↑↓ select ↵ open ⌫ change scope Open full search

PG.CENTER connects PostgreSQL documentation, reference, and ecosystem knowledge. Maintained by Pigsty.

Wiki / Versions

PostgreSQL 18

Read the English manual

Current stable · Recorded build 18.6 · 2026-08-13

First stable release
2025-09-25
Support end
2030-11-14
Indexed releases
6
Original release-note entries
561

Manuals & provenance

PostgreSQL 18 English manual · 1151 loaded pages.

Manual loaded 2026-09-27T00:10:47.078613.

Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.

Upgrade considerations

Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.

Compatibility notes for 18.0 · Changes from the initial release through 18.6

Original migration guidance for 18.0

A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 18.6 for general information on migrating to new major releases.

Version 18 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:

Release history

Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.

ReleaseDate / snapshot cutoffAll changesBug fixesMigration entriesCVE mentions
18.6 2026-08-13 14065031
18.4 2026-05-14 7434011
18.3 2026-02-26 9602
18.2 2026-02-12 753705
18.1 2025-11-13 532802
18.0 2025-09-25 2101110

Initial release changes

Original entries from 18.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.

210 of 210 original entries.

  • Change initdb default to enable data checksums Compatibility Migration

    Change initdb default to enable data checksums (Greg Sabino Mullane) §

    Checksums can be disabled with the new initdb option --no-data-checksums. pg_upgrade requires matching cluster checksum settings, so this new option can be useful to upgrade non-checksum old clusters.

    Original release occurrence · 18.0/migration/001

  • Change time zone abbreviation handling Compatibility Migration

    Change time zone abbreviation handling (Tom Lane) §

    The system will now favor the current session's time zone abbreviations before checking the server variable timezone_abbreviations. Previously timezone_abbreviations was checked first.

    Original release occurrence · 18.0/migration/002

  • Deprecate MD5 password authentication Compatibility Migration

    Deprecate MD5 password authentication (Nathan Bossart) §

    Support for MD5 passwords will be removed in a future major version release. CREATE ROLE and ALTER ROLE now emit deprecation warnings when setting MD5 passwords. These warnings can be disabled by setting the md5_password_warnings parameter to off.

    Original release occurrence · 18.0/migration/003

  • Change VACUUM and ANALYZE to process the inheritance children of a parent Compatibility Migration

    Change VACUUM and ANALYZE to process the inheritance children of a parent (Michael Harris) §

    The previous behavior can be performed by using the new ONLY option.

    Original release occurrence · 18.0/migration/004

  • Prevent COPY FROM from treating \. as an end-of-file marker when reading CSV files Compatibility Migration

    Prevent COPY FROM from treating \. as an end-of-file marker when reading CSV files (Daniel Vérité, Tom Lane) § §

    psql will still treat \. as an end-of-file marker when reading CSV files from STDIN. Older psql clients connecting to PostgreSQL 18 servers might experience \copy problems. This release also enforces that \. must appear alone on a line.

    Original release occurrence · 18.0/migration/005

  • Disallow unlogged partitioned tables Compatibility Migration

    Disallow unlogged partitioned tables (Michael Paquier) §

    Previously ALTER TABLE SET [UN]LOGGED did nothing, and the creation of an unlogged partitioned table did not cause its children to be unlogged.

    Original release occurrence · 18.0/migration/006

  • Execute AFTER triggers as the role that was active when trigger events were queued Compatibility Migration

    Execute AFTER triggers as the role that was active when trigger events were queued (Laurenz Albe) §

    Previously such triggers were run as the role that was active at trigger execution time (e.g., at COMMIT). This is significant for cases where the role is changed between queue time and transaction commit.

    Original release occurrence · 18.0/migration/007

  • Remove non-functional support for rule privileges in GRANT/REVOKE Compatibility Migration

    Remove non-functional support for rule privileges in GRANT/REVOKE (Fujii Masao) §

    These have been non-functional since PostgreSQL 8.2.

    Original release occurrence · 18.0/migration/008

  • Remove column pg_backend_memory_contexts.parent Compatibility Migration

    Remove column pg_backend_memory_contexts.parent (Melih Mutlu) §

    This is no longer needed since pg_backend_memory_contexts.path was added.

    Original release occurrence · 18.0/migration/009

  • Change pg_backend_memory_contexts.level and pg_log_backend_memory_contexts() to be one-based Compatibility Migration

    Change pg_backend_memory_contexts.level and pg_log_backend_memory_contexts() to be one-based (Melih Mutlu, Atsushi Torikoshi, David Rowley, Fujii Masao) § § §

    These were previously zero-based.

    Original release occurrence · 18.0/migration/010

  • Change full text search to use the default collation provider of the cluster to read configuration files and dictionaries, rather than always using libc Compatibility Migration

    Change full text search to use the default collation provider of the cluster to read configuration files and dictionaries, rather than always using libc (Peter Eisentraut) §

    Clusters that default to non-libc collation providers (e.g., ICU, builtin) that behave differently than libc for characters processed by LC_CTYPE could observe changes in behavior of some full-text search functions, as well as the pg_trgm extension. When upgrading such clusters using pg_upgrade, it is recommended to reindex all indexes related to full-text search and pg_trgm after the upgrade.

    Original release occurrence · 18.0/migration/011

  • Automatically remove some unnecessary table self-joins Features

    Automatically remove some unnecessary table self-joins (Andrey Lepikhov, Alexander Kuzmenkov, Alexander Korotkov, Alena Rybakina) §

    This optimization can be disabled using server variable enable_self_join_elimination.

    Original release occurrence · 18.0/changes/001

  • Convert some IN (VALUES ...) to x = ANY ... for better optimizer statistics Features

    Convert some IN (VALUES ...) to x = ANY ... for better optimizer statistics (Alena Rybakina, Andrei Lepikhov) §

    Original release occurrence · 18.0/changes/002

  • Allow transforming OR-clauses to arrays for faster index processing Performance

    Allow transforming OR-clauses to arrays for faster index processing (Alexander Korotkov, Andrey Lepikhov) §

    Original release occurrence · 18.0/changes/003

  • Speed up the processing of INTERSECT, EXCEPT, window aggregates, and view column aliases Performance

    Speed up the processing of INTERSECT, EXCEPT, window aggregates, and view column aliases (Tom Lane, David Rowley) § § § §

    Original release occurrence · 18.0/changes/004

  • Allow the keys of SELECT DISTINCT to be internally reordered to avoid sorting Features

    Allow the keys of SELECT DISTINCT to be internally reordered to avoid sorting (Richard Guo) §

    This optimization can be disabled using enable_distinct_reordering.

    Original release occurrence · 18.0/changes/005

  • Ignore GROUP BY columns that are functionally dependent on other columns Features

    Ignore GROUP BY columns that are functionally dependent on other columns (Zhang Mingli, Jian He, David Rowley) §

    If a GROUP BY clause includes all columns of a unique index, as well as other columns of the same table, those other columns are redundant and can be dropped from the grouping. This was already true for non-deferred primary keys.

    Original release occurrence · 18.0/changes/006

  • Allow some HAVING clauses on GROUPING SETS to be pushed to WHERE clauses Features

    Allow some HAVING clauses on GROUPING SETS to be pushed to WHERE clauses (Richard Guo) § § § §

    This allows earlier row filtering. This release also fixes some GROUPING SETS queries that used to return incorrect results.

    Original release occurrence · 18.0/changes/007

  • Improve row estimates for generate_series() using numeric and timestamp values Features

    Improve row estimates for generate_series() using numeric and timestamp values (David Rowley, Song Jinzhou) § §

    Original release occurrence · 18.0/changes/008

  • Allow the optimizer to use Right Semi Join plans Features

    Allow the optimizer to use Right Semi Join plans (Richard Guo) §

    Semi-joins are used when needing to find if there is at least one match.

