↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Versions

PostgreSQL 17

Read the English manual

Supported · Recorded build 17.11 · 2026-08-13

First stable release
2024-09-26
Support end
2029-11-08
Indexed releases
12
Original release-note entries
727

Manuals & provenance

PostgreSQL 17 English manual · 1146 loaded pages.

Manual loaded 2026-09-27T00:10:47.078613.

Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.

Upgrade considerations

Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.

Compatibility notes for 17.0 · Changes from the initial release through 17.11

Original migration guidance for 17.0

A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 18.6 for general information on migrating to new major releases.

Version 17 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:

Release history

Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.

ReleaseDate / snapshot cutoffAll changesBug fixesMigration entriesCVE mentions
17.11 2026-08-13 10949031
17.10 2026-05-14 5824010
17.9 2026-02-26 6501
17.8 2026-02-12 522304
17.7 2025-11-13 653502
17.6 2025-08-14 712505
17.5 2025-05-08 612801
17.4 2025-02-20 3201
17.3 2025-02-13 713701
17.2 2024-11-21 8401
17.1 2024-11-14 412104
17.0 2024-09-26 1822170

Initial release changes

Original entries from 17.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.

182 of 182 original entries.

  • Change functions to use a safe search_path during maintenance operations Compatibility Migration

    Change functions to use a safe search_path during maintenance operations (Jeff Davis) § §

    This prevents maintenance operations (ANALYZE, CLUSTER, CREATE INDEX, CREATE MATERIALIZED VIEW, REFRESH MATERIALIZED VIEW, REINDEX, or VACUUM) from performing unsafe access. Functions used by expression indexes and materialized views that need to reference non-default schemas must specify a search path during function creation.

    Original release occurrence · 17.0/migration/001

  • Restrict ago to only appear at the end in interval values Compatibility Migration

    Restrict ago to only appear at the end in interval values (Joseph Koshakow) § §

    Also, prevent empty interval units from appearing multiple times.

    Original release occurrence · 17.0/migration/002

  • Remove server variable old_snapshot_threshold Compatibility Migration

    Remove server variable old_snapshot_threshold (Thomas Munro) §

    This variable allowed vacuum to remove rows that potentially could be still visible to running transactions, causing "snapshot too old" errors later if accessed. This feature might be re-added to PostgreSQL later if an improved implementation is found.

    Original release occurrence · 17.0/migration/003

  • Change SET SESSION AUTHORIZATION handling of the initial session user's superuser status Compatibility Migration

    Change SET SESSION AUTHORIZATION handling of the initial session user's superuser status (Joseph Koshakow) §

    The new behavior is based on the session user's superuser status at the time the SET SESSION AUTHORIZATION command is issued, rather than their superuser status at connection time.

    Original release occurrence · 17.0/migration/004

  • Remove feature which simulated per-database users Compatibility Migration

    Remove feature which simulated per-database users (Nathan Bossart) §

    The feature, db_user_namespace, was rarely used.

    Original release occurrence · 17.0/migration/005

  • Remove adminpack contrib extension Compatibility Migration

    Remove adminpack contrib extension (Daniel Gustafsson) §

    This was used by now end-of-life pgAdmin III.

    Original release occurrence · 17.0/migration/006

  • Remove wal_sync_method value fsync_writethrough on Windows Compatibility Migration

    Remove wal_sync_method value fsync_writethrough on Windows (Thomas Munro) §

    This value was the same as fsync on Windows.

    Original release occurrence · 17.0/migration/007

  • Change file boundary handling of two WAL file name functions Compatibility Migration

    Change file boundary handling of two WAL file name functions (Kyotaro Horiguchi, Andres Freund, Bruce Momjian) §

    The functions pg_walfile_name() and pg_walfile_name_offset() used to report the previous LSN segment number when the LSN was on a file segment boundary; it now returns the current LSN segment.

    Original release occurrence · 17.0/migration/008

  • Remove server variable trace_recovery_messages since it is no longer needed Compatibility Migration

    Remove server variable trace_recovery_messages since it is no longer needed (Bharath Rupireddy) §

    Original release occurrence · 17.0/migration/009

  • Remove information schema column element_types.domain_default Compatibility Migration

    Remove information schema column element_types.domain_default (Peter Eisentraut) §

    Original release occurrence · 17.0/migration/010

  • Change pgrowlocks lock mode output labels Compatibility Migration

    Change pgrowlocks lock mode output labels (Bruce Momjian) §

    Original release occurrence · 17.0/migration/011

  • Remove buffers_backend and buffers_backend_fsync from pg_stat_bgwriter Compatibility Migration

    Remove buffers_backend and buffers_backend_fsync from pg_stat_bgwriter (Bharath Rupireddy) §

    These fields are considered redundant to similar columns in pg_stat_io.

    Original release occurrence · 17.0/migration/012

  • Rename I/O block read/write timing statistics columns of pg_stat_statements Compatibility Migration

    Rename I/O block read/write timing statistics columns of pg_stat_statements (Nazir Bilal Yavuz) §

    This renames blk_read_time to shared_blk_read_time, and blk_write_time to shared_blk_write_time.

    Original release occurrence · 17.0/migration/013

  • Change pg_attribute.attstattarget and pg_statistic_ext.stxstattarget to represent the default statistics target as NULL Compatibility Migration

    Change pg_attribute.attstattarget and pg_statistic_ext.stxstattarget to represent the default statistics target as NULL (Peter Eisentraut) § §

    Original release occurrence · 17.0/migration/014

  • Rename pg_collation.colliculocale to colllocale and pg_database.daticulocale to datlocale Compatibility Migration

    Rename pg_collation.colliculocale to colllocale and pg_database.daticulocale to datlocale (Jeff Davis) §

    Original release occurrence · 17.0/migration/015

  • Rename pg_stat_progress_vacuum column max_dead_tuples to max_dead_tuple_bytes, rename num_dead_tuples to num_dead_item_ids, and add dead_tuple_bytes Compatibility Migration

    Rename pg_stat_progress_vacuum column max_dead_tuples to max_dead_tuple_bytes, rename num_dead_tuples to num_dead_item_ids, and add dead_tuple_bytes (Masahiko Sawada) § §

    Original release occurrence · 17.0/migration/016

  • Rename SLRU columns in system view pg_stat_slru Compatibility Migration

    Rename SLRU columns in system view pg_stat_slru (Alvaro Herrera) §

    The column names accepted by pg_stat_reset_slru() are also changed.

