PostgreSQL 18
Read the English manualCurrent stable · Recorded build 18.6 · 2026-08-13
- First stable release
- 2025-09-25
- Support end
- 2030-11-14
- Indexed releases
- 6
- Original release-note entries
- 561
Manuals & provenance
PostgreSQL 18 English manual · 1151 loaded pages.
Manual loaded 2026-09-27T00:10:47.078613.
Release entries: 2026-09-26. Security evidence: 2026-09-26. PDF links use the verified English manifest and locally available files. Lifecycle: PostgreSQL versioning policy.
Upgrade considerations
Major upgrades need a migration method such as dump/reload or pg_upgrade. Read the intervening major-release notes and the target manual. Minor updates can also require extra steps; review the specific release's migration notes. Official upgrade policy.
Compatibility notes for 18.0 · Changes from the initial release through 18.6
Original migration guidance for 18.0
A dump/restore using pg_dumpall or use of pg_upgrade or logical replication is required for those wishing to migrate data from any previous release. See Section 18.6 for general information on migrating to new major releases.
Version 18 contains a number of changes that may affect compatibility with previous releases. Observe the following incompatibilities:
Release history
Every indexed release keeps its original occurrences. CVE counts below are mentions in its notes, including follow-up corrections; they do not count newly fixed vulnerabilities.
Initial release changes
Original entries from 18.0, including feature changes and compatibility notes. Categories aid browsing; they are not upstream classifications.
210 of 210 original entries.
Change initdb default to enable data checksums Compatibility Migration
Change initdb default to enable data checksums (Greg Sabino Mullane) §
Checksums can be disabled with the new initdb option
--no-data-checksums. pg_upgrade requires matching cluster checksum settings, so this new option can be useful to upgrade non-checksum old clusters.Original release occurrence ·
18.0/migration/001Change time zone abbreviation handling Compatibility Migration
Change time zone abbreviation handling (Tom Lane) §
The system will now favor the current session's time zone abbreviations before checking the server variable timezone_abbreviations. Previously
timezone_abbreviationswas checked first.Original release occurrence ·
18.0/migration/002Deprecate MD5 password authentication Compatibility Migration
Deprecate MD5 password authentication (Nathan Bossart) §
Support for MD5 passwords will be removed in a future major version release. CREATE ROLE and ALTER ROLE now emit deprecation warnings when setting MD5 passwords. These warnings can be disabled by setting the md5_password_warnings parameter to
off.Original release occurrence ·
18.0/migration/003Change VACUUM and ANALYZE to process the inheritance children of a parent Compatibility Migration
Change VACUUM and ANALYZE to process the inheritance children of a parent (Michael Harris) §
The previous behavior can be performed by using the new
ONLYoption.Original release occurrence ·
18.0/migration/004Prevent COPY FROM from treating \. as an end-of-file marker when reading CSV files Compatibility Migration
Prevent
COPY FROMfrom treating\.as an end-of-file marker when reading CSV files (Daniel Vérité, Tom Lane) § §psql will still treat
\.as an end-of-file marker when reading CSV files fromSTDIN. Older psql clients connecting to PostgreSQL 18 servers might experience\copyproblems. This release also enforces that\.must appear alone on a line.Original release occurrence ·
18.0/migration/005Disallow unlogged partitioned tables Compatibility Migration
Disallow unlogged partitioned tables (Michael Paquier) §
Previously
ALTER TABLE SET [UN]LOGGEDdid nothing, and the creation of an unlogged partitioned table did not cause its children to be unlogged.Original release occurrence ·
18.0/migration/006Execute AFTER triggers as the role that was active when trigger events were queued Compatibility Migration
Execute
AFTERtriggers as the role that was active when trigger events were queued (Laurenz Albe) §Previously such triggers were run as the role that was active at trigger execution time (e.g., at COMMIT). This is significant for cases where the role is changed between queue time and transaction commit.
Original release occurrence ·
18.0/migration/007Remove non-functional support for rule privileges in GRANT/REVOKE Compatibility Migration
Remove non-functional support for rule privileges in GRANT/REVOKE (Fujii Masao) §
These have been non-functional since PostgreSQL 8.2.
Original release occurrence ·
18.0/migration/008Remove column pg_backend_memory_contexts.parent Compatibility Migration
Remove column
pg_backend_memory_contexts.parent(Melih Mutlu) §This is no longer needed since
pg_backend_memory_contexts.pathwas added.Original release occurrence ·
18.0/migration/009Change pg_backend_memory_contexts.level and pg_log_backend_memory_contexts() to be one-based Compatibility Migration
Change
pg_backend_memory_contexts.levelandpg_log_backend_memory_contexts()to be one-based (Melih Mutlu, Atsushi Torikoshi, David Rowley, Fujii Masao) § § §These were previously zero-based.
Original release occurrence ·
18.0/migration/010Change full text search to use the default collation provider of the cluster to read configuration files and dictionaries, rather than always using libc Compatibility Migration
Change full text search to use the default collation provider of the cluster to read configuration files and dictionaries, rather than always using libc (Peter Eisentraut) §
Clusters that default to non-libc collation providers (e.g., ICU, builtin) that behave differently than libc for characters processed by LC_CTYPE could observe changes in behavior of some full-text search functions, as well as the pg_trgm extension. When upgrading such clusters using pg_upgrade, it is recommended to reindex all indexes related to full-text search and pg_trgm after the upgrade.
