↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Versions

PostgreSQL 16

Read the English manual

Supported · Recorded build 16.15 · 2026-08-13

First stable release
2023-09-14
Support end
2028-11-09
Indexed releases
16
Original release-note entries
930

Manuals & provenance

PostgreSQL 16 English manual · 1172 loaded pages.

Manual loaded 2026-09-27T00:10:47.078613.

Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.

Upgrade considerations

Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.

Compatibility notes for 16.0 · Changes from the initial release through 16.15

Original migration guidance for 16.0

A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 19.6 for general information on migrating to new major releases.

Version 16 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:

Release history

Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.

ReleaseDate / snapshot cutoffAll changesBug fixesMigration entriesCVE mentions
16.15 2026-08-13 9842031
16.14 2026-05-14 502009
16.13 2026-02-26 6501
16.12 2026-02-12 451804
16.11 2025-11-13 593202
16.10 2025-08-14 591905
16.9 2025-05-08 481901
16.8 2025-02-20 2101
16.7 2025-02-13 553101
16.6 2024-11-21 8401
16.5 2024-11-14 542504
16.4 2024-08-08 542702
16.3 2024-05-09 572701
16.2 2024-02-08 703001
16.1 2023-11-09 592803
16.0 2023-09-14 2063130

Initial release changes

Original entries from 16.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.

206 of 206 original entries.

  • Change assignment rules for PL/pgSQL bound cursor variables Compatibility Migration

    Change assignment rules for PL/pgSQL bound cursor variables (Tom Lane) §

    Previously, the string value of such variables was set to match the variable name during cursor assignment; now it will be assigned during OPEN, and will not match the variable name. To restore the previous behavior, assign the desired portal name to the cursor variable before OPEN.

    Original release occurrence · 16.0/migration/001

  • Disallow NULLS NOT DISTINCT indexes for primary keys Compatibility Migration

    Disallow NULLS NOT DISTINCT indexes for primary keys (Daniel Gustafsson) §

    Original release occurrence · 16.0/migration/002

  • Change REINDEX DATABASE and reindexdb to not process indexes on system catalogs Compatibility Migration

    Change REINDEX DATABASE and reindexdb to not process indexes on system catalogs (Simon Riggs) § §

    Processing such indexes is still possible using REINDEX SYSTEM and reindexdb --system.

    Original release occurrence · 16.0/migration/003

  • Tighten GENERATED expression restrictions on inherited and partitioned tables Compatibility Migration

    Tighten GENERATED expression restrictions on inherited and partitioned tables (Amit Langote, Tom Lane) §

    Columns of parent/partitioned and child/partition tables must all have the same generation status, though now the actual generation expressions can be different.

    Original release occurrence · 16.0/migration/004

  • Remove pg_walinspect functions pg_get_wal_records_info_till_end_of_wal() and pg_get_wal_stats_till_end_of_wal() Compatibility Migration

    Remove pg_walinspect functions pg_get_wal_records_info_till_end_of_wal() and pg_get_wal_stats_till_end_of_wal() (Bharath Rupireddy) §

    Original release occurrence · 16.0/migration/005

  • Rename server variable force_parallel_mode to debug_parallel_query Compatibility Migration

    Rename server variable force_parallel_mode to debug_parallel_query (David Rowley) § §

    Original release occurrence · 16.0/migration/006

  • Remove the ability to create views manually with ON SELECT rules Compatibility Migration

    Remove the ability to create views manually with ON SELECT rules (Tom Lane) §

    Original release occurrence · 16.0/migration/007

  • Remove the server variable vacuum_defer_cleanup_age Compatibility Migration

    Remove the server variable vacuum_defer_cleanup_age (Andres Freund) §

    This has been unnecessary since hot_standby_feedback and replication slots were added.

    Original release occurrence · 16.0/migration/008

  • Remove server variable promote_trigger_file Compatibility Migration

    Remove server variable promote_trigger_file (Simon Riggs) §

    This was used to promote a standby to primary, but is now more easily accomplished with pg_ctl promote or pg_promote().

    Original release occurrence · 16.0/migration/009

  • Remove read-only server variables lc_collate and lc_ctype Compatibility Migration

    Remove read-only server variables lc_collate and lc_ctype (Peter Eisentraut) §

    Collations and locales can vary between databases so having them as read-only server variables was unhelpful.

    Original release occurrence · 16.0/migration/010

  • Role inheritance now controls the default inheritance status of member roles added during GRANT Compatibility Migration

    Role inheritance now controls the default inheritance status of member roles added during GRANT (Robert Haas) §

    The role's default inheritance behavior can be overridden with the new GRANT ... WITH INHERIT clause. This allows inheritance of some roles and not others because the members' inheritance status is set at GRANT time. Previously the inheritance status of member roles was controlled only by the role's inheritance status, and changes to a role's inheritance status affected all previous and future member roles.

    Original release occurrence · 16.0/migration/011

  • Restrict the privileges of CREATEROLE and its ability to modify other roles Compatibility Migration

    Restrict the privileges of CREATEROLE and its ability to modify other roles (Robert Haas) § §

    Previously roles with CREATEROLE privileges could change many aspects of any non-superuser role. Such changes, including adding members, now require the role requesting the change to have ADMIN OPTION permission. For example, they can now change the CREATEDB, REPLICATION, and BYPASSRLS properties only if they also have those permissions.

    Original release occurrence · 16.0/migration/012

  • Remove symbolic links for the postmaster binary Compatibility Migration

    Remove symbolic links for the postmaster binary (Peter Eisentraut) §

    Original release occurrence · 16.0/migration/013

  • Allow incremental sorts in more cases, including DISTINCT Features

    Allow incremental sorts in more cases, including DISTINCT (David Rowley) § §

    Original release occurrence · 16.0/changes/001

  • Add the ability for aggregates having ORDER BY or DISTINCT to use pre-sorted data Features

    Add the ability for aggregates having ORDER BY or DISTINCT to use pre-sorted data (David Rowley) § § §

    The new server variable enable_presorted_aggregate can be used to disable this.

    Original release occurrence · 16.0/changes/002

  • Allow memoize atop a UNION ALL Features

    Allow memoize atop a UNION ALL (Richard Guo) §

    Original release occurrence · 16.0/changes/003

  • Allow anti-joins to be performed with the non-nullable input as the inner relation Features

    Allow anti-joins to be performed with the non-nullable input as the inner relation (Richard Guo) §

    Original release occurrence · 16.0/changes/004

  • Allow parallelization of FULL and internal right OUTER hash joins Features

    Allow parallelization of FULL and internal right OUTER hash joins (Melanie Plageman, Thomas Munro) §

    Original release occurrence · 16.0/changes/005

  • Improve the accuracy of GIN index access optimizer costs Features

    Improve the accuracy of GIN index access optimizer costs (Ronan Dunklau) §

    Original release occurrence · 16.0/changes/006

  • Allow more efficient addition of heap and index pages Performance

    Allow more efficient addition of heap and index pages (Andres Freund) § §

    Original release occurrence · 16.0/changes/007

  • During non-freeze operations, perform page freezing where appropriate Performance

    During non-freeze operations, perform page freezing where appropriate (Peter Geoghegan) § § §

    This makes full-table freeze vacuums less necessary.