    Original release occurrence · 17.0/migration/017

  • Allow the optimizer to improve CTE plans by considering the statistics and sort order of columns referenced in earlier row output clauses Features

    Allow the optimizer to improve CTE plans by considering the statistics and sort order of columns referenced in earlier row output clauses (Jian Guo, Richard Guo, Tom Lane) § §

    Original release occurrence · 17.0/changes/001

  • Improve optimization of IS NOT NULL and IS NULL query restrictions Features

    Improve optimization of IS NOT NULL and IS NULL query restrictions (David Rowley, Richard Guo, Andy Fan) § §

    Remove IS NOT NULL restrictions from queries on NOT NULL columns and eliminate scans on NOT NULL columns if IS NULL is specified.

    Original release occurrence · 17.0/changes/002

  • Allow partition pruning on boolean columns on IS [NOT] UNKNOWN conditionals Features

    Allow partition pruning on boolean columns on IS [NOT] UNKNOWN conditionals (David Rowley) §

    Original release occurrence · 17.0/changes/003

  • Improve optimization of range values when using containment operators <@ and @> Features

    Improve optimization of range values when using containment operators <@ and @> (Kim Johan Andersson, Jian He) §

    Original release occurrence · 17.0/changes/004

  • Allow correlated IN subqueries to be transformed into joins Features

    Allow correlated IN subqueries to be transformed into joins (Andy Fan, Tom Lane) §

    Original release occurrence · 17.0/changes/005

  • Improve optimization of the LIMIT clause on partitioned tables, inheritance parents, and UNION ALL queries Features

    Improve optimization of the LIMIT clause on partitioned tables, inheritance parents, and UNION ALL queries (Andy Fan, David Rowley) §

    Original release occurrence · 17.0/changes/006

  • Allow query nodes to be run in parallel in more cases Features

    Allow query nodes to be run in parallel in more cases (Tom Lane) §

    Original release occurrence · 17.0/changes/007

  • Allow GROUP BY columns to be internally ordered to match ORDER BY Features

    Allow GROUP BY columns to be internally ordered to match ORDER BY (Andrei Lepikhov, Teodor Sigaev) §

    This can be disabled using server variable enable_group_by_reordering.

    Original release occurrence · 17.0/changes/008

  • Allow UNION (without ALL) to use MergeAppend Features

    Allow UNION (without ALL) to use MergeAppend (David Rowley) §

    Original release occurrence · 17.0/changes/009

  • Fix MergeAppend plans to more accurately compute the number of rows that need to be sorted Bug fixes

    Fix MergeAppend plans to more accurately compute the number of rows that need to be sorted (Alexander Kuzmenkov) §

    Original release occurrence · 17.0/changes/010

  • Allow GiST and SP-GiST indexes to be part of incremental sorts Features

    Allow GiST and SP-GiST indexes to be part of incremental sorts (Miroslav Bendik) §

    This is particularly useful for ORDER BY clauses where the first column has a GiST and SP-GiST index, and other columns do not.

    Original release occurrence · 17.0/changes/011

  • Add columns to pg_stats to report range-type histogram information Features

    Add columns to pg_stats to report range-type histogram information (Egor Rogov, Soumyadeep Chakraborty) §

    Original release occurrence · 17.0/changes/012

  • Allow btree indexes to more efficiently find a set of values, such as those supplied by IN clauses using constants Features

    Allow btree indexes to more efficiently find a set of values, such as those supplied by IN clauses using constants (Peter Geoghegan, Matthias van de Meent) §

    Original release occurrence · 17.0/changes/013

  • Allow BRIN indexes to be created using parallel workers Features

    Allow BRIN indexes to be created using parallel workers (Tomas Vondra, Matthias van de Meent) §

    Original release occurrence · 17.0/changes/014

  • Allow vacuum to more efficiently remove and freeze tuples Performance

    Allow vacuum to more efficiently remove and freeze tuples (Melanie Plageman, Heikki Linnakangas) §

    WAL traffic caused by vacuum is also more compact.

    Original release occurrence · 17.0/changes/015

  • Allow vacuum to more efficiently store tuple references Performance

    Allow vacuum to more efficiently store tuple references (Masahiko Sawada, John Naylor) § § § §

    Additionally, vacuum is no longer silently limited to one gigabyte of memory when maintenance_work_mem or autovacuum_work_mem are higher.

    Original release occurrence · 17.0/changes/016

  • Optimize vacuuming of relations with no indexes Performance

    Optimize vacuuming of relations with no indexes (Melanie Plageman) §

    Original release occurrence · 17.0/changes/017

  • Increase default vacuum_buffer_usage_limit to 2MB Performance

    Increase default vacuum_buffer_usage_limit to 2MB (Thomas Munro) §

    Original release occurrence · 17.0/changes/018

  • Improve performance when checking roles with many memberships Performance

    Improve performance when checking roles with many memberships (Nathan Bossart) §

    Original release occurrence · 17.0/changes/019

  • Improve performance of heavily-contended WAL writes Performance

    Improve performance of heavily-contended WAL writes (Bharath Rupireddy) §

    Original release occurrence · 17.0/changes/020

  • Improve performance when transferring large blocks of data to a client Performance

    Improve performance when transferring large blocks of data to a client (Melih Mutlu) §

    Original release occurrence · 17.0/changes/021

  • Allow the grouping of file system reads with the new system variable io_combine_limit Performance

    Allow the grouping of file system reads with the new system variable io_combine_limit (Thomas Munro, Andres Freund, Melanie Plageman, Nazir Bilal Yavuz) § § §

    Original release occurrence · 17.0/changes/022

  • Create system view pg_stat_checkpointer Features

    Create system view pg_stat_checkpointer (Bharath Rupireddy, Anton A. Melnikov, Alexander Korotkov) § § §

    Relevant columns have been removed from pg_stat_bgwriter and added to this new system view.

    Original release occurrence · 17.0/changes/023

  • Improve control over resetting statistics Features

    Improve control over resetting statistics (Atsushi Torikoshi, Bharath Rupireddy) § § §

    Allow pg_stat_reset_shared() (with no arguments) and pg_stat_reset_shared(NULL) to reset all shared statistics. Allow pg_stat_reset_shared('slru') and pg_stat_reset_slru() (with no arguments) to reset SLRU statistics, which was already possible with pg_stat_reset_slru(NULL).

    Original release occurrence · 17.0/changes/024

  • Add log messages related to WAL recovery from backups Features

    Add log messages related to WAL recovery from backups (Andres Freund) §

    Original release occurrence · 17.0/changes/025

  • Add log_connections log line for trust connections Features

    Add log_connections log line for trust connections (Jacob Champion) §

    Original release occurrence · 17.0/changes/026

  • Add log message to report walsender acquisition and release of replication slots Features

    Add log message to report walsender acquisition and release of replication slots (Bharath Rupireddy) §

    This is enabled by the server variable log_replication_commands.