Original release occurrence ·
18.0/migration/011Automatically remove some unnecessary table self-joins Features
Automatically remove some unnecessary table self-joins (Andrey Lepikhov, Alexander Kuzmenkov, Alexander Korotkov, Alena Rybakina) §
This optimization can be disabled using server variable enable_self_join_elimination.
Original release occurrence ·
18.0/changes/001Convert some IN (VALUES ...) to x = ANY ... for better optimizer statistics Features
Convert some
IN (VALUES ...)tox = ANY ...for better optimizer statistics (Alena Rybakina, Andrei Lepikhov) §Original release occurrence ·
18.0/changes/002Allow transforming OR-clauses to arrays for faster index processing Performance
Allow transforming
OR-clauses to arrays for faster index processing (Alexander Korotkov, Andrey Lepikhov) §Original release occurrence ·
18.0/changes/003Speed up the processing of INTERSECT, EXCEPT, window aggregates, and view column aliases Performance
Speed up the processing of
INTERSECT,EXCEPT, window aggregates, and view column aliases (Tom Lane, David Rowley) § § § §Original release occurrence ·
18.0/changes/004Allow the keys of SELECT DISTINCT to be internally reordered to avoid sorting Features
Allow the keys of
SELECT DISTINCTto be internally reordered to avoid sorting (Richard Guo) §This optimization can be disabled using enable_distinct_reordering.
Original release occurrence ·
18.0/changes/005Ignore GROUP BY columns that are functionally dependent on other columns Features
Ignore
GROUP BYcolumns that are functionally dependent on other columns (Zhang Mingli, Jian He, David Rowley) §If a
GROUP BYclause includes all columns of a unique index, as well as other columns of the same table, those other columns are redundant and can be dropped from the grouping. This was already true for non-deferred primary keys.Original release occurrence ·
18.0/changes/006Allow some HAVING clauses on GROUPING SETS to be pushed to WHERE clauses Features
Allow some
HAVINGclauses onGROUPING SETSto be pushed toWHEREclauses (Richard Guo) § § § §This allows earlier row filtering. This release also fixes some
GROUPING SETSqueries that used to return incorrect results.Original release occurrence ·
18.0/changes/007Improve row estimates for generate_series() using numeric and timestamp values Features
Improve row estimates for
generate_series()usingnumericandtimestampvalues (David Rowley, Song Jinzhou) § §Original release occurrence ·
18.0/changes/008Allow the optimizer to use Right Semi Join plans Features
Allow the optimizer to use
Right Semi Joinplans (Richard Guo) §Semi-joins are used when needing to find if there is at least one match.
Original release occurrence ·
18.0/changes/009Allow merge joins to use incremental sorts Features
Allow merge joins to use incremental sorts (Richard Guo) §
Original release occurrence ·
18.0/changes/010Improve the efficiency of planning queries accessing many partitions Features
Improve the efficiency of planning queries accessing many partitions (Ashutosh Bapat, Yuya Watari, David Rowley) § §
Original release occurrence ·
18.0/changes/011Allow partitionwise joins in more cases, and reduce its memory usage Features
Allow partitionwise joins in more cases, and reduce its memory usage (Richard Guo, Tom Lane, Ashutosh Bapat) § §
Original release occurrence ·
18.0/changes/012Improve cost estimates of partition queries Features
Improve cost estimates of partition queries (Nikita Malakhov, Andrei Lepikhov) §
Original release occurrence ·
18.0/changes/013Improve SQL-language function plan caching Features
Improve SQL-language function plan caching (Alexander Pyhalov, Tom Lane) § §
Original release occurrence ·
18.0/changes/014Improve handling of disabled optimizer features Features
Improve handling of disabled optimizer features (Robert Haas) §
Original release occurrence ·
18.0/changes/015Allow skip scans of btree indexes Features
Allow skip scans of btree indexes (Peter Geoghegan) § §
This allows multi-column btree indexes to be used in more cases such as when there are no restrictions on the first or early indexed columns (or there are non-equality ones), and there are useful restrictions on later indexed columns.
Original release occurrence ·
18.0/changes/016Allow non-btree unique indexes to be used as partition keys and in materialized views Features
Allow non-btree unique indexes to be used as partition keys and in materialized views (Mark Dilger) § §
The index type must still support equality.
