are
--table-and-children,--exclude-table-and-children, and--exclude-table-data-and-children.Original release occurrence ·
16.0/changes/133Add LZ4 and Zstandard compression to pg_dump Features
Add LZ4 and Zstandard compression to pg_dump (Georgios Kokolatos, Justin Pryzby)
Original release occurrence ·
16.0/changes/134Allow pg_dump and pg_basebackup to use long mode for compression Features
Allow pg_dump and pg_basebackup to use
longmode for compression (Justin Pryzby) § § § §Original release occurrence ·
16.0/changes/135Improve pg_dump to accept a more consistent compression syntax Features
Improve pg_dump to accept a more consistent compression syntax (Georgios Kokolatos) §
Options like
--compress=gzip:5.Original release occurrence ·
16.0/changes/136Add initdb option to set server variables for the duration of initdb and all future server starts Features
Add initdb option to set server variables for the duration of initdb and all future server starts (Tom Lane) §
The option is
-c name=value.Original release occurrence ·
16.0/changes/137Add options to createuser to control more user options Features
Add options to createuser to control more user options (Shinya Kato) § §
Specifically, the new options control the valid-until date, bypassing of row-level security, and role membership.
Original release occurrence ·
16.0/changes/138Deprecate createuser option --role Features
Deprecate createuser option
--role(Nathan Bossart) § §This option could be easily confused with new createuser role membership options, so option
--member-ofhas been added with the same functionality. The--roleoption can still be used.Original release occurrence ·
16.0/changes/139Allow control of vacuumdb schema processing Features
Allow control of vacuumdb schema processing (Gilles Darold) §
These are controlled by options
--schemaand--exclude-schema.Original release occurrence ·
16.0/changes/140Use new VACUUM options to improve the performance of vacuumdb Performance
Original release occurrence ·
16.0/changes/141Have pg_upgrade set the new cluster's locale and encoding Features
Have pg_upgrade set the new cluster's locale and encoding (Jeff Davis) §
This removes the requirement that the new cluster be created with the same locale and encoding settings.
Original release occurrence ·
16.0/changes/142Add pg_upgrade option to specify the default transfer mode Features
Add pg_upgrade option to specify the default transfer mode (Peter Eisentraut) §
The option is
--copy.Original release occurrence ·
16.0/changes/143Improve pg_basebackup to accept numeric compression options Features
Improve pg_basebackup to accept numeric compression options (Georgios Kokolatos, Michael Paquier) §
Options like
--compress=server-5are now supported.Original release occurrence ·
16.0/changes/144Fix pg_basebackup to handle tablespaces stored in the PGDATA directory Bug fixes
Fix pg_basebackup to handle tablespaces stored in the
PGDATAdirectory (Robert Haas) §Original release occurrence ·
16.0/changes/145Add pg_waldump option --save-fullpage to dump full page images Features
Add pg_waldump option
--save-fullpageto dump full page images (David Christensen) §Original release occurrence ·
16.0/changes/146Allow pg_waldump options -t/--timeline to accept hexadecimal values Features
Allow pg_waldump options
-t/--timelineto accept hexadecimal values (Peter Eisentraut) §Original release occurrence ·
16.0/changes/147Add support for progress reporting to pg_verifybackup Features
Add support for progress reporting to pg_verifybackup (Masahiko Sawada) §
Original release occurrence ·
16.0/changes/148Allow pg_rewind to properly track timeline changes Features
Allow pg_rewind to properly track timeline changes (Heikki Linnakangas) § §
Previously if pg_rewind was run after a timeline switch but before a checkpoint was issued, it might incorrectly determine that a rewind was unnecessary.
Original release occurrence ·
16.0/changes/149Have pg_receivewal and pg_recvlogical cleanly exit on SIGTERM Features
Have pg_receivewal and pg_recvlogical cleanly exit on
SIGTERM(Christoph Berg) §This signal is often used by systemd.