    Original release occurrence · 17.0/changes/027

  • Add system view pg_wait_events that reports wait event types Features

    Add system view pg_wait_events that reports wait event types (Bertrand Drouvot) §

    This is useful for adding descriptions to wait events reported in pg_stat_activity.

    Original release occurrence · 17.0/changes/028

  • Add wait events for checkpoint delays Features

    Add wait events for checkpoint delays (Thomas Munro) §

    Original release occurrence · 17.0/changes/029

  • Allow vacuum to report the progress of index processing Features

    Allow vacuum to report the progress of index processing (Sami Imseih) §

    This appears in system view pg_stat_progress_vacuum columns indexes_total and indexes_processed.

    Original release occurrence · 17.0/changes/030

  • Allow granting the right to perform maintenance operations Features

    Allow granting the right to perform maintenance operations (Nathan Bossart) §

    The permission can be granted on a per-table basis using the MAINTAIN privilege and on a per-role basis via the pg_maintain predefined role. Permitted operations are VACUUM, ANALYZE, REINDEX, REFRESH MATERIALIZED VIEW, CLUSTER, and LOCK TABLE.

    Original release occurrence · 17.0/changes/031

  • Allow roles with pg_monitor membership to execute pg_current_logfile() Features

    Allow roles with pg_monitor membership to execute pg_current_logfile() (Pavlo Golub, Nathan Bossart) §

    Original release occurrence · 17.0/changes/032

  • Add system variable allow_alter_system to disallow ALTER SYSTEM Features

    Add system variable allow_alter_system to disallow ALTER SYSTEM (Jelte Fennema-Nio, Gabriele Bartolini) §

    Original release occurrence · 17.0/changes/033

  • Allow ALTER SYSTEM to set unrecognized custom server variables Features

    Allow ALTER SYSTEM to set unrecognized custom server variables (Tom Lane) §

    This is also possible with GRANT ON PARAMETER.

    Original release occurrence · 17.0/changes/034

  • Add server variable transaction_timeout to restrict the duration of transactions Features

    Add server variable transaction_timeout to restrict the duration of transactions (Andrey Borodin, Japin Li, Junwang Zhao, Alexander Korotkov) § § §

    Original release occurrence · 17.0/changes/035

  • Add a builtin platform-independent collation provider Features

    Add a builtin platform-independent collation provider (Jeff Davis) § § § §

    This supports C and C.UTF-8 collations.

    Original release occurrence · 17.0/changes/036

  • Add server variable huge_pages_status to report the use of huge pages by Postgres Features

    Add server variable huge_pages_status to report the use of huge pages by Postgres (Justin Pryzby) §

    This is useful when huge_pages is set to try.

    Original release occurrence · 17.0/changes/037

  • Add server variable to disable event triggers Features

    Add server variable to disable event triggers (Daniel Gustafsson) §

    The setting, event_triggers, allows for the temporary disabling of event triggers for debugging.

    Original release occurrence · 17.0/changes/038

  • Allow the SLRU cache sizes to be configured Features

    Allow the SLRU cache sizes to be configured (Andrey Borodin, Dilip Kumar, Alvaro Herrera) §

    The new server variables are commit_timestamp_buffers, multixact_member_buffers, multixact_offset_buffers, notify_buffers, serializable_buffers, subtransaction_buffers, and transaction_buffers. commit_timestamp_buffers, transaction_buffers, and subtransaction_buffers scale up automatically with shared_buffers.

    Original release occurrence · 17.0/changes/039

  • Add support for incremental file system backup Features

    Add support for incremental file system backup (Robert Haas, Jakub Wartak, Tomas Vondra) § §

    Incremental backups can be created using pg_basebackup's new --incremental option. The new application pg_combinebackup allows manipulation of base and incremental file system backups.

    Original release occurrence · 17.0/changes/040

  • Allow the creation of WAL summarization files Features

    Allow the creation of WAL summarization files (Robert Haas, Nathan Bossart, Hubert Depesz Lubaczewski) § § § §

    These files record the block numbers that have changed within an LSN range and are useful for incremental file system backups. This is controlled by the server variables summarize_wal and wal_summary_keep_time, and introspected with pg_available_wal_summaries(), pg_wal_summary_contents(), and pg_get_wal_summarizer_state().

    Original release occurrence · 17.0/changes/041

  • Add the system identifier to file system backup manifest files Features

    Add the system identifier to file system backup manifest files (Amul Sul) §

    This helps detect invalid WAL usage.

    Original release occurrence · 17.0/changes/042

  • Allow connection string value dbname to be written when pg_basebackup writes connection information to postgresql.auto.conf Features

    Allow connection string value dbname to be written when pg_basebackup writes connection information to postgresql.auto.conf (Vignesh C, Hayato Kuroda) §

    Original release occurrence · 17.0/changes/043

  • Add column pg_replication_slots.invalidation_reason to report the reason for invalid slots Features

    Add column pg_replication_slots.invalidation_reason to report the reason for invalid slots (Shveta Malik, Bharath Rupireddy) § §

    Original release occurrence · 17.0/changes/044

  • Add column pg_replication_slots.inactive_since to report slot inactivity duration Features

    Add column pg_replication_slots.inactive_since to report slot inactivity duration (Bharath Rupireddy) § § §

    Original release occurrence · 17.0/changes/045

  • Add function pg_sync_replication_slots() to synchronize logical replication slots Features

    Add function pg_sync_replication_slots() to synchronize logical replication slots (Hou Zhijie, Shveta Malik, Ajin Cherian, Peter Eisentraut) § §

    Original release occurrence · 17.0/changes/046

  • Add the failover property to the replication protocol Features

    Add the failover property to the replication protocol (Hou Zhijie, Shveta Malik) §

    Original release occurrence · 17.0/changes/047

  • Add application pg_createsubscriber to create a logical replica from a physical standby server Features

    Add application pg_createsubscriber to create a logical replica from a physical standby server (Euler Taveira) §

    Original release occurrence · 17.0/changes/048

  • Have pg_upgrade migrate valid logical slots and subscriptions Features

    Have pg_upgrade migrate valid logical slots and subscriptions (Hayato Kuroda, Hou Zhijie, Vignesh C, Julien Rouhaud, Shlok Kyal) § §

    This allows logical replication to continue quickly after the upgrade. This only works for old PostgreSQL clusters that are version 17 or later.

    Original release occurrence · 17.0/changes/049

  • Enable the failover of logical slots Features

    Enable the failover of logical slots (Hou Zhijie, Shveta Malik, Ajin Cherian) §

    This is controlled by an optional fifth argument to pg_create_logical_replication_slot().