Original release occurrence ·
18.0/changes/017Allow GIN indexes to be created in parallel Features
Original release occurrence ·
18.0/changes/018Allow values to be sorted to speed range-type GiST and btree index builds Features
Original release occurrence ·
18.0/changes/019Add an asynchronous I/O subsystem Performance
Add an asynchronous I/O subsystem (Andres Freund, Thomas Munro, Nazir Bilal Yavuz, Melanie Plageman) § § § § § § § § § § §
This feature allows backends to queue multiple read requests, which allows for more efficient sequential scans, bitmap heap scans, vacuums, etc. This is enabled by server variable io_method, with server variables io_combine_limit and io_max_combine_limit added to control it. This also enables effective_io_concurrency and maintenance_io_concurrency values greater than zero for systems without
fadvise()support. The new system viewpg_aiosshows the file handles being used for asynchronous I/O.Original release occurrence ·
18.0/changes/020Improve the locking performance of queries that access many relations Performance
Improve the locking performance of queries that access many relations (Tomas Vondra) §
Original release occurrence ·
18.0/changes/021Improve the performance and reduce memory usage of hash joins and GROUP BY Performance
Improve the performance and reduce memory usage of hash joins and
GROUP BY(David Rowley, Jeff Davis) § § § § §This also improves hash set operations used by
EXCEPT, and hash lookups of subplan values.Original release occurrence ·
18.0/changes/022Allow normal vacuums to freeze some pages, even though they are all-visible Performance
Allow normal vacuums to freeze some pages, even though they are all-visible (Melanie Plageman) § §
This reduces the overhead of later full-relation freezing. The aggressiveness of this can be controlled by server variable and per-table setting vacuum_max_eager_freeze_failure_rate. Previously vacuum never processed all-visible pages until freezing was required.
Original release occurrence ·
18.0/changes/023Add server variable vacuum_truncate to control file truncation during VACUUM Performance
Add server variable vacuum_truncate to control file truncation during VACUUM (Nathan Bossart, Gurjeet Singh) §
A storage-level parameter with the same name and behavior already existed.
Original release occurrence ·
18.0/changes/024Increase server variables effective_io_concurrency's and maintenance_io_concurrency's default values to 16 Performance
Increase server variables effective_io_concurrency's and maintenance_io_concurrency's default values to 16 (Melanie Plageman) § §
This more accurately reflects modern hardware.
Original release occurrence ·
18.0/changes/025Increase the logging granularity of server variable log_connections Features
Increase the logging granularity of server variable log_connections (Melanie Plageman) §
This server variable was previously only boolean, which is still supported.
Original release occurrence ·
18.0/changes/026Add log_connections option to report the duration of connection stages Features
Add
log_connectionsoption to report the duration of connection stages (Melanie Plageman) §Original release occurrence ·
18.0/changes/027Add log_line_prefix escape %L to output the client IP address Features
Add log_line_prefix escape
%Lto output the client IP address (Greg Sabino Mullane) §Original release occurrence ·
18.0/changes/028Add server variable log_lock_failures to log lock acquisition failures Features
Add server variable log_lock_failures to log lock acquisition failures (Yuki Seino, Fujii Masao) § §
Specifically it reports
SELECT ... NOWAITlock failures.Original release occurrence ·
18.0/changes/029Modify pg_stat_all_tables and its variants to report the time spent in VACUUM, ANALYZE, and their automatic variants Features
Modify
pg_stat_all_tablesand its variants to report the time spent in VACUUM, ANALYZE, and their automatic variants (Sami Imseih) §The new columns are
total_vacuum_time,total_autovacuum_time,total_analyze_time, andtotal_autoanalyze_time.Original release occurrence ·
18.0/changes/030Add delay time reporting to VACUUM and ANALYZE Features
Add delay time reporting to VACUUM and ANALYZE (Bertrand Drouvot, Nathan Bossart) § §
This information appears in the server log, the system views
pg_stat_progress_vacuumandpg_stat_progress_analyze, and the output of VACUUM and ANALYZE when inVERBOSEmode; tracking must be enabled with the server variable track_cost_delay_timing.Original release occurrence ·
18.0/changes/031Add WAL, CPU, and average read statistics output to ANALYZE VERBOSE Features
Original release occurrence ·
18.0/changes/032Add full WAL buffer count to VACUUM/ANALYZE (VERBOSE) and autovacuum log output Features
Add full WAL buffer count to
VACUUM/ANALYZE (VERBOSE)and autovacuum log output (Bertrand Drouvot) §Original release occurrence ·
18.0/changes/033Add per-backend I/O statistics reporting Features
Add per-backend I/O statistics reporting (Bertrand Drouvot) § §
The statistics are accessed via
pg_stat_get_backend_io(). Per-backend I/O statistics can be cleared viapg_stat_reset_backend_stats().Original release occurrence ·
18.0/changes/034Add pg_stat_io columns to report I/O activity in bytes Features
Add
pg_stat_iocolumns to report I/O activity in bytes (Nazir Bilal Yavuz) §The new columns are
read_bytes,write_bytes, andextend_bytes. Theop_bytescolumn, which always equaledBLCKSZ, has been removed.Original release occurrence ·
18.0/changes/035Add WAL I/O activity rows to pg_stat_io Features
Add WAL I/O activity rows to
pg_stat_io(Nazir Bilal Yavuz, Bertrand Drouvot, Michael Paquier) § § §This includes WAL receiver activity and a wait event for such writes.