    Original release occurrence · 18.0/changes/009

  • Allow merge joins to use incremental sorts Features

    Allow merge joins to use incremental sorts (Richard Guo) §

    Original release occurrence · 18.0/changes/010

  • Improve the efficiency of planning queries accessing many partitions Features

    Improve the efficiency of planning queries accessing many partitions (Ashutosh Bapat, Yuya Watari, David Rowley) § §

    Original release occurrence · 18.0/changes/011

  • Allow partitionwise joins in more cases, and reduce its memory usage Features

    Allow partitionwise joins in more cases, and reduce its memory usage (Richard Guo, Tom Lane, Ashutosh Bapat) § §

    Original release occurrence · 18.0/changes/012

  • Improve cost estimates of partition queries Features

    Improve cost estimates of partition queries (Nikita Malakhov, Andrei Lepikhov) §

    Original release occurrence · 18.0/changes/013

  • Improve SQL-language function plan caching Features

    Improve SQL-language function plan caching (Alexander Pyhalov, Tom Lane) § §

    Original release occurrence · 18.0/changes/014

  • Improve handling of disabled optimizer features Features

    Improve handling of disabled optimizer features (Robert Haas) §

    Original release occurrence · 18.0/changes/015

  • Allow skip scans of btree indexes Features

    Allow skip scans of btree indexes (Peter Geoghegan) § §

    This allows multi-column btree indexes to be used in more cases such as when there are no restrictions on the first or early indexed columns (or there are non-equality ones), and there are useful restrictions on later indexed columns.

    Original release occurrence · 18.0/changes/016

  • Allow non-btree unique indexes to be used as partition keys and in materialized views Features

    Allow non-btree unique indexes to be used as partition keys and in materialized views (Mark Dilger) § §

    The index type must still support equality.

    Original release occurrence · 18.0/changes/017

  • Allow GIN indexes to be created in parallel Features

    Allow GIN indexes to be created in parallel (Tomas Vondra, Matthias van de Meent) §

    Original release occurrence · 18.0/changes/018

  • Allow values to be sorted to speed range-type GiST and btree index builds Features

    Allow values to be sorted to speed range-type GiST and btree index builds (Bernd Helmle) §

    Original release occurrence · 18.0/changes/019

  • Add an asynchronous I/O subsystem Performance

    Add an asynchronous I/O subsystem (Andres Freund, Thomas Munro, Nazir Bilal Yavuz, Melanie Plageman) § § § § § § § § § § §

    This feature allows backends to queue multiple read requests, which allows for more efficient sequential scans, bitmap heap scans, vacuums, etc. This is enabled by server variable io_method, with server variables io_combine_limit and io_max_combine_limit added to control it. This also enables effective_io_concurrency and maintenance_io_concurrency values greater than zero for systems without fadvise() support. The new system view pg_aios shows the file handles being used for asynchronous I/O.

    Original release occurrence · 18.0/changes/020

  • Improve the locking performance of queries that access many relations Performance

    Improve the locking performance of queries that access many relations (Tomas Vondra) §

    Original release occurrence · 18.0/changes/021

  • Improve the performance and reduce memory usage of hash joins and GROUP BY Performance

    Improve the performance and reduce memory usage of hash joins and GROUP BY (David Rowley, Jeff Davis) § § § § §

    This also improves hash set operations used by EXCEPT, and hash lookups of subplan values.

    Original release occurrence · 18.0/changes/022

  • Allow normal vacuums to freeze some pages, even though they are all-visible Performance

    Allow normal vacuums to freeze some pages, even though they are all-visible (Melanie Plageman) § §

    This reduces the overhead of later full-relation freezing. The aggressiveness of this can be controlled by server variable and per-table setting vacuum_max_eager_freeze_failure_rate. Previously vacuum never processed all-visible pages until freezing was required.

    Original release occurrence · 18.0/changes/023

  • Add server variable vacuum_truncate to control file truncation during VACUUM Performance

    Add server variable vacuum_truncate to control file truncation during VACUUM (Nathan Bossart, Gurjeet Singh) §

    A storage-level parameter with the same name and behavior already existed.

    Original release occurrence · 18.0/changes/024

  • Increase server variables effective_io_concurrency's and maintenance_io_concurrency's default values to 16 Performance

    Increase server variables effective_io_concurrency's and maintenance_io_concurrency's default values to 16 (Melanie Plageman) § §

    This more accurately reflects modern hardware.

    Original release occurrence · 18.0/changes/025

  • Increase the logging granularity of server variable log_connections Features

    Increase the logging granularity of server variable log_connections (Melanie Plageman) §

    This server variable was previously only boolean, which is still supported.

    Original release occurrence · 18.0/changes/026

  • Add log_connections option to report the duration of connection stages Features

    Add log_connections option to report the duration of connection stages (Melanie Plageman) §

    Original release occurrence · 18.0/changes/027

  • Add log_line_prefix escape %L to output the client IP address Features

    Add log_line_prefix escape %L to output the client IP address (Greg Sabino Mullane) §

    Original release occurrence · 18.0/changes/028

  • Add server variable log_lock_failures to log lock acquisition failures Features

    Add server variable log_lock_failures to log lock acquisition failures (Yuki Seino, Fujii Masao) § §

    Specifically it reports SELECT ... NOWAIT lock failures.

    Original release occurrence · 18.0/changes/029

  • Modify pg_stat_all_tables and its variants to report the time spent in VACUUM, ANALYZE, and their automatic variants Features

    Modify pg_stat_all_tables and its variants to report the time spent in VACUUM, ANALYZE, and their automatic variants (Sami Imseih) §

    The new columns are total_vacuum_time, total_autovacuum_time, total_analyze_time, and total_autoanalyze_time.

    Original release occurrence · 18.0/changes/030

  • Add delay time reporting to VACUUM and ANALYZE Features

    Add delay time reporting to VACUUM and ANALYZE (Bertrand Drouvot, Nathan Bossart) § §

    This information appears in the server log, the system views pg_stat_progress_vacuum and pg_stat_progress_analyze, and the output of VACUUM and ANALYZE when in VERBOSE mode; tracking must be enabled with the server variable track_cost_delay_timing.

    Original release occurrence · 18.0/changes/031

  • Add WAL, CPU, and average read statistics output to ANALYZE VERBOSE Features

    Add WAL, CPU, and average read statistics output to ANALYZE VERBOSE (Anthonin Bonnefoy) § §

    Original release occurrence · 18.0/changes/032

  • Add full WAL buffer count to VACUUM/ANALYZE (VERBOSE) and autovacuum log output Features

    Add full WAL buffer count to VACUUM/ANALYZE (VERBOSE) and autovacuum log output (Bertrand Drouvot) §

    Original release occurrence · 18.0/changes/033

  • Add per-backend I/O statistics reporting Features

    Add per-backend I/O statistics reporting (Bertrand Drouvot) § §

    The statistics are accessed via pg_stat_get_backend_io(). Per-backend I/O statistics can be cleared via pg_stat_reset_backend_stats().

    Original release occurrence · 18.0/changes/034

  • Add pg_stat_io columns to report I/O activity in bytes Features

    Add pg_stat_io columns to report I/O activity in bytes (Nazir Bilal Yavuz) §

    The new columns are read_bytes, write_bytes, and extend_bytes. The op_bytes column, which always equaled BLCKSZ, has been removed.

    Original release occurrence · 18.0/changes/035

  • Add WAL I/O activity rows to pg_stat_io Features

    Add WAL I/O activity rows to pg_stat_io (Nazir Bilal Yavuz, Bertrand Drouvot, Michael Paquier) § § §

    This includes WAL receiver activity and a wait event for such writes.

    Original release occurrence · 18.0/changes/036

  • Change server variable track_wal_io_timing to control tracking WAL timing in pg_stat_io instead of pg_stat_wal Features

    Change server variable track_wal_io_timing to control tracking WAL timing in pg_stat_io instead of pg_stat_wal (Bertrand Drouvot) §

    Original release occurrence · 18.0/changes/037

  • Remove read/sync columns from pg_stat_wal Features

    Remove read/sync columns from pg_stat_wal (Bertrand Drouvot) § §

    This removes columns wal_write, wal_sync, wal_write_time, and wal_sync_time.