    Original release occurrence · 16.0/changes/008

  • Allow window functions to use the faster ROWS mode internally when RANGE mode is active but unnecessary Performance

    Allow window functions to use the faster ROWS mode internally when RANGE mode is active but unnecessary (David Rowley) §

    Original release occurrence · 16.0/changes/009

  • Allow optimization of always-increasing window functions ntile(), cume_dist() and percent_rank() Performance

    Allow optimization of always-increasing window functions ntile(), cume_dist() and percent_rank() (David Rowley) §

    Original release occurrence · 16.0/changes/010

  • Allow aggregate functions string_agg() and array_agg() to be parallelized Performance

    Allow aggregate functions string_agg() and array_agg() to be parallelized (David Rowley) §

    Original release occurrence · 16.0/changes/011

  • Improve performance by caching RANGE and LIST partition lookups Performance

    Improve performance by caching RANGE and LIST partition lookups (Amit Langote, Hou Zhijie, David Rowley) §

    Original release occurrence · 16.0/changes/012

  • Allow control of the shared buffer usage by vacuum and analyze Performance

    Allow control of the shared buffer usage by vacuum and analyze (Melanie Plageman) § § §

    The VACUUM/ANALYZE option is BUFFER_USAGE_LIMIT, and the vacuumdb option is --buffer-usage-limit. The default value is set by server variable vacuum_buffer_usage_limit, which also controls autovacuum.

    Original release occurrence · 16.0/changes/013

  • Support wal_sync_method=fdatasync on Windows Performance

    Support wal_sync_method=fdatasync on Windows (Thomas Munro) §

    Original release occurrence · 16.0/changes/014

  • Allow HOT updates if only BRIN-indexed columns are updated Performance

    Allow HOT updates if only BRIN-indexed columns are updated (Matthias van de Meent, Josef Simanek, Tomas Vondra) §

    Original release occurrence · 16.0/changes/015

  • Improve the speed of updating the process title Performance

    Improve the speed of updating the process title (David Rowley) §

    Original release occurrence · 16.0/changes/016

  • Allow xid/subxid searches and ASCII string detection to use vector operations Performance

    Allow xid/subxid searches and ASCII string detection to use vector operations (Nathan Bossart, John Naylor) § § § §

    ASCII detection is particularly useful for COPY FROM. Vector operations are also used for some C array searches.

    Original release occurrence · 16.0/changes/017

  • Reduce overhead of memory allocations Performance

    Reduce overhead of memory allocations (Andres Freund, David Rowley) §

    Original release occurrence · 16.0/changes/018

  • Add system view pg_stat_io view to track I/O statistics Features

    Add system view pg_stat_io view to track I/O statistics (Melanie Plageman) § § § § §

    Original release occurrence · 16.0/changes/019

  • Record statistics on the last sequential and index scans on tables Features

    Record statistics on the last sequential and index scans on tables (Dave Page) §

    This information appears in pg_stat_*_tables and pg_stat_*_indexes.

    Original release occurrence · 16.0/changes/020

  • Record statistics on the occurrence of updated rows moving to new pages Features

    Record statistics on the occurrence of updated rows moving to new pages (Corey Huinker) §

    The pg_stat_*_tables column is n_tup_newpage_upd.

    Original release occurrence · 16.0/changes/021

  • Add speculative lock information to the pg_locks system view Features

    Add speculative lock information to the pg_locks system view (Masahiko Sawada, Noriyoshi Shinoda) §

    The transaction id is displayed in the transactionid column and the speculative insertion token is displayed in the objid column.

    Original release occurrence · 16.0/changes/022

  • Add the display of prepared statement result types to the pg_prepared_statements view Features

    Add the display of prepared statement result types to the pg_prepared_statements view (Dagfinn Ilmari Mannsåker) § §

    Original release occurrence · 16.0/changes/023

  • Create subscription statistics entries at subscription creation time so stats_reset is accurate Features

    Create subscription statistics entries at subscription creation time so stats_reset is accurate (Andres Freund) §

    Previously entries were created only when the first statistics were reported.

    Original release occurrence · 16.0/changes/024

  • Correct the I/O accounting for temp relation writes shown in pg_stat_database Bug fixes

    Correct the I/O accounting for temp relation writes shown in pg_stat_database (Melanie Plageman) §

    Original release occurrence · 16.0/changes/025

  • Add function pg_stat_get_backend_subxact() to report on a session's subtransaction cache Features

    Add function pg_stat_get_backend_subxact() to report on a session's subtransaction cache (Dilip Kumar) §

    Original release occurrence · 16.0/changes/026

  • Have pg_stat_get_backend_idset(), pg_stat_get_backend_activity(), and related functions use the unchanging backend id Features

    Have pg_stat_get_backend_idset(), pg_stat_get_backend_activity(), and related functions use the unchanging backend id (Nathan Bossart) §

    Previously the index values might change during the lifetime of the session.

    Original release occurrence · 16.0/changes/027

  • Report stand-alone backends with a special backend type Features

    Report stand-alone backends with a special backend type (Melanie Plageman) §

    Original release occurrence · 16.0/changes/028

  • Add wait event SpinDelay to report spinlock sleep delays Features

    Add wait event SpinDelay to report spinlock sleep delays (Andres Freund) §

    Original release occurrence · 16.0/changes/029

  • Create new wait event DSMAllocate to indicate waiting for dynamic shared memory allocation Features

    Create new wait event DSMAllocate to indicate waiting for dynamic shared memory allocation (Thomas Munro) §

    Previously this type of wait was reported as DSMFillZeroWrite, which was also used by mmap() allocations.

    Original release occurrence · 16.0/changes/030

  • Add the database name to the process title of logical WAL senders Features

    Add the database name to the process title of logical WAL senders (Tatsuhiro Nakamori) §

    Physical WAL senders do not display a database name.

    Original release occurrence · 16.0/changes/031

  • Add checkpoint and REDO LSN information to log_checkpoints messages Features

    Add checkpoint and REDO LSN information to log_checkpoints messages (Bharath Rupireddy, Kyotaro Horiguchi) §

    Original release occurrence · 16.0/changes/032

  • Provide additional details during client certificate failures Features

    Provide additional details during client certificate failures (Jacob Champion) §

    Original release occurrence · 16.0/changes/033

  • Add predefined role pg_create_subscription with permission to create subscriptions Features

    Add predefined role pg_create_subscription with permission to create subscriptions (Robert Haas) §

    Original release occurrence · 16.0/changes/034

  • Allow subscriptions to not require passwords Features

    Allow subscriptions to not require passwords (Robert Haas) § § §

    This is accomplished with the option password_required=false.

    Original release occurrence · 16.0/changes/035

  • Simplify permissions for LOCK TABLE Features

    Simplify permissions for LOCK TABLE (Jeff Davis) §

    Previously a user's ability to perform LOCK TABLE at various lock levels was limited to the lock levels required by the commands they had permission to execute on the table. For example, someone with UPDATE permission could perform all lock levels except ACCESS SHARE, even though it was a lesser lock level. Now users can issue lesser lock levels if they already have permission for greater lock levels.

    Original release occurrence · 16.0/changes/036

  • Allow ALTER GROUP group_name ADD USER user_name to be performed with ADMIN OPTION Features

    Allow ALTER GROUP group_name ADD USER user_name to be performed with ADMIN OPTION (Robert Haas) §

    Previously CREATEROLE permission was required.

    Original release occurrence · 16.0/changes/037

  • Allow GRANT to use WITH ADMIN TRUE/FALSE syntax Features

    Allow GRANT to use WITH ADMIN TRUE/FALSE syntax (Robert Haas) §

    Previously only the WITH ADMIN OPTION syntax was supported.

    Original release occurrence · 16.0/changes/038

  • Allow roles that create other roles to automatically inherit the new role's rights or the ability to SET ROLE to the new role Features

    Allow roles that create other roles to automatically inherit the new role's rights or the ability to SET ROLE to the new role (Robert Haas, Shi Yu) § §

    This is controlled by server variable createrole_self_grant.

    Original release occurrence · 16.0/changes/039

  • Prevent users from changing the default privileges of non-inherited roles Features

    Prevent users from changing the default privileges of non-inherited roles (Robert Haas) §

    This is now only allowed for inherited roles.

    Original release occurrence · 16.0/changes/040

  • When granting role membership, require the granted-by role to be a role that has appropriate permissions Features

    When granting role membership, require the granted-by role to be a role that has appropriate permissions (Robert Haas) §

    This is a requirement even when a non-bootstrap superuser is granting role membership.