Original release occurrence ·
18.0/changes/036Change server variable track_wal_io_timing to control tracking WAL timing in pg_stat_io instead of pg_stat_wal Features
Change server variable track_wal_io_timing to control tracking WAL timing in
pg_stat_ioinstead ofpg_stat_wal(Bertrand Drouvot) §Original release occurrence ·
18.0/changes/037Remove read/sync columns from pg_stat_wal Features
Remove read/sync columns from
pg_stat_wal(Bertrand Drouvot) § §This removes columns
wal_write,wal_sync,wal_write_time, andwal_sync_time.Original release occurrence ·
18.0/changes/038Add function pg_stat_get_backend_wal() to return per-backend WAL statistics Features
Add function
pg_stat_get_backend_wal()to return per-backend WAL statistics (Bertrand Drouvot) §Per-backend WAL statistics can be cleared via
pg_stat_reset_backend_stats().Original release occurrence ·
18.0/changes/039Add function pg_ls_summariesdir() to specifically list the contents of PGDATA/pg_wal/summaries Features
Add function
pg_ls_summariesdir()to specifically list the contents ofPGDATA/pg_wal/summaries(Yushi Ogiwara) §Original release occurrence ·
18.0/changes/040Add column pg_stat_checkpointer.num_done to report the number of completed checkpoints Features
Add column
pg_stat_checkpointer.num_doneto report the number of completed checkpoints (Anton A. Melnikov) §Columns
num_timedandnum_requestedcount both completed and skipped checkpoints.Original release occurrence ·
18.0/changes/041Add column pg_stat_checkpointer.slru_written to report SLRU buffers written Features
Add column
pg_stat_checkpointer.slru_writtento report SLRU buffers written (Nitin Jadhav) §Also, modify the checkpoint server log message to report separate shared buffer and SLRU buffer values.
Original release occurrence ·
18.0/changes/042Add columns to pg_stat_database to report parallel worker activity Features
Add columns to
pg_stat_databaseto report parallel worker activity (Benoit Lobréau) §The new columns are
parallel_workers_to_launchandparallel_workers_launched.Original release occurrence ·
18.0/changes/043Have query id computation of constant lists consider only the first and last constants Features
Have query id computation of constant lists consider only the first and last constants (Dmitry Dolgov, Sami Imseih) § § §
Jumbling is used by pg_stat_statements.
Original release occurrence ·
18.0/changes/044Adjust query id computations to group together queries using the same relation name Features
Adjust query id computations to group together queries using the same relation name (Michael Paquier, Sami Imseih) §
This is true even if the tables in different schemas have different column names.
Original release occurrence ·
18.0/changes/045Add column pg_backend_memory_contexts.type to report the type of memory context Features
Add column
pg_backend_memory_contexts.typeto report the type of memory context (David Rowley) §Original release occurrence ·
18.0/changes/046Add column pg_backend_memory_contexts.path to show memory context parents Features
Add column
pg_backend_memory_contexts.pathto show memory context parents (Melih Mutlu) §Original release occurrence ·
18.0/changes/047Add function pg_get_acl() to retrieve database access control details Features
Add function
pg_get_acl()to retrieve database access control details (Joel Jacobson) § §Original release occurrence ·
18.0/changes/048Add function has_largeobject_privilege() to check large object privileges Features
Add function
has_largeobject_privilege()to check large object privileges (Yugo Nagata) §Original release occurrence ·
18.0/changes/049Allow ALTER DEFAULT PRIVILEGES to define large object default privileges Features
Allow ALTER DEFAULT PRIVILEGES to define large object default privileges (Takatsuka Haruka, Yugo Nagata, Laurenz Albe) §
Original release occurrence ·
18.0/changes/050Add predefined role pg_signal_autovacuum_worker Features
Add predefined role
pg_signal_autovacuum_worker(Kirill Reshke) §This allows sending signals to autovacuum workers.
Original release occurrence ·
18.0/changes/051Add support for the OAuth authentication method Features
Add support for the OAuth authentication method (Jacob Champion, Daniel Gustafsson, Thomas Munro) §
This adds an
oauthauthentication method topg_hba.conf, libpq OAuth options, a server variable oauth_validator_libraries to load token validation libraries, and a configure flag--with-libcurlto add the required compile-time libraries.Original release occurrence ·
18.0/changes/052Add server variable ssl_tls13_ciphers to allow specification of multiple colon-separated TLSv1.3 cipher suites Features
Add server variable ssl_tls13_ciphers to allow specification of multiple colon-separated TLSv1.3 cipher suites (Erica Zhang, Daniel Gustafsson) §
Original release occurrence ·
18.0/changes/053Change server variable ssl_groups's default to include elliptic curve X25519 Features
Change server variable ssl_groups's default to include elliptic curve X25519 (Daniel Gustafsson, Jacob Champion) §
Original release occurrence ·
18.0/changes/054Rename server variable ssl_ecdh_curve to ssl_groups and allow multiple colon-separated ECDH curves to be specified Features
Rename server variable
ssl_ecdh_curveto ssl_groups and allow multiple colon-separated ECDH curves to be specified (Erica Zhang, Daniel Gustafsson) §The previous name still works.
Original release occurrence ·
18.0/changes/055Make cancel request keys 256 bits Features
Make cancel request keys 256 bits (Heikki Linnakangas, Jelte Fennema-Nio) § §
This is only possible when the server and client support wire protocol version 3.2, introduced in this release.
Original release occurrence ·
18.0/changes/056Add server variable autovacuum_worker_slots to specify the maximum number of background workers Features
Add server variable autovacuum_worker_slots to specify the maximum number of background workers (Nathan Bossart) §
With this variable set, autovacuum_max_workers can be adjusted at runtime up to this maximum without a server restart.