    Original release occurrence · 17.0/changes/050

  • Add server variable sync_replication_slots to enable failover logical slot synchronization Features

    Add server variable sync_replication_slots to enable failover logical slot synchronization (Shveta Malik, Hou Zhijie, Peter Smith) § §

    Original release occurrence · 17.0/changes/051

  • Add logical replication failover control to CREATE/ALTER SUBSCRIPTION Features

    Add logical replication failover control to CREATE/ALTER SUBSCRIPTION (Shveta Malik, Hou Zhijie, Ajin Cherian) § §

    Original release occurrence · 17.0/changes/052

  • Allow the application of logical replication changes to use hash indexes on the subscriber Features

    Allow the application of logical replication changes to use hash indexes on the subscriber (Hayato Kuroda) §

    Previously only btree indexes could be used for this purpose.

    Original release occurrence · 17.0/changes/053

  • Improve logical decoding performance in cases where there are many subtransactions Performance

    Improve logical decoding performance in cases where there are many subtransactions (Masahiko Sawada) §

    Original release occurrence · 17.0/changes/054

  • Restart apply workers if subscription owner's superuser privileges are revoked Features

    Restart apply workers if subscription owner's superuser privileges are revoked (Vignesh C) §

    This forces reauthentication.

    Original release occurrence · 17.0/changes/055

  • Add flush option to pg_logical_emit_message() Features

    Add flush option to pg_logical_emit_message() (Michael Paquier) §

    This makes the message durable.

    Original release occurrence · 17.0/changes/056

  • Allow specification of physical standbys that must be synchronized before they are visible to subscribers Features

    Allow specification of physical standbys that must be synchronized before they are visible to subscribers (Hou Zhijie, Shveta Malik) § §

    The new server variable is synchronized_standby_slots.

    Original release occurrence · 17.0/changes/057

  • Add worker type column to pg_stat_subscription Features

    Add worker type column to pg_stat_subscription (Peter Smith) §

    Original release occurrence · 17.0/changes/058

  • Add new COPY option ON_ERROR ignore to discard error rows Features

    Add new COPY option ON_ERROR ignore to discard error rows (Damir Belyalov, Atsushi Torikoshi, Alex Shulgin, Jian He, Yugo Nagata) § § § §

    The default behavior is ON_ERROR stop.

    Original release occurrence · 17.0/changes/059

  • Add new COPY option LOG_VERBOSITY which reports COPY FROM ignored error rows Features

    Add new COPY option LOG_VERBOSITY which reports COPY FROM ignored error rows (Bharath Rupireddy) §

    Original release occurrence · 17.0/changes/060

  • Allow COPY FROM to report the number of skipped rows during processing Features

    Allow COPY FROM to report the number of skipped rows during processing (Atsushi Torikoshi) §

    This appears in system view column pg_stat_progress_copy.tuples_skipped.

    Original release occurrence · 17.0/changes/061

  • In COPY FROM, allow easy specification that all columns should be forced null or not null Features

    In COPY FROM, allow easy specification that all columns should be forced null or not null (Zhang Mingli) §

    Original release occurrence · 17.0/changes/062

  • Allow partitioned tables to have identity columns Features

    Allow partitioned tables to have identity columns (Ashutosh Bapat) §

    Original release occurrence · 17.0/changes/063

  • Allow exclusion constraints on partitioned tables Features

    Allow exclusion constraints on partitioned tables (Paul A. Jungwirth) §

    As long as exclusion constraints compare partition key columns for equality, other columns can use exclusion constraint-specific comparisons.

    Original release occurrence · 17.0/changes/064

  • Add clearer ALTER TABLE method to set a column to the default statistics target Features

    Add clearer ALTER TABLE method to set a column to the default statistics target (Peter Eisentraut) §

    The new syntax is ALTER TABLE ... SET STATISTICS DEFAULT; using SET STATISTICS -1 is still supported.

    Original release occurrence · 17.0/changes/065

  • Allow ALTER TABLE to change a column's generation expression Features

    Allow ALTER TABLE to change a column's generation expression (Amul Sul) §

    The syntax is ALTER TABLE ... ALTER COLUMN ... SET EXPRESSION.

    Original release occurrence · 17.0/changes/066

  • Allow specification of table access methods on partitioned tables Features

    Allow specification of table access methods on partitioned tables (Justin Pryzby, Soumyadeep Chakraborty, Michael Paquier) § §

    Original release occurrence · 17.0/changes/067

  • Add DEFAULT setting for ALTER TABLE .. SET ACCESS METHOD Features

    Add DEFAULT setting for ALTER TABLE .. SET ACCESS METHOD (Michael Paquier) §

    Original release occurrence · 17.0/changes/068

  • Add support for event triggers that fire at connection time Features

    Add support for event triggers that fire at connection time (Konstantin Knizhnik, Mikhail Gribkov) §

    Original release occurrence · 17.0/changes/069

  • Add event trigger support for REINDEX Features

    Add event trigger support for REINDEX (Garrett Thornburg, Jian He) §

    Original release occurrence · 17.0/changes/070

  • Allow parenthesized syntax for CLUSTER options if a table name is not specified Features

    Allow parenthesized syntax for CLUSTER options if a table name is not specified (Nathan Bossart) §

    Original release occurrence · 17.0/changes/071

  • Allow EXPLAIN to report optimizer memory usage Features

    Allow EXPLAIN to report optimizer memory usage (Ashutosh Bapat) §

    The option is called MEMORY.

    Original release occurrence · 17.0/changes/072

  • Add EXPLAIN option SERIALIZE to report the cost of converting data for network transmission Features

    Add EXPLAIN option SERIALIZE to report the cost of converting data for network transmission (Stepan Rutz, Matthias van de Meent) §

    Original release occurrence · 17.0/changes/073

  • Add local I/O block read/write timing statistics to EXPLAIN's BUFFERS output Features

    Add local I/O block read/write timing statistics to EXPLAIN's BUFFERS output (Nazir Bilal Yavuz) §

    Original release occurrence · 17.0/changes/074

  • Improve EXPLAIN's display of SubPlan nodes and output parameters Features

    Improve EXPLAIN's display of SubPlan nodes and output parameters (Tom Lane, Dean Rasheed) §

    Original release occurrence · 17.0/changes/075

  • Add JIT deform_counter details to EXPLAIN Features

    Add JIT deform_counter details to EXPLAIN (Dmitry Dolgov) §

    Original release occurrence · 17.0/changes/076

  • Allow the interval data type to support +/-infinity values Features

    Allow the interval data type to support +/-infinity values (Joseph Koshakow, Jian He, Ashutosh Bapat) §

    Original release occurrence · 17.0/changes/077

  • Allow the use of an ENUM added via ALTER TYPE if the type was created in the same transaction Features

    Allow the use of an ENUM added via ALTER TYPE if the type was created in the same transaction (Tom Lane) §

    This was previously disallowed.