    Original release occurrence · 16.0/changes/041

  • Allow non-superusers to grant permissions using a granted-by user that is not the current user Features

    Allow non-superusers to grant permissions using a granted-by user that is not the current user (Robert Haas) §

    The current user still must have sufficient permissions given by the specified granted-by user.

    Original release occurrence · 16.0/changes/042

  • Add GRANT to control permission to use SET ROLE Features

    Add GRANT to control permission to use SET ROLE (Robert Haas) §

    This is controlled by a new GRANT ... SET option.

    Original release occurrence · 16.0/changes/043

  • Add dependency tracking to roles which have granted privileges Features

    Add dependency tracking to roles which have granted privileges (Robert Haas) §

    For example, removing ADMIN OPTION will fail if there are privileges using that option; CASCADE must be used to revoke dependent permissions.

    Original release occurrence · 16.0/changes/044

  • Add dependency tracking of grantors for GRANT records Features

    Add dependency tracking of grantors for GRANT records (Robert Haas) §

    This guarantees that pg_auth_members.grantor values are always valid.

    Original release occurrence · 16.0/changes/045

  • Allow multiple role membership records Features

    Allow multiple role membership records (Robert Haas) § §

    Previously a new membership grant would remove a previous matching membership grant, even if other aspects of the grant did not match.

    Original release occurrence · 16.0/changes/046

  • Prevent removal of superuser privileges for the bootstrap user Features

    Prevent removal of superuser privileges for the bootstrap user (Robert Haas) §

    Restoring such users could lead to errors.

    Original release occurrence · 16.0/changes/047

  • Allow makeaclitem() to accept multiple privilege names Features

    Allow makeaclitem() to accept multiple privilege names (Robins Tharakan) §

    Previously only a single privilege name, like SELECT, was accepted.

    Original release occurrence · 16.0/changes/048

  • Add support for Kerberos credential delegation Features

    Add support for Kerberos credential delegation (Stephen Frost) § § § §

    This is enabled with server variable gss_accept_delegation and libpq connection parameter gssdelegation.

    Original release occurrence · 16.0/changes/049

  • Allow the SCRAM iteration count to be set with server variable scram_iterations Features

    Allow the SCRAM iteration count to be set with server variable scram_iterations (Daniel Gustafsson) §

    Original release occurrence · 16.0/changes/050

  • Improve performance of server variable management Performance

    Improve performance of server variable management (Tom Lane) § §

    Original release occurrence · 16.0/changes/051

  • Tighten restrictions on which server variables can be reset Features

    Tighten restrictions on which server variables can be reset (Masahiko Sawada) §

    Previously, while certain variables, like transaction_isolation, were not affected by RESET ALL, they could be individually reset in inappropriate situations.

    Original release occurrence · 16.0/changes/052

  • Move various postgresql.conf items into new categories Features

    Move various postgresql.conf items into new categories (Shinya Kato) §

    This also affects the categories displayed in the pg_settings view.

    Original release occurrence · 16.0/changes/053

  • Prevent configuration file recursion beyond 10 levels Features

    Prevent configuration file recursion beyond 10 levels (Julien Rouhaud) §

    Original release occurrence · 16.0/changes/054

  • Allow autovacuum to more frequently honor changes to delay settings Features

    Allow autovacuum to more frequently honor changes to delay settings (Melanie Plageman) § §

    Rather than honor changes only at the start of each relation, honor them at the start of each block.

    Original release occurrence · 16.0/changes/055

  • Remove restrictions that archive files be durably renamed Features

    Remove restrictions that archive files be durably renamed (Nathan Bossart) § §

    The archive_command command is now more likely to be called with already-archived files after a crash.

    Original release occurrence · 16.0/changes/056

  • Prevent archive_library and archive_command from being set at the same time Features

    Prevent archive_library and archive_command from being set at the same time (Nathan Bossart) §

    Previously archive_library would override archive_command.

    Original release occurrence · 16.0/changes/057

  • Allow the postmaster to terminate children with an abort signal Features

    Allow the postmaster to terminate children with an abort signal (Tom Lane) §

    This allows collection of a core dump for a stuck child process. This is controlled by send_abort_for_crash and send_abort_for_kill. The postmaster's -T switch is now the same as setting send_abort_for_crash.

    Original release occurrence · 16.0/changes/058

  • Remove the non-functional postmaster -n option Features

    Remove the non-functional postmaster -n option (Tom Lane) §

    Original release occurrence · 16.0/changes/059

  • Allow the server to reserve backend slots for roles with pg_use_reserved_connections membership Features

    Allow the server to reserve backend slots for roles with pg_use_reserved_connections membership (Nathan Bossart) §

    The number of reserved slots is set by server variable reserved_connections.

    Original release occurrence · 16.0/changes/060

  • Allow huge pages to work on newer versions of Windows 10 Features

    Allow huge pages to work on newer versions of Windows 10 (Thomas Munro) §

    This adds the special handling required to enable huge pages on newer versions of Windows 10.

    Original release occurrence · 16.0/changes/061

  • Add debug_io_direct setting for developer usage Features

    Add debug_io_direct setting for developer usage (Thomas Munro, Andres Freund, Bharath Rupireddy) § §

    While primarily for developers, wal_sync_method=open_sync/open_datasync has been modified to not use direct I/O with wal_level=minimal; this is now enabled with debug_io_direct=wal.

    Original release occurrence · 16.0/changes/062

  • Add function pg_split_walfile_name() to report the segment and timeline values of WAL file names Features

    Add function pg_split_walfile_name() to report the segment and timeline values of WAL file names (Bharath Rupireddy) § §

    Original release occurrence · 16.0/changes/063

  • Add support for regular expression matching on database and role entries in pg_hba.conf Features

    Add support for regular expression matching on database and role entries in pg_hba.conf (Bertrand Drouvot) §

    Regular expression patterns are prefixed with a slash. Database and role names that begin with slashes need to be double-quoted if referenced in pg_hba.conf.

    Original release occurrence · 16.0/changes/064

  • Improve user-column handling of pg_ident.conf to match pg_hba.conf Features

    Improve user-column handling of pg_ident.conf to match pg_hba.conf (Jelte Fennema) §

    Specifically, add support for all, role membership with +, and regular expressions with a leading slash. Any user name that matches these patterns must be double-quoted.

    Original release occurrence · 16.0/changes/065

  • Allow include files in pg_hba.conf and pg_ident.conf Features

    Allow include files in pg_hba.conf and pg_ident.conf (Julien Rouhaud) §

    These are controlled by include, include_if_exists, and include_dir. System views pg_hba_file_rules and pg_ident_file_mappings now display the file name.

    Original release occurrence · 16.0/changes/066

  • Allow pg_hba.conf tokens to be of unlimited length Features

    Allow pg_hba.conf tokens to be of unlimited length (Tom Lane) §

    Original release occurrence · 16.0/changes/067

  • Add rule and map numbers to the system view pg_hba_file_rules Features

    Add rule and map numbers to the system view pg_hba_file_rules (Julien Rouhaud) §

    Original release occurrence · 16.0/changes/068

  • Determine the default encoding from the locale when using ICU Features

    Determine the default encoding from the locale when using ICU (Jeff Davis) §

    Previously the default was always UTF-8.

    Original release occurrence · 16.0/changes/069

  • Have CREATE DATABASE and CREATE COLLATION's LOCALE options, and initdb and createdb --locale options, control non-libc collation providers Features

    Have CREATE DATABASE and CREATE COLLATION's LOCALE options, and initdb and createdb --locale options, control non-libc collation providers (Jeff Davis)

    Previously they only controlled libc providers.

    Original release occurrence · 16.0/changes/070

  • Add predefined collations unicode and ucs_basic Features

    Add predefined collations unicode and ucs_basic (Peter Eisentraut) §

    This only works if ICU support is enabled.