Original release occurrence ·
16.0/changes/150Build ICU support by default Features
Build ICU support by default (Jeff Davis) §
This removes build flag
--with-icuand adds flag--without-icu.Original release occurrence ·
16.0/changes/151Add support for SSE2 (Streaming SIMD Extensions 2) vector operations on x86-64 architectures Features
Add support for SSE2 (Streaming SIMD Extensions 2) vector operations on x86-64 architectures (John Naylor) §
Original release occurrence ·
16.0/changes/152Add support for Advanced SIMD (Single Instruction Multiple Data) (NEON) instructions on ARM architectures Features
Add support for Advanced SIMD (Single Instruction Multiple Data) (NEON) instructions on ARM architectures (Nathan Bossart) §
Original release occurrence ·
16.0/changes/153Have Windows binaries built with MSVC use RandomizedBaseAddress (ASLR) Features
Have Windows binaries built with MSVC use
RandomizedBaseAddress(ASLR) (Michael Paquier) §This was already enabled on MinGW builds.
Original release occurrence ·
16.0/changes/154Prevent extension libraries from exporting their symbols by default Features
Prevent extension libraries from exporting their symbols by default (Andres Freund, Tom Lane) § §
Functions that need to be called from the core backend or other extensions must now be explicitly marked
PGDLLEXPORT.Original release occurrence ·
16.0/changes/155Require Windows 10 or newer versions Features
Require Windows 10 or newer versions (Michael Paquier, Juan José Santamaría Flecha) §
Previously Windows Vista and Windows XP were supported.
Original release occurrence ·
16.0/changes/156Require Perl version 5.14 or later Features
Require Perl version 5.14 or later (John Naylor) §
Original release occurrence ·
16.0/changes/157Require Bison version 2.3 or later Features
Require Bison version 2.3 or later (John Naylor) §
Original release occurrence ·
16.0/changes/158Require Flex version 2.5.35 or later Features
Require Flex version 2.5.35 or later (John Naylor) §
Original release occurrence ·
16.0/changes/159Require MIT Kerberos for GSSAPI support Features
Require MIT Kerberos for GSSAPI support (Stephen Frost) §
Original release occurrence ·
16.0/changes/160Remove support for Visual Studio 2013 Features
Remove support for Visual Studio 2013 (Michael Paquier) §
Original release occurrence ·
16.0/changes/161Remove support for HP-UX Features
Remove support for HP-UX (Thomas Munro) §
Original release occurrence ·
16.0/changes/162Remove support for HP/Intel Itanium Features
Remove support for HP/Intel Itanium (Thomas Munro) §
Original release occurrence ·
16.0/changes/163Remove support for M68K, M88K, M32R, and SuperH CPU architectures Features
Original release occurrence ·
16.0/changes/164Remove libpq support for SCM credential authentication Features
Remove libpq support for SCM credential authentication (Michael Paquier) §
Backend support for this authentication method was removed in PostgresSQL 9.1.
Original release occurrence ·
16.0/changes/165Add meson build system Features
Add meson build system (Andres Freund, Nazir Bilal Yavuz, Peter Eisentraut) §
This eventually will replace the Autoconf and Windows-based MSVC build systems.