Original release occurrence ·
18.0/changes/057Allow specification of the fixed number of dead tuples that will trigger an autovacuum Bug fixes
Allow specification of the fixed number of dead tuples that will trigger an autovacuum (Nathan Bossart, Frédéric Yhuel) §
The server variable is autovacuum_vacuum_max_threshold. Percentages are still used for triggering.
Original release occurrence ·
18.0/changes/058Change server variable max_files_per_process to limit only files opened by a backend Features
Change server variable max_files_per_process to limit only files opened by a backend (Andres Freund) §
Previously files opened by the postmaster were also counted toward this limit.
Original release occurrence ·
18.0/changes/059Add server variable num_os_semaphores to report the required number of semaphores Features
Add server variable num_os_semaphores to report the required number of semaphores (Nathan Bossart) §
This is useful for operating system configuration.
Original release occurrence ·
18.0/changes/060Add server variable extension_control_path to specify the location of extension control files Features
Add server variable extension_control_path to specify the location of extension control files (Peter Eisentraut, Matheus Alcantara) § §
Original release occurrence ·
18.0/changes/061Allow inactive replication slots to be automatically invalidated using server variable idle_replication_slot_timeout Features
Allow inactive replication slots to be automatically invalidated using server variable idle_replication_slot_timeout (Nisha Moond, Bharath Rupireddy) §
Original release occurrence ·
18.0/changes/062Add server variable max_active_replication_origins to control the maximum active replication origins Features
Add server variable max_active_replication_origins to control the maximum active replication origins (Euler Taveira) §
This was previously controlled by max_replication_slots, but this new setting allows a higher origin count in cases where fewer slots are required.
Original release occurrence ·
18.0/changes/063Allow the values of generated columns to be logically replicated Features
Allow the values of generated columns to be logically replicated (Shubham Khanna, Vignesh C, Zhijie Hou, Shlok Kyal, Peter Smith) § § § §
If the publication specifies a column list, all specified columns, generated and non-generated, are published. Without a specified column list, publication option
publish_generated_columnscontrols whether generated columns are published. Previously generated columns were not replicated and the subscriber had to compute the values if possible; this is particularly useful for non-PostgreSQL subscribers which lack such a capability.Original release occurrence ·
18.0/changes/064Change the default CREATE SUBSCRIPTION streaming option from off to parallel Features
Change the default CREATE SUBSCRIPTION streaming option from
offtoparallel(Vignesh C) §Original release occurrence ·
18.0/changes/065Allow ALTER SUBSCRIPTION to change the replication slot's two-phase commit behavior Features
Allow ALTER SUBSCRIPTION to change the replication slot's two-phase commit behavior (Hayato Kuroda, Ajin Cherian, Amit Kapila, Zhijie Hou) § §
Original release occurrence ·
18.0/changes/066Log conflicts while applying logical replication changes Features
Log conflicts while applying logical replication changes (Zhijie Hou, Nisha Moond) § § § § §
Also report in new columns of
pg_stat_subscription_stats.Original release occurrence ·
18.0/changes/067Allow generated columns to be virtual, and make them the default Features
Allow generated columns to be virtual, and make them the default (Peter Eisentraut, Jian He, Richard Guo, Dean Rasheed) § § §
Virtual generated columns generate their values when the columns are read, not written. The write behavior can still be specified via the
STOREDoption.Original release occurrence ·
18.0/changes/068Add OLD/NEW support to RETURNING in DML queries Features
Add
OLD/NEWsupport toRETURNINGin DML queries (Dean Rasheed) §Previously
RETURNINGonly returned new values for INSERT and UPDATE, and old values for DELETE; MERGE would return the appropriate value for the internal query executed. This new syntax allows theRETURNINGlist ofINSERT/UPDATE/DELETE/MERGEto explicitly return old and new values by using the special aliasesoldandnew. These aliases can be renamed to avoid identifier conflicts.Original release occurrence ·
18.0/changes/069Allow foreign tables to be created like existing local tables Features
Allow foreign tables to be created like existing local tables (Zhang Mingli) §
The syntax is
CREATE FOREIGN TABLE ... LIKE.Original release occurrence ·
18.0/changes/070Allow LIKE with nondeterministic collations Features
Allow
LIKEwith nondeterministic collations (Peter Eisentraut) §Original release occurrence ·
18.0/changes/071Allow text position search functions with nondeterministic collations Features
Allow text position search functions with nondeterministic collations (Peter Eisentraut) §
These used to generate an error.
Original release occurrence ·
18.0/changes/072Add builtin collation provider PG_UNICODE_FAST Features
Add builtin collation provider
PG_UNICODE_FAST(Jeff Davis) §This locale supports case mapping, but sorts in code point order, not natural language order.