    Original release occurrence · 16.0/changes/071

  • Allow custom ICU collation rules to be created Features

    Allow custom ICU collation rules to be created (Peter Eisentraut) §

    This is done using CREATE COLLATION's new RULES clause, as well as new options for CREATE DATABASE, createdb, and initdb.

    Original release occurrence · 16.0/changes/072

  • Allow Windows to import system locales automatically Features

    Allow Windows to import system locales automatically (Juan José Santamaría Flecha) §

    Previously, only ICU locales could be imported on Windows.

    Original release occurrence · 16.0/changes/073

  • Allow logical decoding on standbys Features

    Allow logical decoding on standbys (Bertrand Drouvot, Andres Freund, Amit Khandekar) § § §

    Snapshot WAL records are required for logical slot creation but cannot be created on standbys. To avoid delays, the new function pg_log_standby_snapshot() allows creation of such records.

    Original release occurrence · 16.0/changes/074

  • Add server variable to control how logical decoding publishers transfer changes and how subscribers apply them Features

    Add server variable to control how logical decoding publishers transfer changes and how subscribers apply them (Shi Yu) § § §

    The variable is debug_logical_replication_streaming.

    Original release occurrence · 16.0/changes/075

  • Allow logical replication initial table synchronization to copy rows in binary format Features

    Allow logical replication initial table synchronization to copy rows in binary format (Melih Mutlu) §

    This is only possible for subscriptions marked as binary.

    Original release occurrence · 16.0/changes/076

  • Allow parallel application of logical replication Features

    Allow parallel application of logical replication (Hou Zhijie, Wang Wei, Amit Kapila) § § §

    The CREATE SUBSCRIPTION STREAMING option now supports parallel to enable application of large transactions by parallel workers. The number of parallel workers is controlled by the new server variable max_parallel_apply_workers_per_subscription. Wait events LogicalParallelApplyMain, LogicalParallelApplyStateChange, and LogicalApplySendData were also added. Column leader_pid was added to system view pg_stat_subscription to track parallel activity.

    Original release occurrence · 16.0/changes/077

  • Improve performance for logical replication apply without a primary key Performance

    Improve performance for logical replication apply without a primary key (Onder Kalaci, Amit Kapila) §

    Specifically, REPLICA IDENTITY FULL can now use btree indexes rather than sequentially scanning the table to find matches.

    Original release occurrence · 16.0/changes/078

  • Allow logical replication subscribers to process only changes that have no origin Features

    Allow logical replication subscribers to process only changes that have no origin (Vignesh C, Amit Kapila) § §

    This can be used to avoid replication loops. This is controlled by the new CREATE SUBSCRIPTION ... ORIGIN option.

    Original release occurrence · 16.0/changes/079

  • Perform logical replication SELECT and DML actions as the table owner Features

    Perform logical replication SELECT and DML actions as the table owner (Robert Haas) § §

    This improves security and now requires subscription owners to be either superusers or to have SET ROLE permission on all roles owning tables in the replication set. The previous behavior of performing all operations as the subscription owner can be enabled with the subscription run_as_owner option.

    Original release occurrence · 16.0/changes/080

  • Have wal_retrieve_retry_interval operate on a per-subscription basis Features

    Have wal_retrieve_retry_interval operate on a per-subscription basis (Nathan Bossart) §

    Previously the retry time was applied globally. This also adds wait events >LogicalRepLauncherDSA and LogicalRepLauncherHash.

    Original release occurrence · 16.0/changes/081

  • Add EXPLAIN option GENERIC_PLAN to display the generic plan for a parameterized query Features

    Add EXPLAIN option GENERIC_PLAN to display the generic plan for a parameterized query (Laurenz Albe) §

    Original release occurrence · 16.0/changes/082

  • Allow a COPY FROM value to map to a column's DEFAULT Features

    Allow a COPY FROM value to map to a column's DEFAULT (Israel Barth Rubio) §

    Original release occurrence · 16.0/changes/083

  • Allow COPY into foreign tables to add rows in batches Features

    Allow COPY into foreign tables to add rows in batches (Andrey Lepikhov, Etsuro Fujita) §

    This is controlled by the postgres_fdw option batch_size.

    Original release occurrence · 16.0/changes/084

  • Allow the STORAGE type to be specified by CREATE TABLE Features

    Allow the STORAGE type to be specified by CREATE TABLE (Teodor Sigaev, Aleksander Alekseev) § §

    Previously only ALTER TABLE could control this.

    Original release occurrence · 16.0/changes/085

  • Allow truncate triggers on foreign tables Features

    Allow truncate triggers on foreign tables (Yugo Nagata) §

    Original release occurrence · 16.0/changes/086

  • Allow VACUUM and vacuumdb to only process TOAST tables Features

    Allow VACUUM and vacuumdb to only process TOAST tables (Nathan Bossart) §

    This is accomplished by having VACUUM turn off PROCESS_MAIN or by vacuumdb using the --no-process-main option.

    Original release occurrence · 16.0/changes/087

  • Add VACUUM options to skip or update all frozen statistics Features

    Add VACUUM options to skip or update all frozen statistics (Tom Lane, Nathan Bossart) §

    The options are SKIP_DATABASE_STATS and ONLY_DATABASE_STATS.

    Original release occurrence · 16.0/changes/088

  • Change REINDEX DATABASE and REINDEX SYSTEM to no longer require an argument Features

    Change REINDEX DATABASE and REINDEX SYSTEM to no longer require an argument (Simon Riggs) § §

    Previously the database name had to be specified.

    Original release occurrence · 16.0/changes/089

  • Allow CREATE STATISTICS to generate a statistics name if none is specified Features

    Allow CREATE STATISTICS to generate a statistics name if none is specified (Simon Riggs) §

    Original release occurrence · 16.0/changes/090

  • Allow non-decimal integer literals Features

    Allow non-decimal integer literals (Peter Eisentraut) §

    For example, 0x42F, 0o273, and 0b100101.

    Original release occurrence · 16.0/changes/091

  • Allow NUMERIC to process hexadecimal, octal, and binary integers of any size Features

    Allow NUMERIC to process hexadecimal, octal, and binary integers of any size (Dean Rasheed) §

    Previously only unquoted eight-byte integers were supported with these non-decimal bases.

    Original release occurrence · 16.0/changes/092

  • Allow underscores in integer and numeric constants Features

    Allow underscores in integer and numeric constants (Peter Eisentraut, Dean Rasheed) §

    This can improve readability for long strings of digits.

    Original release occurrence · 16.0/changes/093

  • Accept the spelling +infinity in datetime input Features

    Accept the spelling +infinity in datetime input (Vik Fearing) §

    Original release occurrence · 16.0/changes/094

  • Prevent the specification of epoch and infinity together with other fields in datetime strings Features

    Prevent the specification of epoch and infinity together with other fields in datetime strings (Joseph Koshakow) §

    Original release occurrence · 16.0/changes/095

  • Remove undocumented support for date input in the form YyearMmonthDday Features

    Remove undocumented support for date input in the form YyearMmonthDday (Joseph Koshakow) §

    Original release occurrence · 16.0/changes/096

  • Add functions pg_input_is_valid() and pg_input_error_info() to check for type conversion errors Features

    Add functions pg_input_is_valid() and pg_input_error_info() to check for type conversion errors (Tom Lane) § §

    Original release occurrence · 16.0/changes/097

  • Allow subqueries in the FROM clause to omit aliases Features

    Allow subqueries in the FROM clause to omit aliases (Dean Rasheed) §

    Original release occurrence · 16.0/changes/098

  • Add support for enhanced numeric literals in SQL/JSON paths Features

    Add support for enhanced numeric literals in SQL/JSON paths (Peter Eisentraut) §

    For example, allow hexadecimal, octal, and binary integers and underscores between digits.