    Original release occurrence · 17.0/changes/078

  • Allow MERGE to modify updatable views Features

    Allow MERGE to modify updatable views (Dean Rasheed) §

    Original release occurrence · 17.0/changes/079

  • Add WHEN NOT MATCHED BY SOURCE to MERGE Features

    Add WHEN NOT MATCHED BY SOURCE to MERGE (Dean Rasheed) §

    WHEN NOT MATCHED on target rows was already supported.

    Original release occurrence · 17.0/changes/080

  • Allow MERGE to use the RETURNING clause Features

    Allow MERGE to use the RETURNING clause (Dean Rasheed) §

    The new RETURNING function merge_action() reports on the DML that generated the row.

    Original release occurrence · 17.0/changes/081

  • Add function JSON_TABLE() to convert JSON data to a table representation Features

    Add function JSON_TABLE() to convert JSON data to a table representation (Nikita Glukhov, Teodor Sigaev, Oleg Bartunov, Alexander Korotkov, Andrew Dunstan, Amit Langote, Jian He) § §

    This function can be used in the FROM clause of SELECT queries as a tuple source.

    Original release occurrence · 17.0/changes/082

  • Add SQL/JSON constructor functions JSON(), JSON_SCALAR(), and JSON_SERIALIZE() Features

    Add SQL/JSON constructor functions JSON(), JSON_SCALAR(), and JSON_SERIALIZE() (Nikita Glukhov, Teodor Sigaev, Oleg Bartunov, Alexander Korotkov, Andrew Dunstan, Amit Langote) §

    Original release occurrence · 17.0/changes/083

  • Add SQL/JSON query functions JSON_EXISTS(), JSON_QUERY(), and JSON_VALUE() Features

    Add SQL/JSON query functions JSON_EXISTS(), JSON_QUERY(), and JSON_VALUE() (Nikita Glukhov, Teodor Sigaev, Oleg Bartunov, Alexander Korotkov, Andrew Dunstan, Amit Langote, Peter Eisentraut, Jian He) § § § § §

    Original release occurrence · 17.0/changes/084

  • Add jsonpath methods to convert JSON values to other JSON data types Features

    Add jsonpath methods to convert JSON values to other JSON data types (Jeevan Chalke) §

    The jsonpath methods are .bigint(), .boolean(), .date(), .decimal([precision [, scale]]), .integer(), .number(), .string(), .time(), .time_tz(), .timestamp(), and .timestamp_tz().

    Original release occurrence · 17.0/changes/085

  • Add to_timestamp() time zone format specifiers Features

    Add to_timestamp() time zone format specifiers (Tom Lane) §

    TZ accepts time zone abbreviations or numeric offsets, while OF accepts only numeric offsets.

    Original release occurrence · 17.0/changes/086

  • Allow the session time zone to be specified by AT LOCAL Features

    Allow the session time zone to be specified by AT LOCAL (Vik Fearing) §

    This is useful when converting adding and removing time zones from time stamps values, rather than specifying the literal session time zone.

    Original release occurrence · 17.0/changes/087

  • Add functions uuid_extract_timestamp() and uuid_extract_version() to return UUID information Features

    Add functions uuid_extract_timestamp() and uuid_extract_version() to return UUID information (Andrey Borodin) §

    Original release occurrence · 17.0/changes/088

  • Add functions to generate random numbers in a specified range Features

    Add functions to generate random numbers in a specified range (Dean Rasheed) §

    The functions are random(min, max) and they take values of type integer, bigint, and numeric.

    Original release occurrence · 17.0/changes/089

  • Add functions to convert integers to binary and octal strings Features

    Add functions to convert integers to binary and octal strings (Eric Radman, Nathan Bossart) §

    The functions are to_bin() and to_oct().

    Original release occurrence · 17.0/changes/090

  • Add Unicode informational functions Features

    Add Unicode informational functions (Jeff Davis) §

    Function unicode_version() returns the Unicode version, icu_unicode_version() returns the ICU version, and unicode_assigned() returns if the characters are assigned Unicode codepoints.

    Original release occurrence · 17.0/changes/091

  • Add function xmltext() to convert text to a single XML text node Features

    Add function xmltext() to convert text to a single XML text node (Jim Jones) §

    Original release occurrence · 17.0/changes/092

  • Add function to_regtypemod() to return the type modifier of a type specification Features

    Add function to_regtypemod() to return the type modifier of a type specification (David Wheeler, Erik Wienhold) §

    Original release occurrence · 17.0/changes/093

  • Add pg_basetype() function to return a domain's base type Features

    Add pg_basetype() function to return a domain's base type (Steve Chavez) §

    Original release occurrence · 17.0/changes/094

  • Add function pg_column_toast_chunk_id() to return a value's TOAST identifier Features

    Add function pg_column_toast_chunk_id() to return a value's TOAST identifier (Yugo Nagata) §

    This returns NULL if the value is not stored in TOAST.

    Original release occurrence · 17.0/changes/095

  • Allow plpgsql %TYPE and %ROWTYPE specifications to represent arrays of non-array types Features

    Allow plpgsql %TYPE and %ROWTYPE specifications to represent arrays of non-array types (Quan Zongliang, Pavel Stehule) §

    Original release occurrence · 17.0/changes/096

  • Allow plpgsql %TYPE specification to reference composite column Features

    Allow plpgsql %TYPE specification to reference composite column (Tom Lane) §

    Original release occurrence · 17.0/changes/097

  • Add libpq function to change role passwords Features

    Add libpq function to change role passwords (Joe Conway) §

    The new function, PQchangePassword(), hashes the new password before sending it to the server.

    Original release occurrence · 17.0/changes/098

  • Add libpq functions to close portals and prepared statements Features

    Add libpq functions to close portals and prepared statements (Jelte Fennema-Nio) §

    The functions are PQclosePrepared(), PQclosePortal(), PQsendClosePrepared(), and PQsendClosePortal().

    Original release occurrence · 17.0/changes/099

  • Add libpq API which allows for blocking and non-blocking cancel requests, with encryption if already in use Features

    Add libpq API which allows for blocking and non-blocking cancel requests, with encryption if already in use (Jelte Fennema-Nio) §

    Previously only blocking, unencrypted cancel requests were supported.

    Original release occurrence · 17.0/changes/100

  • Add libpq function PQsocketPoll() to allow polling of network sockets Features

    Add libpq function PQsocketPoll() to allow polling of network sockets (Tristan Partin, Tom Lane) § §

    Original release occurrence · 17.0/changes/101

  • Add libpq function PQsendPipelineSync() to send a pipeline synchronization point Features

    Add libpq function PQsendPipelineSync() to send a pipeline synchronization point (Anton Kirilov) §

    This is similar to PQpipelineSync() but it does not flush to the server unless the size threshold of the output buffer is reached.