    Original release occurrence · 18.0/changes/038

  • Add function pg_stat_get_backend_wal() to return per-backend WAL statistics Features

    Add function pg_stat_get_backend_wal() to return per-backend WAL statistics (Bertrand Drouvot) §

    Per-backend WAL statistics can be cleared via pg_stat_reset_backend_stats().

    Original release occurrence · 18.0/changes/039

  • Add function pg_ls_summariesdir() to specifically list the contents of PGDATA/pg_wal/summaries Features

    Add function pg_ls_summariesdir() to specifically list the contents of PGDATA/pg_wal/summaries (Yushi Ogiwara) §

    Original release occurrence · 18.0/changes/040

  • Add column pg_stat_checkpointer.num_done to report the number of completed checkpoints Features

    Add column pg_stat_checkpointer.num_done to report the number of completed checkpoints (Anton A. Melnikov) §

    Columns num_timed and num_requested count both completed and skipped checkpoints.

    Original release occurrence · 18.0/changes/041

  • Add column pg_stat_checkpointer.slru_written to report SLRU buffers written Features

    Add column pg_stat_checkpointer.slru_written to report SLRU buffers written (Nitin Jadhav) §

    Also, modify the checkpoint server log message to report separate shared buffer and SLRU buffer values.

    Original release occurrence · 18.0/changes/042

  • Add columns to pg_stat_database to report parallel worker activity Features

    Add columns to pg_stat_database to report parallel worker activity (Benoit Lobréau) §

    The new columns are parallel_workers_to_launch and parallel_workers_launched.

    Original release occurrence · 18.0/changes/043

  • Have query id computation of constant lists consider only the first and last constants Features

    Have query id computation of constant lists consider only the first and last constants (Dmitry Dolgov, Sami Imseih) § § §

    Jumbling is used by pg_stat_statements.

    Original release occurrence · 18.0/changes/044

  • Adjust query id computations to group together queries using the same relation name Features

    Adjust query id computations to group together queries using the same relation name (Michael Paquier, Sami Imseih) §

    This is true even if the tables in different schemas have different column names.

    Original release occurrence · 18.0/changes/045

  • Add column pg_backend_memory_contexts.type to report the type of memory context Features

    Add column pg_backend_memory_contexts.type to report the type of memory context (David Rowley) §

    Original release occurrence · 18.0/changes/046

  • Add column pg_backend_memory_contexts.path to show memory context parents Features

    Add column pg_backend_memory_contexts.path to show memory context parents (Melih Mutlu) §

    Original release occurrence · 18.0/changes/047

  • Add function pg_get_acl() to retrieve database access control details Features

    Add function pg_get_acl() to retrieve database access control details (Joel Jacobson) § §

    Original release occurrence · 18.0/changes/048

  • Add function has_largeobject_privilege() to check large object privileges Features

    Add function has_largeobject_privilege() to check large object privileges (Yugo Nagata) §

    Original release occurrence · 18.0/changes/049

  • Allow ALTER DEFAULT PRIVILEGES to define large object default privileges Features

    Allow ALTER DEFAULT PRIVILEGES to define large object default privileges (Takatsuka Haruka, Yugo Nagata, Laurenz Albe) §

    Original release occurrence · 18.0/changes/050

  • Add predefined role pg_signal_autovacuum_worker Features

    Add predefined role pg_signal_autovacuum_worker (Kirill Reshke) §

    This allows sending signals to autovacuum workers.

    Original release occurrence · 18.0/changes/051

  • Add support for the OAuth authentication method Features

    Add support for the OAuth authentication method (Jacob Champion, Daniel Gustafsson, Thomas Munro) §

    This adds an oauth authentication method to pg_hba.conf, libpq OAuth options, a server variable oauth_validator_libraries to load token validation libraries, and a configure flag --with-libcurl to add the required compile-time libraries.

    Original release occurrence · 18.0/changes/052

  • Add server variable ssl_tls13_ciphers to allow specification of multiple colon-separated TLSv1.3 cipher suites Features

    Add server variable ssl_tls13_ciphers to allow specification of multiple colon-separated TLSv1.3 cipher suites (Erica Zhang, Daniel Gustafsson) §

    Original release occurrence · 18.0/changes/053

  • Change server variable ssl_groups's default to include elliptic curve X25519 Features

    Change server variable ssl_groups's default to include elliptic curve X25519 (Daniel Gustafsson, Jacob Champion) §

    Original release occurrence · 18.0/changes/054

  • Rename server variable ssl_ecdh_curve to ssl_groups and allow multiple colon-separated ECDH curves to be specified Features

    Rename server variable ssl_ecdh_curve to ssl_groups and allow multiple colon-separated ECDH curves to be specified (Erica Zhang, Daniel Gustafsson) §

    The previous name still works.

    Original release occurrence · 18.0/changes/055

  • Make cancel request keys 256 bits Features

    Make cancel request keys 256 bits (Heikki Linnakangas, Jelte Fennema-Nio) § §

    This is only possible when the server and client support wire protocol version 3.2, introduced in this release.

    Original release occurrence · 18.0/changes/056

  • Add server variable autovacuum_worker_slots to specify the maximum number of background workers Features

    Add server variable autovacuum_worker_slots to specify the maximum number of background workers (Nathan Bossart) §

    With this variable set, autovacuum_max_workers can be adjusted at runtime up to this maximum without a server restart.

    Original release occurrence · 18.0/changes/057

  • Allow specification of the fixed number of dead tuples that will trigger an autovacuum Bug fixes

    Allow specification of the fixed number of dead tuples that will trigger an autovacuum (Nathan Bossart, Frédéric Yhuel) §

    The server variable is autovacuum_vacuum_max_threshold. Percentages are still used for triggering.

    Original release occurrence · 18.0/changes/058

  • Change server variable max_files_per_process to limit only files opened by a backend Features

    Change server variable max_files_per_process to limit only files opened by a backend (Andres Freund) §

    Previously files opened by the postmaster were also counted toward this limit.

    Original release occurrence · 18.0/changes/059

  • Add server variable num_os_semaphores to report the required number of semaphores Features

    Add server variable num_os_semaphores to report the required number of semaphores (Nathan Bossart) §

    This is useful for operating system configuration.

    Original release occurrence · 18.0/changes/060

  • Add server variable extension_control_path to specify the location of extension control files Features

    Add server variable extension_control_path to specify the location of extension control files (Peter Eisentraut, Matheus Alcantara) § §

    Original release occurrence · 18.0/changes/061

  • Allow inactive replication slots to be automatically invalidated using server variable idle_replication_slot_timeout Features

    Allow inactive replication slots to be automatically invalidated using server variable idle_replication_slot_timeout (Nisha Moond, Bharath Rupireddy) §

    Original release occurrence · 18.0/changes/062

  • Add server variable max_active_replication_origins to control the maximum active replication origins Features

    Add server variable max_active_replication_origins to control the maximum active replication origins (Euler Taveira) §

    This was previously controlled by max_replication_slots, but this new setting allows a higher origin count in cases where fewer slots are required.

    Original release occurrence · 18.0/changes/063

  • Allow the values of generated columns to be logically replicated Features

    Allow the values of generated columns to be logically replicated (Shubham Khanna, Vignesh C, Zhijie Hou, Shlok Kyal, Peter Smith) § § § §

    If the publication specifies a column list, all specified columns, generated and non-generated, are published. Without a specified column list, publication option publish_generated_columns controls whether generated columns are published. Previously generated columns were not replicated and the subscriber had to compute the values if possible; this is particularly useful for non-PostgreSQL subscribers which lack such a capability.