    Original release occurrence · 16.0/changes/099

  • Add SQL/JSON constructors Features

    Add SQL/JSON constructors (Nikita Glukhov, Teodor Sigaev, Oleg Bartunov, Alexander Korotkov, Amit Langote) §

    The new functions JSON_ARRAY(), JSON_ARRAYAGG(), JSON_OBJECT(), and JSON_OBJECTAGG() are part of the SQL standard.

    Original release occurrence · 16.0/changes/100

  • Add SQL/JSON object checks Features

    Add SQL/JSON object checks (Nikita Glukhov, Teodor Sigaev, Oleg Bartunov, Alexander Korotkov, Amit Langote, Andrew Dunstan) §

    The IS JSON checks include checks for values, arrays, objects, scalars, and unique keys.

    Original release occurrence · 16.0/changes/101

  • Allow JSON string parsing to use vector operations Features

    Allow JSON string parsing to use vector operations (John Naylor) §

    Original release occurrence · 16.0/changes/102

  • Improve the handling of full text highlighting function ts_headline() for OR and NOT expressions Features

    Improve the handling of full text highlighting function ts_headline() for OR and NOT expressions (Tom Lane) §

    Original release occurrence · 16.0/changes/103

  • Add functions to add, subtract, and generate timestamptz values in a specified time zone Features

    Add functions to add, subtract, and generate timestamptz values in a specified time zone (Przemyslaw Sztoch, Gurjeet Singh) §

    The functions are date_add(), date_subtract(), and generate_series().

    Original release occurrence · 16.0/changes/104

  • Change date_trunc(unit, timestamptz, time_zone) to be an immutable function Features

    Change date_trunc(unit, timestamptz, time_zone) to be an immutable function (Przemyslaw Sztoch) §

    This allows the creation of expression indexes using this function.

    Original release occurrence · 16.0/changes/105

  • Add server variable SYSTEM_USER Features

    Add server variable SYSTEM_USER (Bertrand Drouvot) §

    This reports the authentication method and its authenticated user.

    Original release occurrence · 16.0/changes/106

  • Add functions array_sample() and array_shuffle() Features

    Add functions array_sample() and array_shuffle() (Martin Kalcher) §

    Original release occurrence · 16.0/changes/107

  • Add aggregate function ANY_VALUE() which returns any value from a set Features

    Add aggregate function ANY_VALUE() which returns any value from a set (Vik Fearing) §

    Original release occurrence · 16.0/changes/108

  • Add function random_normal() to supply normally-distributed random numbers Features

    Add function random_normal() to supply normally-distributed random numbers (Paul Ramsey) §

    Original release occurrence · 16.0/changes/109

  • Add error function erf() and its complement erfc() Features

    Add error function erf() and its complement erfc() (Dean Rasheed) §

    Original release occurrence · 16.0/changes/110

  • Improve the accuracy of numeric power() for integer exponents Features

    Improve the accuracy of numeric power() for integer exponents (Dean Rasheed) §

    Original release occurrence · 16.0/changes/111

  • Add XMLSERIALIZE() option INDENT to pretty-print its output Features

    Add XMLSERIALIZE() option INDENT to pretty-print its output (Jim Jones) §

    Original release occurrence · 16.0/changes/112

  • Change pg_collation_actual_version() to return a reasonable value for the default collation Features

    Change pg_collation_actual_version() to return a reasonable value for the default collation (Jeff Davis) §

    Previously it returned NULL.

    Original release occurrence · 16.0/changes/113

  • Allow pg_read_file() and pg_read_binary_file() to ignore missing files Features

    Allow pg_read_file() and pg_read_binary_file() to ignore missing files (Kyotaro Horiguchi) §

    Original release occurrence · 16.0/changes/114

  • Add byte specification (B) to pg_size_bytes() Features

    Add byte specification (B) to pg_size_bytes() (Peter Eisentraut) §

    Original release occurrence · 16.0/changes/115

  • Allow to_reg* functions to accept numeric OIDs as input Features

    Allow to_reg* functions to accept numeric OIDs as input (Tom Lane) §

    Original release occurrence · 16.0/changes/116

  • Add the ability to get the current function's OID in PL/pgSQL Features

    Add the ability to get the current function's OID in PL/pgSQL (Pavel Stehule) §

    This is accomplished with GET DIAGNOSTICS variable = PG_ROUTINE_OID.

    Original release occurrence · 16.0/changes/117

  • Add libpq connection option require_auth to specify a list of acceptable authentication methods Features

    Add libpq connection option require_auth to specify a list of acceptable authentication methods (Jacob Champion) §

    This can also be used to disallow certain authentication methods.

    Original release occurrence · 16.0/changes/118

  • Allow multiple libpq-specified hosts to be randomly selected Features

    Allow multiple libpq-specified hosts to be randomly selected (Jelte Fennema) § §

    This is enabled with load_balance_hosts=random and can be used for load balancing.

    Original release occurrence · 16.0/changes/119

  • Add libpq option sslcertmode to control transmission of the client certificate Features

    Add libpq option sslcertmode to control transmission of the client certificate (Jacob Champion) §

    The option values are disable, allow, and require.

    Original release occurrence · 16.0/changes/120

  • Allow libpq to use the system certificate pool for certificate verification Features

    Allow libpq to use the system certificate pool for certificate verification (Jacob Champion, Thomas Habets) §

    This is enabled with sslrootcert=system, which also enables sslmode=verify-full.

    Original release occurrence · 16.0/changes/121

  • Allow ECPG variable declarations to use typedef names that match unreserved SQL keywords Features

    Allow ECPG variable declarations to use typedef names that match unreserved SQL keywords (Tom Lane) §

    This change does prevent keywords which match C typedef names from being processed as keywords in later EXEC SQL blocks.

    Original release occurrence · 16.0/changes/122

  • Allow psql to control the maximum width of header lines in expanded format Features

    Allow psql to control the maximum width of header lines in expanded format (Platon Pronko) §

    This is controlled by xheader_width.

    Original release occurrence · 16.0/changes/123

  • Add psql command \drg to show role membership details Features

    Add psql command \drg to show role membership details (Pavel Luzanov) § §

    The Member of output column has been removed from \du and \dg because this new command displays this information in more detail.

    Original release occurrence · 16.0/changes/124

  • Allow psql's access privilege commands to show system objects Features

    Allow psql's access privilege commands to show system objects (Nathan Bossart) § §

    The options are \dpS and \zS.

    Original release occurrence · 16.0/changes/125

  • Add FOREIGN designation to psql \d+ for foreign table children and partitions Features

    Add FOREIGN designation to psql \d+ for foreign table children and partitions (Ian Lawrence Barwick) §

    Original release occurrence · 16.0/changes/126

  • Prevent \df+ from showing function source code Features

    Prevent \df+ from showing function source code (Isaac Morland) §

    Function bodies are more easily viewed with \sf.

    Original release occurrence · 16.0/changes/127

  • Allow psql to submit queries using the extended query protocol Features

    Allow psql to submit queries using the extended query protocol (Peter Eisentraut) §

    Passing arguments to such queries is done using the new psql \bind command.

    Original release occurrence · 16.0/changes/128

  • Allow psql \watch to limit the number of executions Features

    Allow psql \watch to limit the number of executions (Andrey Borodin) §

    The \watch options can now be named when specified.

    Original release occurrence · 16.0/changes/129

  • Detect invalid values for psql \watch, and allow zero to specify no delay Features

    Detect invalid values for psql \watch, and allow zero to specify no delay (Andrey Borodin) §

    Original release occurrence · 16.0/changes/130

  • Allow psql scripts to obtain the exit status of shell commands and queries Features

    Allow psql scripts to obtain the exit status of shell commands and queries (Corey Huinker, Tom Lane) § §

    The new psql control variables are SHELL_ERROR and SHELL_EXIT_CODE.