Original release occurrence ·
18.0/changes/073Allow VACUUM and ANALYZE to process partitioned tables without processing their children Features
Allow VACUUM and ANALYZE to process partitioned tables without processing their children (Michael Harris) §
This is enabled with the new
ONLYoption. This is useful since autovacuum does not process partitioned tables, just its children.Original release occurrence ·
18.0/changes/074Add functions to modify per-relation and per-column optimizer statistics Features
Add functions to modify per-relation and per-column optimizer statistics (Corey Huinker) § § §
The functions are
pg_restore_relation_stats(),pg_restore_attribute_stats(),pg_clear_relation_stats(), andpg_clear_attribute_stats().Original release occurrence ·
18.0/changes/075Add server variable file_copy_method to control the file copying method Features
Add server variable file_copy_method to control the file copying method (Nazir Bilal Yavuz) §
This controls whether
CREATE DATABASE ... STRATEGY=FILE_COPYandALTER DATABASE ... SET TABLESPACEuses file copy or clone.Original release occurrence ·
18.0/changes/076Allow the specification of non-overlapping PRIMARY KEY, UNIQUE, and foreign key constraints Features
Allow the specification of non-overlapping
PRIMARY KEY,UNIQUE, and foreign key constraints (Paul A. Jungwirth) § §This is specified by
WITHOUT OVERLAPSforPRIMARY KEYandUNIQUE, and byPERIODfor foreign keys, all applied to the last specified column.Original release occurrence ·
18.0/changes/077Allow CHECK and foreign key constraints to be specified as NOT ENFORCED Features
Allow
CHECKand foreign key constraints to be specified asNOT ENFORCED(Amul Sul) § §This also adds column
pg_constraint.conenforced.Original release occurrence ·
18.0/changes/078Require primary/foreign key relationships to use either deterministic collations or the the same nondeterministic collations Features
Require primary/foreign key relationships to use either deterministic collations or the the same nondeterministic collations (Peter Eisentraut) §
The restore of a pg_dump, also used by pg_upgrade, will fail if these requirements are not met; schema changes must be made for these upgrade methods to succeed.
Original release occurrence ·
18.0/changes/079Store column NOT NULL specifications in pg_constraint Features
Store column
NOT NULLspecifications inpg_constraint(Álvaro Herrera, Bernd Helmle) § §This allows names to be specified for
NOT NULLconstraint. This also addsNOT NULLconstraints to foreign tables andNOT NULLinheritance control to local tables.Original release occurrence ·
18.0/changes/080Allow ALTER TABLE to set the NOT VALID attribute of NOT NULL constraints Features
Allow ALTER TABLE to set the
NOT VALIDattribute ofNOT NULLconstraints (Rushabh Lathia, Jian He) §Original release occurrence ·
18.0/changes/081Allow modification of the inheritability of NOT NULL constraints Features
Allow modification of the inheritability of
NOT NULLconstraints (Suraj Kharage, Álvaro Herrera) § §The syntax is
ALTER TABLE ... ALTER CONSTRAINT ... [NO] INHERIT.Original release occurrence ·
18.0/changes/082Allow NOT VALID foreign key constraints on partitioned tables Features
Allow
NOT VALIDforeign key constraints on partitioned tables (Amul Sul) §Original release occurrence ·
18.0/changes/083Allow dropping of constraints ONLY on partitioned tables Features
Allow dropping of constraints
ONLYon partitioned tables (Álvaro Herrera) §This was previously erroneously prohibited.
Original release occurrence ·
18.0/changes/084Add REJECT_LIMIT to control the number of invalid rows COPY FROM can ignore Features
Add
REJECT_LIMITto control the number of invalid rowsCOPY FROMcan ignore (Atsushi Torikoshi) §This is available when
ON_ERROR = 'ignore'.Original release occurrence ·
18.0/changes/085Allow COPY TO to copy rows from populated materialized views Features
Allow
COPY TOto copy rows from populated materialized views (Jian He) §Original release occurrence ·
18.0/changes/086Add COPY LOG_VERBOSITY level silent to suppress log output of ignored rows Features
Add
COPYLOG_VERBOSITYlevelsilentto suppress log output of ignored rows (Atsushi Torikoshi) §This new level suppresses output for discarded input rows when
on_error = 'ignore'.Original release occurrence ·
18.0/changes/087Disallow COPY FREEZE on foreign tables Features
Disallow
COPY FREEZEon foreign tables (Nathan Bossart) §Previously, the
COPYworked but theFREEZEwas ignored, so disallow this command.Original release occurrence ·
18.0/changes/088Automatically include BUFFERS output in EXPLAIN ANALYZE Features
Automatically include
BUFFERSoutput inEXPLAIN ANALYZE(Guillaume Lelarge, David Rowley) §Original release occurrence ·
18.0/changes/089Add full WAL buffer count to EXPLAIN (WAL) output Features
Add full WAL buffer count to
EXPLAIN (WAL)output (Bertrand Drouvot) §Original release occurrence ·
18.0/changes/090In EXPLAIN ANALYZE, report the number of index lookups used per index scan node Features
In
EXPLAIN ANALYZE, report the number of index lookups used per index scan node (Peter Geoghegan) §Original release occurrence ·
18.0/changes/091Modify EXPLAIN to output fractional row counts Features
Original release occurrence ·
18.0/changes/092Add memory and disk usage details to Material, Window Aggregate, and common table expression nodes to EXPLAIN output Features
Add memory and disk usage details to
Material,Window Aggregate, and common table expression nodes toEXPLAINoutput (David Rowley, Tatsuo Ishii) § § § §Original release occurrence ·
18.0/changes/093Add details about window function arguments to EXPLAIN output Features
Add details about window function arguments to
EXPLAINoutput (Tom Lane) §Original release occurrence ·
18.0/changes/094Add Parallel Bitmap Heap Scan worker cache statistics to EXPLAIN ANALYZE Features
Add
Parallel Bitmap Heap Scanworker cache statistics toEXPLAIN ANALYZE(David Geier, Heikki Linnakangas, Donghang Lin, Alena Rybakina, David Rowley) §Original release occurrence ·
18.0/changes/095Indicate disabled nodes in EXPLAIN ANALYZE output Features
Original release occurrence ·
18.0/changes/096Improve Unicode full case mapping and conversion Features
Improve Unicode full case mapping and conversion (Jeff Davis) § §
This adds the ability to do conditional and title case mapping, and case map single characters to multiple characters.