    Original release occurrence · 18.0/changes/064

  • Change the default CREATE SUBSCRIPTION streaming option from off to parallel Features

    Change the default CREATE SUBSCRIPTION streaming option from off to parallel (Vignesh C) §

    Original release occurrence · 18.0/changes/065

  • Allow ALTER SUBSCRIPTION to change the replication slot's two-phase commit behavior Features

    Allow ALTER SUBSCRIPTION to change the replication slot's two-phase commit behavior (Hayato Kuroda, Ajin Cherian, Amit Kapila, Zhijie Hou) § §

    Original release occurrence · 18.0/changes/066

  • Log conflicts while applying logical replication changes Features

    Log conflicts while applying logical replication changes (Zhijie Hou, Nisha Moond) § § § § §

    Also report in new columns of pg_stat_subscription_stats.

    Original release occurrence · 18.0/changes/067

  • Allow generated columns to be virtual, and make them the default Features

    Allow generated columns to be virtual, and make them the default (Peter Eisentraut, Jian He, Richard Guo, Dean Rasheed) § § §

    Virtual generated columns generate their values when the columns are read, not written. The write behavior can still be specified via the STORED option.

    Original release occurrence · 18.0/changes/068

  • Add OLD/NEW support to RETURNING in DML queries Features

    Add OLD/NEW support to RETURNING in DML queries (Dean Rasheed) §

    Previously RETURNING only returned new values for INSERT and UPDATE, and old values for DELETE; MERGE would return the appropriate value for the internal query executed. This new syntax allows the RETURNING list of INSERT/UPDATE/DELETE/MERGE to explicitly return old and new values by using the special aliases old and new. These aliases can be renamed to avoid identifier conflicts.

    Original release occurrence · 18.0/changes/069

  • Allow foreign tables to be created like existing local tables Features

    Allow foreign tables to be created like existing local tables (Zhang Mingli) §

    The syntax is CREATE FOREIGN TABLE ... LIKE.

    Original release occurrence · 18.0/changes/070

  • Allow LIKE with nondeterministic collations Features

    Allow LIKE with nondeterministic collations (Peter Eisentraut) §

    Original release occurrence · 18.0/changes/071

  • Allow text position search functions with nondeterministic collations Features

    Allow text position search functions with nondeterministic collations (Peter Eisentraut) §

    These used to generate an error.

    Original release occurrence · 18.0/changes/072

  • Add builtin collation provider PG_UNICODE_FAST Features

    Add builtin collation provider PG_UNICODE_FAST (Jeff Davis) §

    This locale supports case mapping, but sorts in code point order, not natural language order.

    Original release occurrence · 18.0/changes/073

  • Allow VACUUM and ANALYZE to process partitioned tables without processing their children Features

    Allow VACUUM and ANALYZE to process partitioned tables without processing their children (Michael Harris) §

    This is enabled with the new ONLY option. This is useful since autovacuum does not process partitioned tables, just its children.

    Original release occurrence · 18.0/changes/074

  • Add functions to modify per-relation and per-column optimizer statistics Features

    Add functions to modify per-relation and per-column optimizer statistics (Corey Huinker) § § §

    The functions are pg_restore_relation_stats(), pg_restore_attribute_stats(), pg_clear_relation_stats(), and pg_clear_attribute_stats().

    Original release occurrence · 18.0/changes/075

  • Add server variable file_copy_method to control the file copying method Features

    Add server variable file_copy_method to control the file copying method (Nazir Bilal Yavuz) §

    This controls whether CREATE DATABASE ... STRATEGY=FILE_COPY and ALTER DATABASE ... SET TABLESPACE uses file copy or clone.

    Original release occurrence · 18.0/changes/076

  • Allow the specification of non-overlapping PRIMARY KEY, UNIQUE, and foreign key constraints Features

    Allow the specification of non-overlapping PRIMARY KEY, UNIQUE, and foreign key constraints (Paul A. Jungwirth) § §

    This is specified by WITHOUT OVERLAPS for PRIMARY KEY and UNIQUE, and by PERIOD for foreign keys, all applied to the last specified column.

    Original release occurrence · 18.0/changes/077

  • Allow CHECK and foreign key constraints to be specified as NOT ENFORCED Features

    Allow CHECK and foreign key constraints to be specified as NOT ENFORCED (Amul Sul) § §

    This also adds column pg_constraint.conenforced.

    Original release occurrence · 18.0/changes/078

  • Require primary/foreign key relationships to use either deterministic collations or the the same nondeterministic collations Features

    Require primary/foreign key relationships to use either deterministic collations or the the same nondeterministic collations (Peter Eisentraut) §

    The restore of a pg_dump, also used by pg_upgrade, will fail if these requirements are not met; schema changes must be made for these upgrade methods to succeed.

    Original release occurrence · 18.0/changes/079

  • Store column NOT NULL specifications in pg_constraint Features

    Store column NOT NULL specifications in pg_constraint (Álvaro Herrera, Bernd Helmle) § §

    This allows names to be specified for NOT NULL constraint. This also adds NOT NULL constraints to foreign tables and NOT NULL inheritance control to local tables.

    Original release occurrence · 18.0/changes/080

  • Allow ALTER TABLE to set the NOT VALID attribute of NOT NULL constraints Features

    Allow ALTER TABLE to set the NOT VALID attribute of NOT NULL constraints (Rushabh Lathia, Jian He) §

    Original release occurrence · 18.0/changes/081

  • Allow modification of the inheritability of NOT NULL constraints Features

    Allow modification of the inheritability of NOT NULL constraints (Suraj Kharage, Álvaro Herrera) § §

    The syntax is ALTER TABLE ... ALTER CONSTRAINT ... [NO] INHERIT.

    Original release occurrence · 18.0/changes/082

  • Allow NOT VALID foreign key constraints on partitioned tables Features

    Allow NOT VALID foreign key constraints on partitioned tables (Amul Sul) §

    Original release occurrence · 18.0/changes/083

  • Allow dropping of constraints ONLY on partitioned tables Features

    Allow dropping of constraints ONLY on partitioned tables (Álvaro Herrera) §

    This was previously erroneously prohibited.

    Original release occurrence · 18.0/changes/084

  • Add REJECT_LIMIT to control the number of invalid rows COPY FROM can ignore Features

    Add REJECT_LIMIT to control the number of invalid rows COPY FROM can ignore (Atsushi Torikoshi) §

    This is available when ON_ERROR = 'ignore'.

    Original release occurrence · 18.0/changes/085

  • Allow COPY TO to copy rows from populated materialized views Features

    Allow COPY TO to copy rows from populated materialized views (Jian He) §

    Original release occurrence · 18.0/changes/086

  • Add COPY LOG_VERBOSITY level silent to suppress log output of ignored rows Features

    Add COPY LOG_VERBOSITY level silent to suppress log output of ignored rows (Atsushi Torikoshi) §

    This new level suppresses output for discarded input rows when on_error = 'ignore'.

    Original release occurrence · 18.0/changes/087

  • Disallow COPY FREEZE on foreign tables Features

    Disallow COPY FREEZE on foreign tables (Nathan Bossart) §

    Previously, the COPY worked but the FREEZE was ignored, so disallow this command.