    Original release occurrence · 16.0/changes/131

  • Various psql tab completion improvements Features

    Various psql tab completion improvements (Vignesh C, Aleksander Alekseev, Dagfinn Ilmari Mannsåker, Shi Yu, Michael Paquier, Ken Kato, Peter Smith) § § § § § § § § § § § §

    Original release occurrence · 16.0/changes/132

  • Add pg_dump control of dumping child tables and partitions Features

    Add pg_dump control of dumping child tables and partitions (Gilles Darold) §

    The new options are --table-and-children, --exclude-table-and-children, and --exclude-table-data-and-children.

    Original release occurrence · 16.0/changes/133

  • Add LZ4 and Zstandard compression to pg_dump Features

    Add LZ4 and Zstandard compression to pg_dump (Georgios Kokolatos, Justin Pryzby)

    Original release occurrence · 16.0/changes/134

  • Allow pg_dump and pg_basebackup to use long mode for compression Features

    Allow pg_dump and pg_basebackup to use long mode for compression (Justin Pryzby) § § § §

    Original release occurrence · 16.0/changes/135

  • Improve pg_dump to accept a more consistent compression syntax Features

    Improve pg_dump to accept a more consistent compression syntax (Georgios Kokolatos) §

    Options like --compress=gzip:5.

    Original release occurrence · 16.0/changes/136

  • Add initdb option to set server variables for the duration of initdb and all future server starts Features

    Add initdb option to set server variables for the duration of initdb and all future server starts (Tom Lane) §

    The option is -c name=value.

    Original release occurrence · 16.0/changes/137

  • Add options to createuser to control more user options Features

    Add options to createuser to control more user options (Shinya Kato) § §

    Specifically, the new options control the valid-until date, bypassing of row-level security, and role membership.

    Original release occurrence · 16.0/changes/138

  • Deprecate createuser option --role Features

    Deprecate createuser option --role (Nathan Bossart) § §

    This option could be easily confused with new createuser role membership options, so option --member-of has been added with the same functionality. The --role option can still be used.

    Original release occurrence · 16.0/changes/139

  • Allow control of vacuumdb schema processing Features

    Allow control of vacuumdb schema processing (Gilles Darold) §

    These are controlled by options --schema and --exclude-schema.

    Original release occurrence · 16.0/changes/140

  • Use new VACUUM options to improve the performance of vacuumdb Performance

    Use new VACUUM options to improve the performance of vacuumdb (Tom Lane, Nathan Bossart) §

    Original release occurrence · 16.0/changes/141

  • Have pg_upgrade set the new cluster's locale and encoding Features

    Have pg_upgrade set the new cluster's locale and encoding (Jeff Davis) §

    This removes the requirement that the new cluster be created with the same locale and encoding settings.

    Original release occurrence · 16.0/changes/142

  • Add pg_upgrade option to specify the default transfer mode Features

    Add pg_upgrade option to specify the default transfer mode (Peter Eisentraut) §

    The option is --copy.

    Original release occurrence · 16.0/changes/143

  • Improve pg_basebackup to accept numeric compression options Features

    Improve pg_basebackup to accept numeric compression options (Georgios Kokolatos, Michael Paquier) §

    Options like --compress=server-5 are now supported.

    Original release occurrence · 16.0/changes/144

  • Fix pg_basebackup to handle tablespaces stored in the PGDATA directory Bug fixes

    Fix pg_basebackup to handle tablespaces stored in the PGDATA directory (Robert Haas) §

    Original release occurrence · 16.0/changes/145

  • Add pg_waldump option --save-fullpage to dump full page images Features

    Add pg_waldump option --save-fullpage to dump full page images (David Christensen) §

    Original release occurrence · 16.0/changes/146

  • Allow pg_waldump options -t/--timeline to accept hexadecimal values Features

    Allow pg_waldump options -t/--timeline to accept hexadecimal values (Peter Eisentraut) §

    Original release occurrence · 16.0/changes/147

  • Add support for progress reporting to pg_verifybackup Features

    Add support for progress reporting to pg_verifybackup (Masahiko Sawada) §

    Original release occurrence · 16.0/changes/148

  • Allow pg_rewind to properly track timeline changes Features

    Allow pg_rewind to properly track timeline changes (Heikki Linnakangas) § §

    Previously if pg_rewind was run after a timeline switch but before a checkpoint was issued, it might incorrectly determine that a rewind was unnecessary.

    Original release occurrence · 16.0/changes/149

  • Have pg_receivewal and pg_recvlogical cleanly exit on SIGTERM Features

    Have pg_receivewal and pg_recvlogical cleanly exit on SIGTERM (Christoph Berg) §

    This signal is often used by systemd.

    Original release occurrence · 16.0/changes/150

  • Build ICU support by default Features

    Build ICU support by default (Jeff Davis) §

    This removes build flag --with-icu and adds flag --without-icu.

    Original release occurrence · 16.0/changes/151

  • Add support for SSE2 (Streaming SIMD Extensions 2) vector operations on x86-64 architectures Features

    Add support for SSE2 (Streaming SIMD Extensions 2) vector operations on x86-64 architectures (John Naylor) §

    Original release occurrence · 16.0/changes/152

  • Add support for Advanced SIMD (Single Instruction Multiple Data) (NEON) instructions on ARM architectures Features

    Add support for Advanced SIMD (Single Instruction Multiple Data) (NEON) instructions on ARM architectures (Nathan Bossart) §

    Original release occurrence · 16.0/changes/153

  • Have Windows binaries built with MSVC use RandomizedBaseAddress (ASLR) Features

    Have Windows binaries built with MSVC use RandomizedBaseAddress (ASLR) (Michael Paquier) §

    This was already enabled on MinGW builds.

    Original release occurrence · 16.0/changes/154

  • Prevent extension libraries from exporting their symbols by default Features

    Prevent extension libraries from exporting their symbols by default (Andres Freund, Tom Lane) § §

    Functions that need to be called from the core backend or other extensions must now be explicitly marked PGDLLEXPORT.

    Original release occurrence · 16.0/changes/155

  • Require Windows 10 or newer versions Features

    Require Windows 10 or newer versions (Michael Paquier, Juan José Santamaría Flecha) §

    Previously Windows Vista and Windows XP were supported.

    Original release occurrence · 16.0/changes/156

  • Require Perl version 5.14 or later Features

    Require Perl version 5.14 or later (John Naylor) §

    Original release occurrence · 16.0/changes/157

  • Require Bison version 2.3 or later Features

    Require Bison version 2.3 or later (John Naylor) §

    Original release occurrence · 16.0/changes/158

  • Require Flex version 2.5.35 or later Features

    Require Flex version 2.5.35 or later (John Naylor) §

    Original release occurrence · 16.0/changes/159

  • Require MIT Kerberos for GSSAPI support Features

    Require MIT Kerberos for GSSAPI support (Stephen Frost) §

    Original release occurrence · 16.0/changes/160

  • Remove support for Visual Studio 2013 Features

    Remove support for Visual Studio 2013 (Michael Paquier) §

    Original release occurrence · 16.0/changes/161

  • Remove support for HP-UX Features

    Remove support for HP-UX (Thomas Munro) §

    Original release occurrence · 16.0/changes/162

  • Remove support for HP/Intel Itanium Features

    Remove support for HP/Intel Itanium (Thomas Munro) §

    Original release occurrence · 16.0/changes/163

  • Remove support for M68K, M88K, M32R, and SuperH CPU architectures Features

    Remove support for M68K, M88K, M32R, and SuperH CPU architectures (Thomas Munro) § §

    Original release occurrence · 16.0/changes/164

  • Remove libpq support for SCM credential authentication Features

    Remove libpq support for SCM credential authentication (Michael Paquier) §

    Backend support for this authentication method was removed in PostgresSQL 9.1.