Original release occurrence ·
16.0/changes/166Allow control of the location of the openssl binary used by the build system Features
Allow control of the location of the openssl binary used by the build system (Peter Eisentraut) §
Make finding openssl program a configure or meson option
Original release occurrence ·
16.0/changes/167Add build option to allow testing of small table segment sizes Features
Add build option to allow testing of small table segment sizes (Andres Freund) §
The build options are
--with-segsize-blocksand-Dsegsize_blocks.Original release occurrence ·
16.0/changes/168Add pgindent options Features
Add pgindent options (Andrew Dunstan) § § § § § § §
The new options are
--show-diff,--silent-diff,--commit, and--help, and allow multiple--excludeoptions. Also require the typedef file to be explicitly specified. Options--code-baseand--buildwere also removed.Original release occurrence ·
16.0/changes/169Add pg_bsd_indent source code to the main tree Features
Add pg_bsd_indent source code to the main tree (Tom Lane) §
Original release occurrence ·
16.0/changes/170Improve make_ctags and make_etags Features
Improve make_ctags and make_etags (Yugo Nagata) §
Original release occurrence ·
16.0/changes/171Adjust pg_attribute columns for efficiency Features
Adjust
pg_attributecolumns for efficiency (Peter Eisentraut) §Original release occurrence ·
16.0/changes/172Improve use of extension-based indexes on boolean columns Features
Improve use of extension-based indexes on boolean columns (Zongliang Quan, Tom Lane) §
Original release occurrence ·
16.0/changes/173Add support for Daitch-Mokotoff Soundex to fuzzystrmatch Features
Add support for Daitch-Mokotoff Soundex to fuzzystrmatch (Dag Lem) §
Original release occurrence ·
16.0/changes/174Allow auto_explain to log values passed to parameterized statements Features
Allow auto_explain to log values passed to parameterized statements (Dagfinn Ilmari Mannsåker) §
This affects queries using server-side
PREPARE/EXECUTEand client-side parse/bind. Logging is controlled byauto_explain.log_parameter_max_length; by default query parameters will be logged with no length restriction.Original release occurrence ·
16.0/changes/175Have auto_explain's log_verbose mode honor the value of compute_query_id Features
Have auto_explain's
log_verbosemode honor the value ofcompute_query_id(Atsushi Torikoshi) §Previously even if
compute_query_idwas enabled,log_verbosewas not showing the query identifier.Original release occurrence ·
16.0/changes/176Change the maximum length of ltree labels from 256 to 1000 and allow hyphens Features
Original release occurrence ·
16.0/changes/177Have pg_stat_statements normalize constants used in utility commands Features
Have
pg_stat_statementsnormalize constants used in utility commands (Michael Paquier) §Previously constants appeared instead of placeholders, e.g.,
$1.Original release occurrence ·
16.0/changes/178Add pg_walinspect function pg_get_wal_block_info() to report WAL block information Features
Add pg_walinspect function
pg_get_wal_block_info()to report WAL block information (Michael Paquier, Melanie Plageman, Bharath Rupireddy) § § § §Original release occurrence ·
16.0/changes/179Change how pg_walinspect functions pg_get_wal_records_info() and pg_get_wal_stats() interpret ending LSNs Features
Change how pg_walinspect functions
pg_get_wal_records_info()andpg_get_wal_stats()interpret ending LSNs (Bharath Rupireddy) §Previously ending LSNs which represent nonexistent WAL locations would generate an error, while they will now be interpreted as the end of the WAL.
Original release occurrence ·
16.0/changes/180Add detailed descriptions of WAL records in pg_walinspect and pg_waldump Features
Add detailed descriptions of WAL records in pg_walinspect and pg_waldump (Melanie Plageman, Peter Geoghegan) § § § §
Original release occurrence ·
16.0/changes/181Add pageinspect function bt_multi_page_stats() to report statistics on multiple pages Features
Add pageinspect function
bt_multi_page_stats()to report statistics on multiple pages (Hamid Akhtar) §This is similar to
bt_page_stats()except it can report on a range of pages.Original release occurrence ·
16.0/changes/182Add empty range output column to pageinspect function brin_page_items() Features
Add empty range output column to pageinspect function
brin_page_items()(Tomas Vondra) §Original release occurrence ·
16.0/changes/183Redesign archive modules to be more flexible Features
Redesign archive modules to be more flexible (Nathan Bossart) §
Initialization changes will require modules written for older versions of Postgres to be updated.