    Original release occurrence · 18.0/changes/088

  • Automatically include BUFFERS output in EXPLAIN ANALYZE Features

    Automatically include BUFFERS output in EXPLAIN ANALYZE (Guillaume Lelarge, David Rowley) §

    Original release occurrence · 18.0/changes/089

  • Add full WAL buffer count to EXPLAIN (WAL) output Features

    Add full WAL buffer count to EXPLAIN (WAL) output (Bertrand Drouvot) §

    Original release occurrence · 18.0/changes/090

  • In EXPLAIN ANALYZE, report the number of index lookups used per index scan node Features

    In EXPLAIN ANALYZE, report the number of index lookups used per index scan node (Peter Geoghegan) §

    Original release occurrence · 18.0/changes/091

  • Modify EXPLAIN to output fractional row counts Features

    Modify EXPLAIN to output fractional row counts (Ibrar Ahmed, Ilia Evdokimov, Robert Haas) § §

    Original release occurrence · 18.0/changes/092

  • Add memory and disk usage details to Material, Window Aggregate, and common table expression nodes to EXPLAIN output Features

    Add memory and disk usage details to Material, Window Aggregate, and common table expression nodes to EXPLAIN output (David Rowley, Tatsuo Ishii) § § § §

    Original release occurrence · 18.0/changes/093

  • Add details about window function arguments to EXPLAIN output Features

    Add details about window function arguments to EXPLAIN output (Tom Lane) §

    Original release occurrence · 18.0/changes/094

  • Add Parallel Bitmap Heap Scan worker cache statistics to EXPLAIN ANALYZE Features

    Add Parallel Bitmap Heap Scan worker cache statistics to EXPLAIN ANALYZE (David Geier, Heikki Linnakangas, Donghang Lin, Alena Rybakina, David Rowley) §

    Original release occurrence · 18.0/changes/095

  • Indicate disabled nodes in EXPLAIN ANALYZE output Features

    Indicate disabled nodes in EXPLAIN ANALYZE output (Robert Haas, David Rowley, Laurenz Albe) § § §

    Original release occurrence · 18.0/changes/096

  • Improve Unicode full case mapping and conversion Features

    Improve Unicode full case mapping and conversion (Jeff Davis) § §

    This adds the ability to do conditional and title case mapping, and case map single characters to multiple characters.

    Original release occurrence · 18.0/changes/097

  • Allow jsonb null values to be cast to scalar types as NULL Features

    Allow jsonb null values to be cast to scalar types as NULL (Tom Lane) §

    Previously such casts generated an error.

    Original release occurrence · 18.0/changes/098

  • Add optional parameter to json{b}_strip_nulls to allow removal of null array elements Features

    Add optional parameter to json{b}_strip_nulls to allow removal of null array elements (Florents Tselai) §

    Original release occurrence · 18.0/changes/099

  • Add function array_sort() which sorts an array's first dimension Features

    Add function array_sort() which sorts an array's first dimension (Junwang Zhao, Jian He) §

    Original release occurrence · 18.0/changes/100

  • Add function array_reverse() which reverses an array's first dimension Features

    Add function array_reverse() which reverses an array's first dimension (Aleksander Alekseev) §

    Original release occurrence · 18.0/changes/101

  • Add function reverse() to reverse bytea bytes Features

    Add function reverse() to reverse bytea bytes (Aleksander Alekseev) §

    Original release occurrence · 18.0/changes/102

  • Allow casting between integer types and bytea Features

    Allow casting between integer types and bytea (Aleksander Alekseev) §

    The integer values are stored as bytea two's complement values.

    Original release occurrence · 18.0/changes/103

  • Update Unicode data to Unicode 16.0.0 Features

    Update Unicode data to Unicode 16.0.0 (Peter Eisentraut) §

    Original release occurrence · 18.0/changes/104

  • Add full text search stemming for Estonian Features

    Add full text search stemming for Estonian (Tom Lane) §

    Original release occurrence · 18.0/changes/105

  • Improve the XML error codes to more closely match the SQL standard Features

    Improve the XML error codes to more closely match the SQL standard (Tom Lane) §

    These errors are reported via SQLSTATE.

    Original release occurrence · 18.0/changes/106

  • Add function casefold() to allow for more sophisticated case-insensitive matching Features

    Add function casefold() to allow for more sophisticated case-insensitive matching (Jeff Davis) §

    This allows more accurate comparisons, i.e., a character can have multiple upper or lower case equivalents, or upper or lower case conversion changes the number of characters.

    Original release occurrence · 18.0/changes/107

  • Allow MIN()/MAX() aggregates on arrays and composite types Features

    Allow MIN()/MAX() aggregates on arrays and composite types (Aleksander Alekseev, Marat Buharov) § §

    Original release occurrence · 18.0/changes/108

  • Add a WEEK option to EXTRACT() Features

    Add a WEEK option to EXTRACT() (Tom Lane) §

    Original release occurrence · 18.0/changes/109

  • Improve the output EXTRACT(QUARTER ...) for negative values Features

    Improve the output EXTRACT(QUARTER ...) for negative values (Tom Lane) §

    Original release occurrence · 18.0/changes/110

  • Add roman numeral support to to_number() Features

    Add roman numeral support to to_number() (Hunaid Sohail) §

    This is accessed via the RN pattern.

    Original release occurrence · 18.0/changes/111

  • Add UUID version 7 generation function uuidv7() Features

    Add UUID version 7 generation function uuidv7() (Andrey Borodin) §

    This UUID value is temporally sortable. Function alias uuidv4() has been added to explicitly generate version 4 UUIDs.

    Original release occurrence · 18.0/changes/112

  • Add functions crc32() and crc32c() to compute CRC values Features

    Add functions crc32() and crc32c() to compute CRC values (Aleksander Alekseev) §

    Original release occurrence · 18.0/changes/113

  • Add math functions gamma() and lgamma() Features

    Add math functions gamma() and lgamma() (Dean Rasheed) §

    Original release occurrence · 18.0/changes/114

  • Allow => syntax for named cursor arguments in PL/pgSQL Features

    Allow => syntax for named cursor arguments in PL/pgSQL (Pavel Stehule) §

    We previously only accepted :=.

    Original release occurrence · 18.0/changes/115

  • Allow regexp_match[es]()/regexp_like()/regexp_replace()/regexp_count()/regexp_instr()/regexp_substr()/regexp_split_to_table()/regexp_split_to_array() to use named arguments Features

    Original release occurrence · 18.0/changes/116

  • Add function PQfullProtocolVersion() to report the full, including minor, protocol version number Features

    Add function PQfullProtocolVersion() to report the full, including minor, protocol version number (Jacob Champion, Jelte Fennema-Nio) §

    Original release occurrence · 18.0/changes/117

  • Add libpq connection parameters and environment variables to specify the minimum and maximum acceptable protocol version for connections Features

    Add libpq connection parameters and environment variables to specify the minimum and maximum acceptable protocol version for connections (Jelte Fennema-Nio) § §

    Original release occurrence · 18.0/changes/118

  • Report search_path changes to the client Features

    Report search_path changes to the client (Alexander Kukushkin, Jelte Fennema-Nio, Tomas Vondra) § §

    Original release occurrence · 18.0/changes/119

  • Add PQtrace() output for all message types, including authentication Features

    Add PQtrace() output for all message types, including authentication (Jelte Fennema-Nio) § § § § §

    Original release occurrence · 18.0/changes/120

  • Add libpq connection parameter sslkeylogfile which dumps out SSL key material Features

    Add libpq connection parameter sslkeylogfile which dumps out SSL key material (Abhishek Chanda, Daniel Gustafsson) §

    This is useful for debugging.

    Original release occurrence · 18.0/changes/121

  • Modify some libpq function signatures to use int64_t Features

    Modify some libpq function signatures to use int64_t (Thomas Munro) §

    These previously used pg_int64, which is now deprecated.

    Original release occurrence · 18.0/changes/122

  • Allow psql to parse, bind, and close named prepared statements Features

    Allow psql to parse, bind, and close named prepared statements (Anthonin Bonnefoy, Michael Paquier) § §

    This is accomplished with new commands \parse, \bind_named, and \close_prepared.

    Original release occurrence · 18.0/changes/123

  • Add psql backslash commands to allowing issuance of pipeline queries Features

    Add psql backslash commands to allowing issuance of pipeline queries (Anthonin Bonnefoy) § § §

    The new commands are \startpipeline, \syncpipeline, \sendpipeline, \endpipeline, \flushrequest, \flush, and \getresults.