    Original release occurrence · 17.0/changes/102

  • Add libpq function PQsetChunkedRowsMode() to allow retrieval of results in chunks Features

    Add libpq function PQsetChunkedRowsMode() to allow retrieval of results in chunks (Daniel Vérité) §

    Original release occurrence · 17.0/changes/103

  • Allow TLS connections without requiring a network round-trip negotiation Features

    Allow TLS connections without requiring a network round-trip negotiation (Greg Stark, Heikki Linnakangas, Peter Eisentraut, Michael Paquier, Daniel Gustafsson) § § § § § § § §

    This is enabled with the client-side option sslnegotiation=direct, requires ALPN, and only works on PostgreSQL 17 and later servers.

    Original release occurrence · 17.0/changes/104

  • Improve psql display of default and empty privileges Features

    Improve psql display of default and empty privileges (Erik Wienhold, Laurenz Albe) §

    Command \dp now displays (none) for empty privileges; default still displays as empty.

    Original release occurrence · 17.0/changes/105

  • Have backslash commands honor \pset null Features

    Have backslash commands honor \pset null (Erik Wienhold, Laurenz Albe) §

    Previously \pset null was ignored.

    Original release occurrence · 17.0/changes/106

  • Allow psql's \watch to stop after a minimum number of rows returned Features

    Allow psql's \watch to stop after a minimum number of rows returned (Greg Sabino Mullane) §

    The parameter is min_rows.

    Original release occurrence · 17.0/changes/107

  • Allow psql connection attempts to be canceled with control-C Features

    Allow psql connection attempts to be canceled with control-C (Tristan Partin) §

    Original release occurrence · 17.0/changes/108

  • Allow psql to honor FETCH_COUNT for non-SELECT queries Features

    Allow psql to honor FETCH_COUNT for non-SELECT queries (Daniel Vérité) §

    Original release occurrence · 17.0/changes/109

  • Improve psql tab completion Features

    Improve psql tab completion (Dagfinn Ilmari Mannsåker, Gilles Darold, Christoph Heiss, Steve Chavez, Vignesh C, Pavel Borisov, Jian He) § § § § § § § §

    Original release occurrence · 17.0/changes/110

  • Add application pg_walsummary to dump WAL summary files Features

    Add application pg_walsummary to dump WAL summary files (Robert Haas) §

    Original release occurrence · 17.0/changes/111

  • Allow pg_dump's large objects to be restorable in batches Features

    Allow pg_dump's large objects to be restorable in batches (Tom Lane) §

    This allows the restoration of many large objects to avoid transaction limits and to be restored in parallel.

    Original release occurrence · 17.0/changes/112

  • Add pg_dump option --exclude-extension Features

    Add pg_dump option --exclude-extension (Ayush Vatsa) §

    Original release occurrence · 17.0/changes/113

  • Allow pg_dump, pg_dumpall, and pg_restore to specify include/exclude objects in a file Features

    Allow pg_dump, pg_dumpall, and pg_restore to specify include/exclude objects in a file (Pavel Stehule, Daniel Gustafsson) §

    The option is called --filter.

    Original release occurrence · 17.0/changes/114

  • Add the --sync-method parameter to several client applications Features

    Add the --sync-method parameter to several client applications (Justin Pryzby, Nathan Bossart) §

    The applications are initdb, pg_basebackup, pg_checksums, pg_dump, pg_rewind, and pg_upgrade.

    Original release occurrence · 17.0/changes/115

  • Add pg_restore option --transaction-size to allow object restores in transaction batches Features

    Add pg_restore option --transaction-size to allow object restores in transaction batches (Tom Lane) §

    This allows the performance benefits of transaction batches without the problems of excessively large transaction blocks.

    Original release occurrence · 17.0/changes/116

  • Change pgbench debug mode option from -d to --debug Features

    Change pgbench debug mode option from -d to --debug (Greg Sabino Mullane) §

    Option -d is now used for the database name, and the new --dbname option can be used as well.

    Original release occurrence · 17.0/changes/117

  • Add pgbench option --exit-on-abort to exit after any client aborts Features

    Add pgbench option --exit-on-abort to exit after any client aborts (Yugo Nagata) §

    Original release occurrence · 17.0/changes/118

  • Add pgbench command \syncpipeline to allow sending of sync messages Features

    Add pgbench command \syncpipeline to allow sending of sync messages (Anthonin Bonnefoy) §

    Original release occurrence · 17.0/changes/119

  • Allow pg_archivecleanup to remove backup history files Features

    Allow pg_archivecleanup to remove backup history files (Atsushi Torikoshi) §

    The option is --clean-backup-history.

    Original release occurrence · 17.0/changes/120

  • Add some long options to pg_archivecleanup Features

    Add some long options to pg_archivecleanup (Atsushi Torikoshi) §

    The long options are --debug, --dry-run, and --strip-extension.

    Original release occurrence · 17.0/changes/121

  • Allow pg_basebackup and pg_receivewal to use dbname in their connection specification Features

    Allow pg_basebackup and pg_receivewal to use dbname in their connection specification (Jelte Fennema-Nio) §

    This is useful for connection poolers that are sensitive to the database name.

    Original release occurrence · 17.0/changes/122

  • Add pg_upgrade option --copy-file-range Features

    Add pg_upgrade option --copy-file-range (Thomas Munro) §

    This is supported on Linux and FreeBSD.

    Original release occurrence · 17.0/changes/123

  • Allow reindexdb --index to process indexes from different tables in parallel Features

    Allow reindexdb --index to process indexes from different tables in parallel (Maxim Orlov, Svetlana Derevyanko, Alexander Korotkov) §

    Original release occurrence · 17.0/changes/124

  • Allow reindexdb, vacuumdb, and clusterdb to process objects in all databases matching a pattern Features

    Allow reindexdb, vacuumdb, and clusterdb to process objects in all databases matching a pattern (Nathan Bossart) § § §

    The new option --all controls this behavior.

    Original release occurrence · 17.0/changes/125

  • Remove support for OpenSSL 1.0.1 Features

    Remove support for OpenSSL 1.0.1 (Michael Paquier) §

    Original release occurrence · 17.0/changes/126

  • Allow tests to pass in OpenSSL FIPS mode Features

    Allow tests to pass in OpenSSL FIPS mode (Peter Eisentraut) § §

    Original release occurrence · 17.0/changes/127

  • Use CPU AVX-512 instructions for bit counting Features

    Use CPU AVX-512 instructions for bit counting (Paul Amonson, Nathan Bossart, Ants Aasma) § §

    Original release occurrence · 17.0/changes/128

  • Require LLVM version 10 or later Features

    Require LLVM version 10 or later (Thomas Munro) §

    Original release occurrence · 17.0/changes/129

  • Use native CRC instructions on 64-bit LoongArch CPUs Features

    Use native CRC instructions on 64-bit LoongArch CPUs (Xudong Yang) §

    Original release occurrence · 17.0/changes/130

  • Remove AIX support Features

    Remove AIX support (Heikki Linnakangas) §

    Original release occurrence · 17.0/changes/131

  • Remove the Microsoft Visual Studio-specific PostgreSQL build option Features

    Remove the Microsoft Visual Studio-specific PostgreSQL build option (Michael Paquier) §

    Meson is now the only available method for Visual Studio builds.