    Original release occurrence · 16.0/changes/165

  • Add meson build system Features

    Add meson build system (Andres Freund, Nazir Bilal Yavuz, Peter Eisentraut) §

    This eventually will replace the Autoconf and Windows-based MSVC build systems.

    Original release occurrence · 16.0/changes/166

  • Allow control of the location of the openssl binary used by the build system Features

    Allow control of the location of the openssl binary used by the build system (Peter Eisentraut) §

    Make finding openssl program a configure or meson option

    Original release occurrence · 16.0/changes/167

  • Add build option to allow testing of small table segment sizes Features

    Add build option to allow testing of small table segment sizes (Andres Freund) §

    The build options are --with-segsize-blocks and -Dsegsize_blocks.

    Original release occurrence · 16.0/changes/168

  • Add pgindent options Features

    Add pgindent options (Andrew Dunstan) § § § § § § §

    The new options are --show-diff, --silent-diff, --commit, and --help, and allow multiple --exclude options. Also require the typedef file to be explicitly specified. Options --code-base and --build were also removed.

    Original release occurrence · 16.0/changes/169

  • Add pg_bsd_indent source code to the main tree Features

    Add pg_bsd_indent source code to the main tree (Tom Lane) §

    Original release occurrence · 16.0/changes/170

  • Improve make_ctags and make_etags Features

    Improve make_ctags and make_etags (Yugo Nagata) §

    Original release occurrence · 16.0/changes/171

  • Adjust pg_attribute columns for efficiency Features

    Adjust pg_attribute columns for efficiency (Peter Eisentraut) §

    Original release occurrence · 16.0/changes/172

  • Improve use of extension-based indexes on boolean columns Features

    Improve use of extension-based indexes on boolean columns (Zongliang Quan, Tom Lane) §

    Original release occurrence · 16.0/changes/173

  • Add support for Daitch-Mokotoff Soundex to fuzzystrmatch Features

    Add support for Daitch-Mokotoff Soundex to fuzzystrmatch (Dag Lem) §

    Original release occurrence · 16.0/changes/174

  • Allow auto_explain to log values passed to parameterized statements Features

    Allow auto_explain to log values passed to parameterized statements (Dagfinn Ilmari Mannsåker) §

    This affects queries using server-side PREPARE/EXECUTE and client-side parse/bind. Logging is controlled by auto_explain.log_parameter_max_length; by default query parameters will be logged with no length restriction.

    Original release occurrence · 16.0/changes/175

  • Have auto_explain's log_verbose mode honor the value of compute_query_id Features

    Have auto_explain's log_verbose mode honor the value of compute_query_id (Atsushi Torikoshi) §

    Previously even if compute_query_id was enabled, log_verbose was not showing the query identifier.

    Original release occurrence · 16.0/changes/176

  • Change the maximum length of ltree labels from 256 to 1000 and allow hyphens Features

    Change the maximum length of ltree labels from 256 to 1000 and allow hyphens (Garen Torikian) §

    Original release occurrence · 16.0/changes/177

  • Have pg_stat_statements normalize constants used in utility commands Features

    Have pg_stat_statements normalize constants used in utility commands (Michael Paquier) §

    Previously constants appeared instead of placeholders, e.g., $1.

    Original release occurrence · 16.0/changes/178

  • Add pg_walinspect function pg_get_wal_block_info() to report WAL block information Features

    Add pg_walinspect function pg_get_wal_block_info() to report WAL block information (Michael Paquier, Melanie Plageman, Bharath Rupireddy) § § § §

    Original release occurrence · 16.0/changes/179

  • Change how pg_walinspect functions pg_get_wal_records_info() and pg_get_wal_stats() interpret ending LSNs Features

    Change how pg_walinspect functions pg_get_wal_records_info() and pg_get_wal_stats() interpret ending LSNs (Bharath Rupireddy) §

    Previously ending LSNs which represent nonexistent WAL locations would generate an error, while they will now be interpreted as the end of the WAL.

    Original release occurrence · 16.0/changes/180

  • Add detailed descriptions of WAL records in pg_walinspect and pg_waldump Features

    Add detailed descriptions of WAL records in pg_walinspect and pg_waldump (Melanie Plageman, Peter Geoghegan) § § § §

    Original release occurrence · 16.0/changes/181

  • Add pageinspect function bt_multi_page_stats() to report statistics on multiple pages Features

    Add pageinspect function bt_multi_page_stats() to report statistics on multiple pages (Hamid Akhtar) §

    This is similar to bt_page_stats() except it can report on a range of pages.

    Original release occurrence · 16.0/changes/182

  • Add empty range output column to pageinspect function brin_page_items() Features

    Add empty range output column to pageinspect function brin_page_items() (Tomas Vondra) §

    Original release occurrence · 16.0/changes/183

  • Redesign archive modules to be more flexible Features

    Redesign archive modules to be more flexible (Nathan Bossart) §

    Initialization changes will require modules written for older versions of Postgres to be updated.

    Original release occurrence · 16.0/changes/184

  • Correct inaccurate pg_stat_statements row tracking extended query protocol statements Bug fixes

    Correct inaccurate pg_stat_statements row tracking extended query protocol statements (Sami Imseih) §

    Original release occurrence · 16.0/changes/185

  • Add pg_buffercache function pg_buffercache_usage_counts() to report usage totals Features

    Add pg_buffercache function pg_buffercache_usage_counts() to report usage totals (Nathan Bossart) §

    Original release occurrence · 16.0/changes/186

  • Add pg_buffercache function pg_buffercache_summary() to report summarized buffer statistics Features

    Add pg_buffercache function pg_buffercache_summary() to report summarized buffer statistics (Melih Mutlu) §

    Original release occurrence · 16.0/changes/187

  • Allow the schemas of required extensions to be referenced in extension scripts using the new syntax @extschema:referenced_extension_name@ Features

    Allow the schemas of required extensions to be referenced in extension scripts using the new syntax @extschema:referenced_extension_name@ (Regina Obe) §

    Original release occurrence · 16.0/changes/188

  • Allow required extensions to be marked as non-relocatable using no_relocate Features

    Allow required extensions to be marked as non-relocatable using no_relocate (Regina Obe) §

    This allows @extschema:referenced_extension_name@ to be treated as a constant for the lifetime of the extension.

    Original release occurrence · 16.0/changes/189

  • Allow postgres_fdw to do aborts in parallel Features

    Allow postgres_fdw to do aborts in parallel (Etsuro Fujita) §

    This is enabled with postgres_fdw option parallel_abort.

    Original release occurrence · 16.0/changes/190

  • Make ANALYZE on foreign postgres_fdw tables more efficient Features

    Make ANALYZE on foreign postgres_fdw tables more efficient (Tomas Vondra) §

    The postgres_fdw option analyze_sampling controls the sampling method.

    Original release occurrence · 16.0/changes/191

  • Restrict shipment of reg* type constants in postgres_fdw to those referencing built-in objects or extensions marked as shippable Features

    Restrict shipment of reg* type constants in postgres_fdw to those referencing built-in objects or extensions marked as shippable (Tom Lane) §

    Original release occurrence · 16.0/changes/192

  • Have postgres_fdw and dblink handle interrupts during connection establishment Features

    Have postgres_fdw and dblink handle interrupts during connection establishment (Andres Freund) §

    Original release occurrence · 16.0/changes/193

Security evidence

60 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.

CVE-2026-6638 · PostgreSQL REFRESH PUBLICATION allows SQL injection via table name CVSS 3.7

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.

Fixed in this branch: 16.14. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-6637 · PostgreSQL refint allows stack buffer overflow and SQL injection CVSS 8.8

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 16.14. Component: contrib module.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6479 · PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion CVSS 7.5

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 16.14. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2026-6478 · PostgreSQL discloses MD5-hashed passwords via covert timing channel CVSS 6.5

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 16.14. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-6477 · PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory CVSS 8.8

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 16.14. Component: client.