Original release occurrence ·
16.0/changes/184Correct inaccurate pg_stat_statements row tracking extended query protocol statements Bug fixes
Correct inaccurate pg_stat_statements row tracking extended query protocol statements (Sami Imseih) §
Original release occurrence ·
16.0/changes/185Add pg_buffercache function pg_buffercache_usage_counts() to report usage totals Features
Add pg_buffercache function
pg_buffercache_usage_counts()to report usage totals (Nathan Bossart) §Original release occurrence ·
16.0/changes/186Add pg_buffercache function pg_buffercache_summary() to report summarized buffer statistics Features
Add pg_buffercache function
pg_buffercache_summary()to report summarized buffer statistics (Melih Mutlu) §Original release occurrence ·
16.0/changes/187Allow the schemas of required extensions to be referenced in extension scripts using the new syntax @extschema:referenced_extension_name@ Features
Allow the schemas of required extensions to be referenced in extension scripts using the new syntax
@extschema:referenced_extension_name@(Regina Obe) §Original release occurrence ·
16.0/changes/188Allow required extensions to be marked as non-relocatable using no_relocate Features
Allow required extensions to be marked as non-relocatable using
no_relocate(Regina Obe) §This allows
@extschema:referenced_extension_name@to be treated as a constant for the lifetime of the extension.Original release occurrence ·
16.0/changes/189Allow postgres_fdw to do aborts in parallel Features
Allow postgres_fdw to do aborts in parallel (Etsuro Fujita) §
This is enabled with postgres_fdw option
parallel_abort.Original release occurrence ·
16.0/changes/190Make ANALYZE on foreign postgres_fdw tables more efficient Features
Make
ANALYZEon foreign postgres_fdw tables more efficient (Tomas Vondra) §The postgres_fdw option
analyze_samplingcontrols the sampling method.Original release occurrence ·
16.0/changes/191Restrict shipment of reg* type constants in postgres_fdw to those referencing built-in objects or extensions marked as shippable Features
Restrict shipment of
reg* type constants in postgres_fdw to those referencing built-in objects or extensions marked as shippable (Tom Lane) §Original release occurrence ·
16.0/changes/192Have postgres_fdw and dblink handle interrupts during connection establishment Features
Original release occurrence ·
16.0/changes/193
Security evidence
60 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.
CVE-2026-6638 · PostgreSQL REFRESH PUBLICATION allows SQL injection via table name CVSS 3.7
SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.
Fixed in this branch: 16.14. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-6637 · PostgreSQL refint allows stack buffer overflow and SQL injection CVSS 8.8
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 16.14. Component: contrib module.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6479 · PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion CVSS 7.5
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 16.14. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2026-6478 · PostgreSQL discloses MD5-hashed passwords via covert timing channel CVSS 6.5
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 16.14. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-6477 · PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory CVSS 8.8
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 16.14. Component: client.
Official affected-branch entry: 16.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6475 · PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice CVSS 8.8
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 16.14. Component: client.
Official affected-branch entry: 16.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6474 · PostgreSQL timeofday() can disclose portions of server memory CVSS 4.3
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 16.14. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-6473 · PostgreSQL server undersizes allocations, via integer wraparound CVSS 8.8
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 16.14. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
- 16.15: Fix integer overflows in memory-allocation calculations in PL/Perl and PL/Tcl
- 16.14: Fix assorted integer overflows in memory-allocation calculations
- 16.14: Reject over-length options in ts_headline()
- 16.14: Guard against field overflow within contrib/intarray's query_int type and contrib/ltree's ltxtquery type
- 16.14: Guard against overly long values of contrib/ltree's lquery type
CVE-2026-6472 · PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege CVSS 5.4
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 16.14. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-6471 · PostgreSQL logical decoding can dlopen arbitrary file CVSS 7.2
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6470 · PostgreSQL fails to check type USAGE privilege CVSS 4.3
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2026-6469 · PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership CVSS 3.8
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Release-note mentions:
CVE-2026-6464 · PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands CVSS 8.1
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: client.
Official affected-branch entry: 16.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2006 · PostgreSQL missing validation of multibyte character length executes arbitrary code CVSS 8.8
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 16.12. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2005 · PostgreSQL pgcrypto heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 16.12. Component: contrib module.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2004 · PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code CVSS 8.8
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 16.12. Component: contrib module.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2003 · PostgreSQL oidvector discloses a few bytes of memory CVSS 4.3
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 16.12. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-19385 · PostgreSQL pg_dump heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: client.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-18408 · PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: client.
Official affected-branch entry: 16.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-18024 · PostgreSQL ascii() function reads past end of buffer CVSS 4.3
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-16241 · PostgreSQL ECPG integer underflow can crash the client CVSS 3.8
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: client.
Official affected-branch entry: 16.