    Original release occurrence · 18.0/changes/124

  • Allow adding pipeline status to the psql prompt and add related state variables Features

    Allow adding pipeline status to the psql prompt and add related state variables (Anthonin Bonnefoy) §

    The new prompt character is %P and the new psql variables are PIPELINE_SYNC_COUNT, PIPELINE_COMMAND_COUNT, and PIPELINE_RESULT_COUNT.

    Original release occurrence · 18.0/changes/125

  • Allow adding the connection service name to the psql prompt or access it via psql variable Features

    Allow adding the connection service name to the psql prompt or access it via psql variable (Michael Banck) §

    Original release occurrence · 18.0/changes/126

  • Add psql option to use expanded mode on all list commands Features

    Add psql option to use expanded mode on all list commands (Dean Rasheed) §

    Adding backslash suffix x enables this.

    Original release occurrence · 18.0/changes/127

  • Change psql's \conninfo to use tabular format and include more information Features

    Change psql's \conninfo to use tabular format and include more information (Álvaro Herrera, Maiquel Grassi, Hunaid Sohail) §

    Original release occurrence · 18.0/changes/128

  • Add function's leakproof indicator to psql's \df+, \do+, \dAo+, and \dC+ outputs Features

    Add function's leakproof indicator to psql's \df+, \do+, \dAo+, and \dC+ outputs (Yugo Nagata) §

    Original release occurrence · 18.0/changes/129

  • Add access method details for partitioned relations in \dP+ Features

    Add access method details for partitioned relations in \dP+ (Justin Pryzby) §

    Original release occurrence · 18.0/changes/130

  • Add default_version to the psql \dx extension output Features

    Add default_version to the psql \dx extension output (Magnus Hagander) §

    Original release occurrence · 18.0/changes/131

  • Add psql variable WATCH_INTERVAL to set the default \watch wait time Features

    Add psql variable WATCH_INTERVAL to set the default \watch wait time (Daniel Gustafsson) §

    Original release occurrence · 18.0/changes/132

  • Change initdb to default to enabling checksums Features

    Change initdb to default to enabling checksums (Greg Sabino Mullane) § §

    The new initdb option --no-data-checksums disables checksums.

    Original release occurrence · 18.0/changes/133

  • Add initdb option --no-sync-data-files to avoid syncing heap/index files Features

    Add initdb option --no-sync-data-files to avoid syncing heap/index files (Nathan Bossart) §

    initdb option --no-sync is still available to avoid syncing any files.

    Original release occurrence · 18.0/changes/134

  • Add vacuumdb option --missing-stats-only to compute only missing optimizer statistics Features

    Add vacuumdb option --missing-stats-only to compute only missing optimizer statistics (Corey Huinker, Nathan Bossart) § §

    This option can only be run by superusers and can only be used with options --analyze-only and --analyze-in-stages.

    Original release occurrence · 18.0/changes/135

  • Add pg_combinebackup option -k/--link to enable hard linking Features

    Add pg_combinebackup option -k/--link to enable hard linking (Israel Barth Rubio, Robert Haas) §

    Only some files can be hard linked. This should not be used if the backups will be used independently.

    Original release occurrence · 18.0/changes/136

  • Allow pg_verifybackup to verify tar-format backups Features

    Allow pg_verifybackup to verify tar-format backups (Amul Sul) §

    Original release occurrence · 18.0/changes/137

  • If pg_rewind's --source-server specifies a database name, use it in --write-recovery-conf output Features

    If pg_rewind's --source-server specifies a database name, use it in --write-recovery-conf output (Masahiko Sawada) §

    Original release occurrence · 18.0/changes/138

  • Add pg_resetwal option --char-signedness to change the default char signedness Features

    Add pg_resetwal option --char-signedness to change the default char signedness (Masahiko Sawada) §

    Original release occurrence · 18.0/changes/139

  • Add pg_dump option --statistics Features

    Add pg_dump option --statistics (Jeff Davis) § §

    Original release occurrence · 18.0/changes/140

  • Add pg_dump and pg_dumpall option --sequence-data to dump sequence data that would normally be excluded Features

    Add pg_dump and pg_dumpall option --sequence-data to dump sequence data that would normally be excluded (Nathan Bossart) § §

    Original release occurrence · 18.0/changes/141

  • Add pg_dump, pg_dumpall, and pg_restore options --statistics-only, --no-statistics, --no-data, and --no-schema Features

    Add pg_dump, pg_dumpall, and pg_restore options --statistics-only, --no-statistics, --no-data, and --no-schema (Corey Huinker, Jeff Davis) §

    Original release occurrence · 18.0/changes/142

  • Add option --no-policies to disable row level security policy processing in pg_dump, pg_dumpall, pg_restore Features

    Add option --no-policies to disable row level security policy processing in pg_dump, pg_dumpall, pg_restore (Nikolay Samokhvalov) §

    This is useful for migrating to systems with different policies.

    Original release occurrence · 18.0/changes/143

  • Allow pg_upgrade to preserve optimizer statistics Features

    Allow pg_upgrade to preserve optimizer statistics (Corey Huinker, Jeff Davis, Nathan Bossart) § § § §

    Extended statistics are not preserved. Also add pg_upgrade option --no-statistics to disable statistics preservation.

    Original release occurrence · 18.0/changes/144

  • Allow pg_upgrade to process database checks in parallel Features

    Allow pg_upgrade to process database checks in parallel (Nathan Bossart) § § § § § § § § § § §

    This is controlled by the existing --jobs option.

    Original release occurrence · 18.0/changes/145

  • Add pg_upgrade option --swap to swap directories rather than copy, clone, or link files Features

    Add pg_upgrade option --swap to swap directories rather than copy, clone, or link files (Nathan Bossart) §

    This mode is potentially the fastest.

    Original release occurrence · 18.0/changes/146

  • Add pg_upgrade option --set-char-signedness to set the default char signedness of new cluster Features

    Add pg_upgrade option --set-char-signedness to set the default char signedness of new cluster (Masahiko Sawada) § §

    This is to handle cases where a pre-PostgreSQL 18 cluster's default CPU signedness does not match the new cluster.

    Original release occurrence · 18.0/changes/147

  • Add pg_createsubscriber option --all to create logical replicas for all databases Features

    Add pg_createsubscriber option --all to create logical replicas for all databases (Shubham Khanna) §

    Original release occurrence · 18.0/changes/148

  • Add pg_createsubscriber option --clean to remove publications Features

    Add pg_createsubscriber option --clean to remove publications (Shubham Khanna) § §

    Original release occurrence · 18.0/changes/149

  • Add pg_createsubscriber option --enable-two-phase to enable prepared transactions Features

    Add pg_createsubscriber option --enable-two-phase to enable prepared transactions (Shubham Khanna) §

    Original release occurrence · 18.0/changes/150

  • Add pg_recvlogical option --enable-failover to specify failover slots Features

    Add pg_recvlogical option --enable-failover to specify failover slots (Hayato Kuroda) §

    Also add option --enable-two-phase as a synonym for --two-phase, and deprecate the latter.

    Original release occurrence · 18.0/changes/151

  • Allow pg_recvlogical --drop-slot to work without --dbname Features

    Allow pg_recvlogical --drop-slot to work without --dbname (Hayato Kuroda) §

    Original release occurrence · 18.0/changes/152

  • Separate the loading and running of injection points Features

    Separate the loading and running of injection points (Michael Paquier, Heikki Linnakangas) § §

    Injection points can now be created, but not run, via INJECTION_POINT_LOAD(), and such injection points can be run via INJECTION_POINT_CACHED().