Original release occurrence ·
18.0/changes/097Allow jsonb null values to be cast to scalar types as NULL Features
Allow
jsonbnullvalues to be cast to scalar types asNULL(Tom Lane) §Previously such casts generated an error.
Original release occurrence ·
18.0/changes/098Add optional parameter to json{b}_strip_nulls to allow removal of null array elements Features
Add optional parameter to
json{b}_strip_nullsto allow removal of null array elements (Florents Tselai) §Original release occurrence ·
18.0/changes/099Add function array_sort() which sorts an array's first dimension Features
Add function
array_sort()which sorts an array's first dimension (Junwang Zhao, Jian He) §Original release occurrence ·
18.0/changes/100Add function array_reverse() which reverses an array's first dimension Features
Add function
array_reverse()which reverses an array's first dimension (Aleksander Alekseev) §Original release occurrence ·
18.0/changes/101Add function reverse() to reverse bytea bytes Features
Original release occurrence ·
18.0/changes/102Allow casting between integer types and bytea Features
Allow casting between integer types and
bytea(Aleksander Alekseev) §The integer values are stored as
byteatwo's complement values.Original release occurrence ·
18.0/changes/103Update Unicode data to Unicode 16.0.0 Features
Original release occurrence ·
18.0/changes/104Add full text search stemming for Estonian Features
Original release occurrence ·
18.0/changes/105Improve the XML error codes to more closely match the SQL standard Features
Improve the
XMLerror codes to more closely match the SQL standard (Tom Lane) §These errors are reported via
SQLSTATE.Original release occurrence ·
18.0/changes/106Add function casefold() to allow for more sophisticated case-insensitive matching Features
Add function
casefold()to allow for more sophisticated case-insensitive matching (Jeff Davis) §This allows more accurate comparisons, i.e., a character can have multiple upper or lower case equivalents, or upper or lower case conversion changes the number of characters.
Original release occurrence ·
18.0/changes/107Allow MIN()/MAX() aggregates on arrays and composite types Features
Original release occurrence ·
18.0/changes/108Add a WEEK option to EXTRACT() Features
Original release occurrence ·
18.0/changes/109Improve the output EXTRACT(QUARTER ...) for negative values Features
Improve the output
EXTRACT(QUARTER ...)for negative values (Tom Lane) §Original release occurrence ·
18.0/changes/110Add roman numeral support to to_number() Features
Add roman numeral support to
to_number()(Hunaid Sohail) §This is accessed via the
RNpattern.Original release occurrence ·
18.0/changes/111Add UUID version 7 generation function uuidv7() Features
Add
UUIDversion 7 generation functionuuidv7()(Andrey Borodin) §This
UUIDvalue is temporally sortable. Function aliasuuidv4()has been added to explicitly generate version 4 UUIDs.Original release occurrence ·
18.0/changes/112Add functions crc32() and crc32c() to compute CRC values Features
Original release occurrence ·
18.0/changes/113Add math functions gamma() and lgamma() Features
Original release occurrence ·
18.0/changes/114Allow => syntax for named cursor arguments in PL/pgSQL Features
Allow
=>syntax for named cursor arguments in PL/pgSQL (Pavel Stehule) §We previously only accepted
:=.Original release occurrence ·
18.0/changes/115Allow regexp_match[es]()/regexp_like()/regexp_replace()/regexp_count()/regexp_instr()/regexp_substr()/regexp_split_to_table()/regexp_split_to_array() to use named arguments Features
Allow
regexp_match[es]()/regexp_like()/regexp_replace()/regexp_count()/regexp_instr()/regexp_substr()/regexp_split_to_table()/regexp_split_to_array()to use named arguments (Jian He) §Original release occurrence ·
18.0/changes/116Add function PQfullProtocolVersion() to report the full, including minor, protocol version number Features
Add function
PQfullProtocolVersion()to report the full, including minor, protocol version number (Jacob Champion, Jelte Fennema-Nio) §Original release occurrence ·
18.0/changes/117Add libpq connection parameters and environment variables to specify the minimum and maximum acceptable protocol version for connections Features
Add libpq connection parameters and environment variables to specify the minimum and maximum acceptable protocol version for connections (Jelte Fennema-Nio) § §
Original release occurrence ·
18.0/changes/118Report search_path changes to the client Features
Report search_path changes to the client (Alexander Kukushkin, Jelte Fennema-Nio, Tomas Vondra) § §
Original release occurrence ·
18.0/changes/119Add libpq connection parameter sslkeylogfile which dumps out SSL key material Features
Add libpq connection parameter
sslkeylogfilewhich dumps out SSL key material (Abhishek Chanda, Daniel Gustafsson) §This is useful for debugging.