Official affected-branch entry: 16.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6475 · PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice CVSS 8.8

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 16.14. Component: client.

Official affected-branch entry: 16.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6474 · PostgreSQL timeofday() can disclose portions of server memory CVSS 4.3

Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 16.14. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-6473 · PostgreSQL server undersizes allocations, via integer wraparound CVSS 8.8

Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 16.14. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6472 · PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege CVSS 5.4

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 16.14. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-6471 · PostgreSQL logical decoding can dlopen arbitrary file CVSS 7.2

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6470 · PostgreSQL fails to check type USAGE privilege CVSS 4.3

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2026-6469 · PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership CVSS 3.8

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

Release-note mentions:

CVE-2026-6464 · PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands CVSS 8.1

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: client.

Official affected-branch entry: 16.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2006 · PostgreSQL missing validation of multibyte character length executes arbitrary code CVSS 8.8

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 16.12. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2005 · PostgreSQL pgcrypto heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 16.12. Component: contrib module.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2004 · PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code CVSS 8.8

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 16.12. Component: contrib module.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2003 · PostgreSQL oidvector discloses a few bytes of memory CVSS 4.3

Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 16.12. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-19385 · PostgreSQL pg_dump heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: client.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-18408 · PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client CVSS 8.8

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: client.

Official affected-branch entry: 16.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-18024 · PostgreSQL ascii() function reads past end of buffer CVSS 4.3

Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-16241 · PostgreSQL ECPG integer underflow can crash the client CVSS 3.8

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: client.

Official affected-branch entry: 16.

AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

Release-note mentions:

CVE-2026-16239 · PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-16238 · PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-15742 · PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: contrib module.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-15741 · PostgreSQL expression deparse allows SQL injection via EXTRACT argument CVSS 8.8

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14681 · PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL CVSS 4.2

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14680 · PostgreSQL type confusion via "internal" arguments CVSS 8.8

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14679 · PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory CVSS 8.2

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Release-note mentions:

CVE-2026-14678 · PostgreSQL pg_trgm picksplit reads past end of buffer CVSS 4.3

Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: contrib module.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-14677 · PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14676 · PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

No fixed version for this branch is recorded. Component: contrib module.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14673 · PostgreSQL amcheck does not clear untrusted search path CVSS 3.8

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

Fixed in this branch: 16.15. Component: contrib module.

Official affected-branch entry: 16.

AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14672 · PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle CVSS 5.3

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-14671 · PostgreSQL refint plan cache type confusion executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: contrib module.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14670 · PostgreSQL plperl tied object heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14669 · PostgreSQL to_char heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14668 · PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read CVSS 8.1

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Release-note mentions:

CVE-2026-14666 · PostgreSQL row security caching disregards role modifications CVSS 4.2

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14664 · PostgreSQL regexp heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14663 · PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext CVSS 6.5

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: contrib module.

Official affected-branch entry: 16.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14662 · PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 16.15. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8715 · PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server CVSS 8.8

Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.

Fixed in this branch: 16.10. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client CVSS 8.8

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

Fixed in this branch: 16.10. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8713 · PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table CVSS 3.1

PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

Fixed in this branch: 16.10. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2025-4207 · PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation CVSS 5.9

Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.

Fixed in this branch: 16.9. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound CVSS 5.9

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Fixed in this branch: 16.11. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege CVSS 3.1

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Fixed in this branch: 16.11. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2025-1094 · PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation CVSS 8.1

Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.

Fixed in this branch: 16.7. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-7348 · PostgreSQL relation replacement during pg_dump executes arbitrary SQL CVSS 8.8

Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected. The PostgreSQL project thanks Noah Misch for reporting this problem.

Fixed in this branch: 16.4. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-4317 · Restrict visibility of "pg_stats_ext" and "pg_stats_ext_exprs" entries to the table owner CVSS 3.1

Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an unprivileged database user to read most common values and other statistics from CREATE STATISTICS commands of other users. The most common values may reveal column values the eavesdropper could not otherwise read or results of functions they cannot execute. Installing an unaffected version only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after installing that version. Current PostgreSQL installations will remain vulnerable until they follow the instructions in the release notes, which are provided as a convenience in the below section. Within major versions 14-16, minor versions before PostgreSQL 16.3, 15.7, and 14.12 are affected. Versions before PostgreSQL 14 are unaffected. This fix only fixes fresh PostgreSQL installations, namely those that are created with the initdb utility after this fix is applied. If you have a current PostgreSQL installation and are concerned about this issue, please use the following remediation steps to fix the issue: From the above URLs, you can click the URL that says "raw" to download a version that you can copy and paste. Be sure to use the script appropriate to your PostgreSQL major version. If you do not see this file, either your version is not vulnerable (only PostgreSQL 14, 15, and 16 are affected) or your minor version is too old to have the fix. \i /usr/share/postgresql/fix-CVE-2024-4317.sql ALTER DATABASE template0 WITH ALLOW_CONNECTIONS true; After executing the fix-CVE-2024-4317.sql script in template0 and template1 , you should revoke the ability for template0 to accept connections. You can do this with the following command: ALTER DATABASE template0 WITH ALLOW_CONNECTIONS false; The PostgreSQL project thanks Lukas Fittl for reporting this problem.

Fixed in this branch: 16.3. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code CVSS 8.8

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.

Fixed in this branch: 16.5. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID CVSS 4.2

Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 16.5. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle CVSS 3.1

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 16.5. Component: client.

Official affected-branch entry: 16.

AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes CVSS 4.2

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

Fixed in this branch: 16.5. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2024-0985 · PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL CVSS 8.0

UPDATE (June 19, 2024) : Added v16 as impacted. Updated description to clarify the attack vector. Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted materialized views. The victim is a superuser or member of one of the attacker's roles. The attack requires luring the victim into running REFRESH MATERIALIZED VIEW CONCURRENTLY on the attacker's materialized view.

Fixed in this branch: 16.2. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-5870 · Role "pg_signal_backend" can signal certain superuser processes CVSS 2.2

Documentation says the pg_signal_backend role cannot signal "a backend owned by a superuser". On the contrary, it can signal background workers, including the logical replication launcher. It can signal autovacuum workers and the autovacuum launcher. Signaling autovacuum workers and those two launchers provides no meaningful exploit, so exploiting this vulnerability requires a non-core extension with a less-resilient background worker. For example, a non-core background worker that does not auto-restart would experience a denial of service with respect to that particular background worker. The PostgreSQL project thanks Hemanth Sandrana and Mahendrakar Srinivasarao for reporting this problem.

Fixed in this branch: 16.1. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2023-5869 · Buffer overrun from integer overflow in array modification CVSS 8.8

While modifying certain SQL array values, missing overflow checks let authenticated database users write arbitrary bytes to a memory area that facilitates arbitrary code execution. Missing overflow checks also let authenticated database users read a wide area of server memory. The CVE-2021-32027 fix covered some attacks of this description, but it missed others. The PostgreSQL project thanks Pedro Gallegos for reporting this problem.

Fixed in this branch: 16.1. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2023-5868 · Memory disclosure in aggregate function calls CVSS 4.3

Certain aggregate function calls receiving "unknown"-type arguments could disclose bytes of server memory from the end of the "unknown"-type value to the next zero byte. One typically gets an "unknown"-type value via a string literal having no type designation. We have not confirmed or ruled out viability of attacks that arrange for presence of notable, confidential information in disclosed bytes. The PostgreSQL project thanks Jingzhou Fu for reporting this problem.

Fixed in this branch: 16.1. Component: core server.

Official affected-branch entry: 16.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2012-0868 · Line breaks in object names can be exploited to execute arbitrary SQL when reloading a pg_dump file.

No fixed version for this branch is recorded.

Release-note mentions:

Export this branch as JSON · Compare any two indexed releases