    Original release occurrence · 17.0/changes/132

  • Remove configure option --disable-thread-safety Features

    Remove configure option --disable-thread-safety (Thomas Munro, Heikki Linnakangas) § §

    We now assume all supported platforms have sufficient thread support.

    Original release occurrence · 17.0/changes/133

  • Remove configure option --with-CC Features

    Remove configure option --with-CC (Heikki Linnakangas) §

    Setting the CC environment variable is now the only supported method for specifying the compiler.

    Original release occurrence · 17.0/changes/134

  • User-defined data type receive functions will no longer receive their data null-terminated Features

    User-defined data type receive functions will no longer receive their data null-terminated (David Rowley) §

    Original release occurrence · 17.0/changes/135

  • Add incremental JSON parser for use with huge JSON documents Features

    Add incremental JSON parser for use with huge JSON documents (Andrew Dunstan) §

    Original release occurrence · 17.0/changes/136

  • Convert top-level README file to Markdown Features

    Convert top-level README file to Markdown (Nathan Bossart) §

    Original release occurrence · 17.0/changes/137

  • Remove no longer needed top-level INSTALL file Features

    Remove no longer needed top-level INSTALL file (Tom Lane) §

    Original release occurrence · 17.0/changes/138

  • Remove make's distprep option Features

    Remove make's distprep option (Peter Eisentraut) §

    Original release occurrence · 17.0/changes/139

  • Add make support for Android shared libraries Features

    Add make support for Android shared libraries (Peter Eisentraut) §

    Original release occurrence · 17.0/changes/140

  • Add backend support for injection points Features

    Add backend support for injection points (Michael Paquier) § § § §

    This is used for server debugging and they must be enabled at server compile time.

    Original release occurrence · 17.0/changes/141

  • Add dynamic shared memory registry Features

    Add dynamic shared memory registry (Nathan Bossart) §

    This allows shared libraries which are not initialized at startup to coordinate dynamic shared memory access.

    Original release occurrence · 17.0/changes/142

  • Fix emit_log_hook to use the same time value as other log records for the same query Bug fixes

    Fix emit_log_hook to use the same time value as other log records for the same query (Kambam Vinay, Michael Paquier) §

    Original release occurrence · 17.0/changes/143

  • Improve documentation for using jsonpath for predicate checks Features

    Improve documentation for using jsonpath for predicate checks (David Wheeler) §

    Original release occurrence · 17.0/changes/144

  • Allow joins with non-join qualifications to be pushed down to foreign servers and custom scans Features

    Allow joins with non-join qualifications to be pushed down to foreign servers and custom scans (Richard Guo, Etsuro Fujita) §

    Foreign data wrappers and custom scans will need to be modified to handle these cases.

    Original release occurrence · 17.0/changes/145

  • Allow pushdown of EXISTS and IN subqueries to postgres_fdw foreign servers Features

    Allow pushdown of EXISTS and IN subqueries to postgres_fdw foreign servers (Alexander Pyhalov) §

    Original release occurrence · 17.0/changes/146

  • Increase the default foreign data wrapper tuple cost Features

    Increase the default foreign data wrapper tuple cost (David Rowley, Umair Shahid) § §

    This value is used by the optimizer.

    Original release occurrence · 17.0/changes/147

  • Allow dblink database operations to be interrupted Features

    Allow dblink database operations to be interrupted (Noah Misch) §

    Original release occurrence · 17.0/changes/148

  • Allow the creation of hash indexes on ltree columns Features

    Allow the creation of hash indexes on ltree columns (Tommy Pavlicek) §

    This also enables hash join and hash aggregation on ltree columns.

    Original release occurrence · 17.0/changes/149

  • Allow unaccent character translation rules to contain whitespace and quotes Features

    Allow unaccent character translation rules to contain whitespace and quotes (Michael Paquier) §

    The syntax for the unaccent.rules file has changed.

    Original release occurrence · 17.0/changes/150

  • Allow amcheck to check for unique constraint violations using new option --checkunique Features

    Allow amcheck to check for unique constraint violations using new option --checkunique (Anastasia Lubennikova, Pavel Borisov, Maxim Orlov) §

    Original release occurrence · 17.0/changes/151

  • Allow citext tests to pass in OpenSSL FIPS mode Features

    Allow citext tests to pass in OpenSSL FIPS mode (Peter Eisentraut) §

    Original release occurrence · 17.0/changes/152

  • Allow pgcrypto tests to pass in OpenSSL FIPS mode Features

    Allow pgcrypto tests to pass in OpenSSL FIPS mode (Peter Eisentraut) §

    Original release occurrence · 17.0/changes/153

  • Remove some unused SPI macros Features

    Remove some unused SPI macros (Bharath Rupireddy) §

    Original release occurrence · 17.0/changes/154

  • Allow ALTER OPERATOR to set more optimization attributes Features

    Allow ALTER OPERATOR to set more optimization attributes (Tommy Pavlicek) §

    This is useful for extensions.

    Original release occurrence · 17.0/changes/155

  • Allow extensions to define custom wait events Features

    Allow extensions to define custom wait events (Masahiro Ikeda) § § § §

    Custom wait events have been added to postgres_fdw and dblink.

    Original release occurrence · 17.0/changes/156

  • Add pg_buffercache function pg_buffercache_evict() to allow shared buffer eviction Features

    Add pg_buffercache function pg_buffercache_evict() to allow shared buffer eviction (Palak Chaturvedi, Thomas Munro) §

    This is useful for testing.

    Original release occurrence · 17.0/changes/157

  • Replace CALL parameters in pg_stat_statements with placeholders Features

    Replace CALL parameters in pg_stat_statements with placeholders (Sami Imseih) §

    Original release occurrence · 17.0/changes/158

  • Replace savepoint names stored in pg_stat_statements with placeholders Features

    Replace savepoint names stored in pg_stat_statements with placeholders (Greg Sabino Mullane) §

    This greatly reduces the number of entries needed to record SAVEPOINT, RELEASE SAVEPOINT, and ROLLBACK TO SAVEPOINT commands.