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Release-note mentions:
CVE-2026-16239 · PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code CVSS 8.8
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-16238 · PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code CVSS 8.8
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-15742 · PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound CVSS 8.8
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: contrib module.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-15741 · PostgreSQL expression deparse allows SQL injection via EXTRACT argument CVSS 8.8
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14681 · PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL CVSS 4.2
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14680 · PostgreSQL type confusion via "internal" arguments CVSS 8.8
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14679 · PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory CVSS 8.2
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Release-note mentions:
CVE-2026-14678 · PostgreSQL pg_trgm picksplit reads past end of buffer CVSS 4.3
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: contrib module.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-14677 · PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound CVSS 8.8
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14676 · PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
No fixed version for this branch is recorded. Component: contrib module.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14673 · PostgreSQL amcheck does not clear untrusted search path CVSS 3.8
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.
Fixed in this branch: 16.15. Component: contrib module.
Official affected-branch entry: 16.
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14672 · PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle CVSS 5.3
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-14671 · PostgreSQL refint plan cache type confusion executes arbitrary code CVSS 8.8
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: contrib module.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14670 · PostgreSQL plperl tied object heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14669 · PostgreSQL to_char heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14668 · PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read CVSS 8.1
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Release-note mentions:
CVE-2026-14666 · PostgreSQL row security caching disregards role modifications CVSS 4.2
Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14664 · PostgreSQL regexp heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14663 · PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext CVSS 6.5
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: contrib module.
Official affected-branch entry: 16.
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14662 · PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound CVSS 8.8
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 16.15. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2025-8715 · PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server CVSS 8.8
Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.
Fixed in this branch: 16.10. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
Fixed in this branch: 16.10. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2025-8713 · PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table CVSS 3.1
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
Fixed in this branch: 16.10. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2025-4207 · PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation CVSS 5.9
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
Fixed in this branch: 16.9. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound CVSS 5.9
Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
Fixed in this branch: 16.11. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege CVSS 3.1
Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
Fixed in this branch: 16.11. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2025-1094 · PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation CVSS 8.1
Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.
Fixed in this branch: 16.7. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-7348 · PostgreSQL relation replacement during pg_dump executes arbitrary SQL CVSS 8.8
Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected. The PostgreSQL project thanks Noah Misch for reporting this problem.
Fixed in this branch: 16.4. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-4317 · Restrict visibility of "pg_stats_ext" and "pg_stats_ext_exprs" entries to the table owner CVSS 3.1
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes, which are provided as a convenience in the below section. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected. This fix only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after this fix is applied. If you have a current PostgreSQL installation and are concerned about this issue, please use the following remediation steps to fix the issue: From the above URLs, you can click the URL that says "raw" to download a version that you can copy and paste. Be sure to use the script appropriate to your PostgreSQL major version. If you do not see this file, either your version is not vulnerable (only PostgreSQL 14, 15, and 16 are affected) or your minor version is too old to have the fix. \i /usr/share/postgresql/fix-CVE-2024-4317.sql ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; After executing the fix-CVE-2024-4317.sql script in template0 and template1 , you should revoke the ability for template0 to accept connections. You can do this with the following command: ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; The PostgreSQL project thanks Lukas Fittl for reporting this problem.
Fixed in this branch: 16.3. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code CVSS 8.8
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.
Fixed in this branch: 16.5. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID CVSS 4.2
Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.
Fixed in this branch: 16.5. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle CVSS 3.1
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.
Fixed in this branch: 16.5. Component: client.
Official affected-branch entry: 16.
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Release-note mentions:
CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes CVSS 4.2
Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
Fixed in this branch: 16.5. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2024-0985 · PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL CVSS 8.0
UPDATE (June 19, 2024) : Added v16 as impacted. Updated description to clarify the attack vector. Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view.
Fixed in this branch: 16.2. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes CVSS 2.2
Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.
Fixed in this branch: 16.1. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2023-5869 · Buffer overrun from integer overflow in array modification CVSS 8.8
While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.
Fixed in this branch: 16.1. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2023-5868 · Memory disclosure in aggregate function calls CVSS 4.3
Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.
Fixed in this branch: 16.1. Component: core server.
Official affected-branch entry: 16.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2012-0868 · Line breaks in object names can be exploited to execute arbitrary SQL when reloading a pg_dump file.
No fixed version for this branch is recorded.
Release-note mentions:
Export this branch as JSON · Compare any two indexed releases