    Original release occurrence · 18.0/changes/153

  • Support runtime arguments in injection points Features

    Support runtime arguments in injection points (Michael Paquier) §

    Original release occurrence · 18.0/changes/154

  • Allow inline injection point test code with IS_INJECTION_POINT_ATTACHED() Features

    Allow inline injection point test code with IS_INJECTION_POINT_ATTACHED() (Heikki Linnakangas) §

    Original release occurrence · 18.0/changes/155

  • Improve the performance of processing long JSON strings using SIMD (Single Instruction Multiple Data) Performance

    Improve the performance of processing long JSON strings using SIMD (Single Instruction Multiple Data) (David Rowley) §

    Original release occurrence · 18.0/changes/156

  • Speed up CRC32C calculations using x86 AVX-512 instructions Performance

    Speed up CRC32C calculations using x86 AVX-512 instructions (Raghuveer Devulapalli, Paul Amonson) §

    Original release occurrence · 18.0/changes/157

  • Add ARM Neon and SVE CPU intrinsics for popcount (integer bit counting) Features

    Add ARM Neon and SVE CPU intrinsics for popcount (integer bit counting) (Chiranmoy Bhattacharya, Devanga Susmitha, Rama Malladi) § §

    Original release occurrence · 18.0/changes/158

  • Improve the speed of numeric multiplication and division Features

    Improve the speed of numeric multiplication and division (Joel Jacobson, Dean Rasheed) § § § §

    Original release occurrence · 18.0/changes/159

  • Add configure option --with-libnuma to enable NUMA awareness Features

    Add configure option --with-libnuma to enable NUMA awareness (Jakub Wartak, Bertrand Drouvot) § § §

    The function pg_numa_available() reports on NUMA awareness, and system views pg_shmem_allocations_numa and pg_buffercache_numa which report on shared memory distribution across NUMA nodes.

    Original release occurrence · 18.0/changes/160

  • Add TOAST table to pg_index to allow for very large expression indexes Features

    Add TOAST table to pg_index to allow for very large expression indexes (Nathan Bossart) §

    Original release occurrence · 18.0/changes/161

  • Remove column pg_attribute.attcacheoff Features

    Remove column pg_attribute.attcacheoff (David Rowley) §

    Original release occurrence · 18.0/changes/162

  • Add column pg_class.relallfrozen Features

    Add column pg_class.relallfrozen (Melanie Plageman) §

    Original release occurrence · 18.0/changes/163

  • Add amgettreeheight, amconsistentequality, and amconsistentordering to the index access method API Features

    Add amgettreeheight, amconsistentequality, and amconsistentordering to the index access method API (Mark Dilger) § §

    Original release occurrence · 18.0/changes/164

  • Add GiST support function stratnum() Features

    Add GiST support function stratnum() (Paul A. Jungwirth) §

    Original release occurrence · 18.0/changes/165

  • Record the default CPU signedness of char in pg_controldata Features

    Record the default CPU signedness of char in pg_controldata (Masahiko Sawada) §

    Original release occurrence · 18.0/changes/166

  • Add support for Python "Limited API" in PL/Python Features

    Add support for Python "Limited API" in PL/Python (Peter Eisentraut) § §

    This helps prevent problems caused by Python 3.x version mismatches.

    Original release occurrence · 18.0/changes/167

  • Change the minimum supported Python version to 3.6.8 Features

    Change the minimum supported Python version to 3.6.8 (Jacob Champion) §

    Original release occurrence · 18.0/changes/168

  • Remove support for OpenSSL versions older than 1.1.1 Features

    Remove support for OpenSSL versions older than 1.1.1 (Daniel Gustafsson) § §

    Original release occurrence · 18.0/changes/169

  • If LLVM is enabled, require version 14 or later Features

    If LLVM is enabled, require version 14 or later (Thomas Munro) §

    Original release occurrence · 18.0/changes/170

  • Add macro PG_MODULE_MAGIC_EXT to allow extensions to report their name and version Features

    Add macro PG_MODULE_MAGIC_EXT to allow extensions to report their name and version (Andrei Lepikhov) §

    This information can be access via the new function pg_get_loaded_modules().

    Original release occurrence · 18.0/changes/171

  • Document that SPI_connect()/SPI_connect_ext() always returns success (SPI_OK_CONNECT) Features

    Document that SPI_connect()/SPI_connect_ext() always returns success (SPI_OK_CONNECT) (Stepan Neretin) §

    Errors are always reported via ereport().

    Original release occurrence · 18.0/changes/172

  • Add documentation section about API and ABI compatibility Features

    Add documentation section about API and ABI compatibility (David Wheeler, Peter Eisentraut) §

    Original release occurrence · 18.0/changes/173

  • Remove the experimental designation of Meson builds on Windows Features

    Remove the experimental designation of Meson builds on Windows (Aleksander Alekseev) §

    Original release occurrence · 18.0/changes/174

  • Remove configure options --disable-spinlocks and --disable-atomics Features

    Remove configure options --disable-spinlocks and --disable-atomics (Thomas Munro) § §

    Thirty-two-bit atomic operations are now required.

    Original release occurrence · 18.0/changes/175

  • Remove support for the HPPA/PA-RISC architecture Features

    Remove support for the HPPA/PA-RISC architecture (Tom Lane) §

    Original release occurrence · 18.0/changes/176

  • Add extension pg_logicalinspect to inspect logical snapshots Features

    Add extension pg_logicalinspect to inspect logical snapshots (Bertrand Drouvot) §

    Original release occurrence · 18.0/changes/177

  • Add extension pg_overexplain which adds debug details to EXPLAIN output Features

    Add extension pg_overexplain which adds debug details to EXPLAIN output (Robert Haas) §

    Original release occurrence · 18.0/changes/178

  • Add output columns to postgres_fdw_get_connections() Features

    Add output columns to postgres_fdw_get_connections() (Hayato Kuroda, Sagar Dilip Shedge) § § § §

    New output column used_in_xact indicates if the foreign data wrapper is being used by a current transaction, closed indicates if it is closed, user_name indicates the user name, and remote_backend_pid indicates the remote backend process identifier.

    Original release occurrence · 18.0/changes/179

  • Allow SCRAM authentication from the client to be passed to postgres_fdw servers Features

    Allow SCRAM authentication from the client to be passed to postgres_fdw servers (Matheus Alcantara, Peter Eisentraut) §

    This avoids storing postgres_fdw authentication information in the database, and is enabled with the postgres_fdw use_scram_passthrough connection option. libpq uses new connection parameters scram_client_key and scram_server_key.

    Original release occurrence · 18.0/changes/180

  • Allow SCRAM authentication from the client to be passed to dblink servers Features

    Allow SCRAM authentication from the client to be passed to dblink servers (Matheus Alcantara) §

    Original release occurrence · 18.0/changes/181

  • Add on_error and log_verbosity options to file_fdw Features

    Add on_error and log_verbosity options to file_fdw (Atsushi Torikoshi) §

    These control how file_fdw handles and reports invalid file rows.

    Original release occurrence · 18.0/changes/182

  • Add reject_limit to control the number of invalid rows file_fdw can ignore Features

    Add reject_limit to control the number of invalid rows file_fdw can ignore (Atsushi Torikoshi) §

    This is active when ON_ERROR = 'ignore'.

    Original release occurrence · 18.0/changes/183

  • Add configurable variable min_password_length to passwordcheck Features

    Add configurable variable min_password_length to passwordcheck (Emanuele Musella, Maurizio Boriani) §

    This controls the minimum password length.

    Original release occurrence · 18.0/changes/184

  • Have pgbench report the number of failed, retried, or skipped transactions in per-script reports Features

    Have pgbench report the number of failed, retried, or skipped transactions in per-script reports (Yugo Nagata) §

    Original release occurrence · 18.0/changes/185

  • Add isn server variable weak to control invalid check digit acceptance Features

    Add isn server variable weak to control invalid check digit acceptance (Viktor Holmberg) §

    This was previously only controlled by function isn_weak().