    Original release occurrence · 17.0/changes/159

  • Replace the two-phase commit GIDs stored in pg_stat_statements with placeholders Features

    Replace the two-phase commit GIDs stored in pg_stat_statements with placeholders (Michael Paquier) §

    This greatly reduces the number of entries needed to record PREPARE TRANSACTION, COMMIT PREPARED, and ROLLBACK PREPARED.

    Original release occurrence · 17.0/changes/160

  • Track DEALLOCATE in pg_stat_statements Features

    Track DEALLOCATE in pg_stat_statements (Dagfinn Ilmari Mannsåker, Michael Paquier) §

    DEALLOCATE names are stored in pg_stat_statements as placeholders.

    Original release occurrence · 17.0/changes/161

  • Add local I/O block read/write timing statistics columns of pg_stat_statements Features

    Add local I/O block read/write timing statistics columns of pg_stat_statements (Nazir Bilal Yavuz) § §

    The new columns are local_blk_read_time and local_blk_write_time.

    Original release occurrence · 17.0/changes/162

  • Add JIT deform_counter details to pg_stat_statements Features

    Add JIT deform_counter details to pg_stat_statements (Dmitry Dolgov) §

    Original release occurrence · 17.0/changes/163

  • Add optional fourth argument (minmax_only) to pg_stat_statements_reset() to allow for the resetting of only min/max statistics Features

    Add optional fourth argument (minmax_only) to pg_stat_statements_reset() to allow for the resetting of only min/max statistics (Andrei Zubkov) §

    This argument defaults to false.

    Original release occurrence · 17.0/changes/164

  • Add pg_stat_statements columns stats_since and minmax_stats_since to track entry creation time and last min/max reset time Features

    Add pg_stat_statements columns stats_since and minmax_stats_since to track entry creation time and last min/max reset time (Andrei Zubkov) §

    Original release occurrence · 17.0/changes/165

Security evidence

55 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.

CVE-2026-6638 · PostgreSQL REFRESH PUBLICATION allows SQL injection via table name CVSS 3.7

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.

Fixed in this branch: 17.10. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-6637 · PostgreSQL refint allows stack buffer overflow and SQL injection CVSS 8.8

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 17.10. Component: contrib module.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6479 · PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion CVSS 7.5

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 17.10. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2026-6478 · PostgreSQL discloses MD5-hashed passwords via covert timing channel CVSS 6.5

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 17.10. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-6477 · PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory CVSS 8.8

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 17.10. Component: client.

Official affected-branch entry: 17.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6476 · PostgreSQL pg_createsubscriber allows SQL injection via subscription name CVSS 7.2

SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_createsubscriber next runs. Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected. Versions before PostgreSQL 17 are unaffected.

Fixed in this branch: 17.10. Component: client.

Official affected-branch entry: 17.

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6475 · PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice CVSS 8.8

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 17.10. Component: client.

Official affected-branch entry: 17.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6474 · PostgreSQL timeofday() can disclose portions of server memory CVSS 4.3

Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 17.10. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-6473 · PostgreSQL server undersizes allocations, via integer wraparound CVSS 8.8

Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 17.10. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6472 · PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege CVSS 5.4

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 17.10. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-6471 · PostgreSQL logical decoding can dlopen arbitrary file CVSS 7.2

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6470 · PostgreSQL fails to check type USAGE privilege CVSS 4.3

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2026-6469 · PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership CVSS 3.8

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

Release-note mentions:

CVE-2026-6464 · PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands CVSS 8.1

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: client.

Official affected-branch entry: 17.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2006 · PostgreSQL missing validation of multibyte character length executes arbitrary code CVSS 8.8

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 17.8. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2005 · PostgreSQL pgcrypto heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 17.8. Component: contrib module.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2004 · PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code CVSS 8.8

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 17.8. Component: contrib module.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2003 · PostgreSQL oidvector discloses a few bytes of memory CVSS 4.3

Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 17.8. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-19385 · PostgreSQL pg_dump heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: client.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-18408 · PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client CVSS 8.8

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: client.

Official affected-branch entry: 17.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-18024 · PostgreSQL ascii() function reads past end of buffer CVSS 4.3

Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-16241 · PostgreSQL ECPG integer underflow can crash the client CVSS 3.8

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: client.

Official affected-branch entry: 17.

AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

Release-note mentions:

CVE-2026-16239 · PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-16238 · PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-15742 · PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: contrib module.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-15741 · PostgreSQL expression deparse allows SQL injection via EXTRACT argument CVSS 8.8

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14681 · PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL CVSS 4.2

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14680 · PostgreSQL type confusion via "internal" arguments CVSS 8.8

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14679 · PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory CVSS 8.2

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Release-note mentions:

CVE-2026-14678 · PostgreSQL pg_trgm picksplit reads past end of buffer CVSS 4.3

Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: contrib module.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-14677 · PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14676 · PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

No fixed version for this branch is recorded. Component: contrib module.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14673 · PostgreSQL amcheck does not clear untrusted search path CVSS 3.8

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

No fixed version for this branch is recorded. Component: contrib module.

AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14672 · PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle CVSS 5.3

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-14671 · PostgreSQL refint plan cache type confusion executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: contrib module.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14670 · PostgreSQL plperl tied object heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14669 · PostgreSQL to_char heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14668 · PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read CVSS 8.1

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Release-note mentions:

CVE-2026-14666 · PostgreSQL row security caching disregards role modifications CVSS 4.2

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14664 · PostgreSQL regexp heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14663 · PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext CVSS 6.5

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: contrib module.

Official affected-branch entry: 17.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14662 · PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 17.11. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8715 · PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server CVSS 8.8

Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.

Fixed in this branch: 17.6. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client CVSS 8.8

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

Fixed in this branch: 17.6. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8713 · PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table CVSS 3.1

PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

Fixed in this branch: 17.6. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2025-4207 · PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation CVSS 5.9

Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.

Fixed in this branch: 17.5. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound CVSS 5.9

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Fixed in this branch: 17.7. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege CVSS 3.1

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Fixed in this branch: 17.7. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2025-1094 · PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation CVSS 8.1

Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.

Fixed in this branch: 17.3. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code CVSS 8.8

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.

Fixed in this branch: 17.1. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID CVSS 4.2

Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.

Fixed in this branch: 17.1. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle CVSS 3.1

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.

Fixed in this branch: 17.1. Component: client.

Official affected-branch entry: 17.

AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Release-note mentions:

CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes CVSS 4.2

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

Fixed in this branch: 17.1. Component: core server.

Official affected-branch entry: 17.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2017-7484 · selectivity estimators bypass SELECT privilege checks CVSS 4.3

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2012-0868 · Line breaks in object names can be exploited to execute arbitrary SQL when reloading a pg_dump file.

No fixed version for this branch is recorded.

Release-note mentions:

Export this branch as JSON · Compare any two indexed releases