    Original release occurrence · 18.0/changes/186

  • Allow values to be sorted to speed btree_gist index builds Features

    Allow values to be sorted to speed btree_gist index builds (Bernd Helmle, Andrey Borodin) §

    Original release occurrence · 18.0/changes/187

  • Add amcheck check function gin_index_check() to verify GIN indexes Features

    Add amcheck check function gin_index_check() to verify GIN indexes (Grigory Kryachko, Heikki Linnakangas, Andrey Borodin) §

    Original release occurrence · 18.0/changes/188

  • Add functions pg_buffercache_evict_relation() and pg_buffercache_evict_all() to evict unpinned shared buffers Features

    Add functions pg_buffercache_evict_relation() and pg_buffercache_evict_all() to evict unpinned shared buffers (Nazir Bilal Yavuz) §

    The existing function pg_buffercache_evict() now returns the buffer flush status.

    Original release occurrence · 18.0/changes/189

  • Allow extensions to install custom EXPLAIN options Features

    Allow extensions to install custom EXPLAIN options (Robert Haas, Sami Imseih) § § §

    Original release occurrence · 18.0/changes/190

  • Allow extensions to use the server's cumulative statistics API Features

    Allow extensions to use the server's cumulative statistics API (Michael Paquier) § §

    Original release occurrence · 18.0/changes/191

  • Allow the queries of CREATE TABLE AS and DECLARE to be tracked by pg_stat_statements Features

    Allow the queries of CREATE TABLE AS and DECLARE to be tracked by pg_stat_statements (Anthonin Bonnefoy) §

    They are also now assigned query ids.

    Original release occurrence · 18.0/changes/192

  • Allow the parameterization of SET values in pg_stat_statements Features

    Allow the parameterization of SET values in pg_stat_statements (Greg Sabino Mullane, Michael Paquier) §

    This reduces the bloat caused by SET statements with differing constants.

    Original release occurrence · 18.0/changes/193

  • Add pg_stat_statements columns to report parallel activity Features

    Add pg_stat_statements columns to report parallel activity (Guillaume Lelarge) §

    The new columns are parallel_workers_to_launch and parallel_workers_launched.

    Original release occurrence · 18.0/changes/194

  • Add pg_stat_statements.wal_buffers_full to report full WAL buffers Features

    Add pg_stat_statements.wal_buffers_full to report full WAL buffers (Bertrand Drouvot) §

    Original release occurrence · 18.0/changes/195

  • Add pgcrypto algorithms sha256crypt and sha512crypt Features

    Add pgcrypto algorithms sha256crypt and sha512crypt (Bernd Helmle) §

    Original release occurrence · 18.0/changes/196

  • Add CFB mode to pgcrypto encryption and decryption Features

    Add CFB mode to pgcrypto encryption and decryption (Umar Hayat) §

    Original release occurrence · 18.0/changes/197

  • Add function fips_mode() to report the server's FIPS mode Features

    Add function fips_mode() to report the server's FIPS mode (Daniel Gustafsson) §

    Original release occurrence · 18.0/changes/198

  • Add pgcrypto server variable builtin_crypto_enabled to allow disabling builtin non-FIPS mode cryptographic functions Features

    Add pgcrypto server variable builtin_crypto_enabled to allow disabling builtin non-FIPS mode cryptographic functions (Daniel Gustafsson, Joe Conway) §

    This is useful for guaranteeing FIPS mode behavior.

    Original release occurrence · 18.0/changes/199

Security evidence

47 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.

CVE-2026-6638 · PostgreSQL REFRESH PUBLICATION allows SQL injection via table name CVSS 3.7

SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.

Fixed in this branch: 18.4. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-6637 · PostgreSQL refint allows stack buffer overflow and SQL injection CVSS 8.8

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 18.4. Component: contrib module.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6575 · PostgreSQL pg_restore_attribute_stats accepts values that cause query planning to read past end of stats array CVSS 4.3

Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor versions before PostgreSQL 18.4 are affected. Versions before PostgreSQL 18 are unaffected.

Fixed in this branch: 18.4. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-6479 · PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion CVSS 7.5

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 18.4. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2026-6478 · PostgreSQL discloses MD5-hashed passwords via covert timing channel CVSS 6.5

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 18.4. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-6477 · PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory CVSS 8.8

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 18.4. Component: client.

Official affected-branch entry: 18.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6476 · PostgreSQL pg_createsubscriber allows SQL injection via subscription name CVSS 7.2

SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_createsubscriber next runs. Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected. Versions before PostgreSQL 17 are unaffected.

Fixed in this branch: 18.4. Component: client.

Official affected-branch entry: 18.

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6475 · PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice CVSS 8.8

Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 18.4. Component: client.

Official affected-branch entry: 18.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6474 · PostgreSQL timeofday() can disclose portions of server memory CVSS 4.3

Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 18.4. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-6473 · PostgreSQL server undersizes allocations, via integer wraparound CVSS 8.8

Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 18.4. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6472 · PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege CVSS 5.4

Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Fixed in this branch: 18.4. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-6471 · PostgreSQL logical decoding can dlopen arbitrary file CVSS 7.2

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-6470 · PostgreSQL fails to check type USAGE privilege CVSS 4.3

Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

CVE-2026-6469 · PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership CVSS 3.8

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

Release-note mentions:

CVE-2026-6464 · PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands CVSS 8.1

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: client.

Official affected-branch entry: 18.

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2007 · PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory CVSS 8.2

Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.

Fixed in this branch: 18.2. Component: contrib module.

Official affected-branch entry: 18.

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Release-note mentions:

CVE-2026-2006 · PostgreSQL missing validation of multibyte character length executes arbitrary code CVSS 8.8

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 18.2. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2005 · PostgreSQL pgcrypto heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 18.2. Component: contrib module.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2004 · PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code CVSS 8.8

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 18.2. Component: contrib module.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-2003 · PostgreSQL oidvector discloses a few bytes of memory CVSS 4.3

Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Fixed in this branch: 18.2. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-19385 · PostgreSQL pg_dump heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: client.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-18408 · PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client CVSS 8.8

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: client.

Official affected-branch entry: 18.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-18024 · PostgreSQL ascii() function reads past end of buffer CVSS 4.3

Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-16241 · PostgreSQL ECPG integer underflow can crash the client CVSS 3.8

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: client.

Official affected-branch entry: 18.

AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

Release-note mentions:

CVE-2026-16239 · PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-16238 · PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-15742 · PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: contrib module.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-15741 · PostgreSQL expression deparse allows SQL injection via EXTRACT argument CVSS 8.8

SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14681 · PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL CVSS 4.2

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14680 · PostgreSQL type confusion via "internal" arguments CVSS 8.8

Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14679 · PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory CVSS 8.2

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Release-note mentions:

CVE-2026-14678 · PostgreSQL pg_trgm picksplit reads past end of buffer CVSS 4.3

Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: contrib module.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-14677 · PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14676 · PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.

Fixed in this branch: 18.6. Component: contrib module.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14673 · PostgreSQL amcheck does not clear untrusted search path CVSS 3.8

Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.

Fixed in this branch: 18.6. Component: contrib module.

Official affected-branch entry: 18.

AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14672 · PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle CVSS 5.3

Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Release-note mentions:

CVE-2026-14671 · PostgreSQL refint plan cache type confusion executes arbitrary code CVSS 8.8

Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: contrib module.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14670 · PostgreSQL plperl tied object heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14669 · PostgreSQL to_char heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14668 · PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read CVSS 8.1

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Release-note mentions:

CVE-2026-14666 · PostgreSQL row security caching disregards role modifications CVSS 4.2

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14664 · PostgreSQL regexp heap buffer overflow executes arbitrary code CVSS 8.8

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2026-14663 · PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext CVSS 6.5

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: contrib module.

Official affected-branch entry: 18.

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Release-note mentions:

CVE-2026-14662 · PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound CVSS 8.8

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Fixed in this branch: 18.6. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client CVSS 8.8

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.

No fixed version for this branch is recorded. Component: core server.

AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Release-note mentions:

CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound CVSS 5.9

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Fixed in this branch: 18.1. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Release-note mentions:

CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege CVSS 3.1

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Fixed in this branch: 18.1. Component: core server.

Official affected-branch entry: 18.

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Release-note mentions:

Export this branch as JSON · Compare any two indexed releases