Original release occurrence ·
18.0/changes/121Modify some libpq function signatures to use int64_t Features
Modify some libpq function signatures to use
int64_t(Thomas Munro) §These previously used
pg_int64, which is now deprecated.Original release occurrence ·
18.0/changes/122Allow psql to parse, bind, and close named prepared statements Features
Allow psql to parse, bind, and close named prepared statements (Anthonin Bonnefoy, Michael Paquier) § §
This is accomplished with new commands
\parse,\bind_named, and\close_prepared.Original release occurrence ·
18.0/changes/123Add psql backslash commands to allowing issuance of pipeline queries Features
Add psql backslash commands to allowing issuance of pipeline queries (Anthonin Bonnefoy) § § §
The new commands are
\startpipeline,\syncpipeline,\sendpipeline,\endpipeline,\flushrequest,\flush, and\getresults.Original release occurrence ·
18.0/changes/124Allow adding pipeline status to the psql prompt and add related state variables Features
Allow adding pipeline status to the psql prompt and add related state variables (Anthonin Bonnefoy) §
The new prompt character is
%Pand the new psql variables arePIPELINE_SYNC_COUNT,PIPELINE_COMMAND_COUNT, andPIPELINE_RESULT_COUNT.Original release occurrence ·
18.0/changes/125Allow adding the connection service name to the psql prompt or access it via psql variable Features
Allow adding the connection service name to the psql prompt or access it via psql variable (Michael Banck) §
Original release occurrence ·
18.0/changes/126Add psql option to use expanded mode on all list commands Features
Add psql option to use expanded mode on all list commands (Dean Rasheed) §
Adding backslash suffix
xenables this.Original release occurrence ·
18.0/changes/127Change psql's \conninfo to use tabular format and include more information Features
Change psql's
\conninfoto use tabular format and include more information (Álvaro Herrera, Maiquel Grassi, Hunaid Sohail) §Original release occurrence ·
18.0/changes/128Add function's leakproof indicator to psql's \df+, \do+, \dAo+, and \dC+ outputs Features
Original release occurrence ·
18.0/changes/129Add access method details for partitioned relations in \dP+ Features
Original release occurrence ·
18.0/changes/130Add default_version to the psql \dx extension output Features
Original release occurrence ·
18.0/changes/131Add psql variable WATCH_INTERVAL to set the default \watch wait time Features
Add psql variable
WATCH_INTERVALto set the default\watchwait time (Daniel Gustafsson) §Original release occurrence ·
18.0/changes/132Change initdb to default to enabling checksums Features
Change initdb to default to enabling checksums (Greg Sabino Mullane) § §
The new initdb option
--no-data-checksumsdisables checksums.Original release occurrence ·
18.0/changes/133Add initdb option --no-sync-data-files to avoid syncing heap/index files Features
Add initdb option
--no-sync-data-filesto avoid syncing heap/index files (Nathan Bossart) §initdb option
--no-syncis still available to avoid syncing any files.Original release occurrence ·
18.0/changes/134Add vacuumdb option --missing-stats-only to compute only missing optimizer statistics Features
Add vacuumdb option
--missing-stats-onlyto compute only missing optimizer statistics (Corey Huinker, Nathan Bossart) § §This option can only be run by superusers and can only be used with options
--analyze-onlyand--analyze-in-stages.Original release occurrence ·
18.0/changes/135Add pg_combinebackup option -k/--link to enable hard linking Features
Add pg_combinebackup option
-k/--linkto enable hard linking (Israel Barth Rubio, Robert Haas) §Only some files can be hard linked. This should not be used if the backups will be used independently.
Original release occurrence ·
18.0/changes/136Allow pg_verifybackup to verify tar-format backups Features
Allow pg_verifybackup to verify tar-format backups (Amul Sul) §
Original release occurrence ·
18.0/changes/137If pg_rewind's --source-server specifies a database name, use it in --write-recovery-conf output Features
If pg_rewind's
--source-serverspecifies a database name, use it in--write-recovery-confoutput (Masahiko Sawada) §Original release occurrence ·
18.0/changes/138Add pg_resetwal option --char-signedness to change the default char signedness Features
Add pg_resetwal option
--char-signednessto change the defaultcharsignedness (Masahiko Sawada) §Original release occurrence ·
18.0/changes/139Add pg_dump option --statistics Features
Original release occurrence ·
18.0/changes/140Add pg_dump and pg_dumpall option --sequence-data to dump sequence data that would normally be excluded Features
Add pg_dump and pg_dumpall option
--sequence-datato dump sequence data that would normally be excluded (Nathan Bossart) § §Original release occurrence ·
18.0/changes/141Add pg_dump, pg_dumpall, and pg_restore options --statistics-only, --no-statistics, --no-data, and --no-schema Features
Add pg_dump, pg_dumpall, and pg_restore options
--statistics-only,--no-statistics,--no-data, and--no-schema(Corey Huinker, Jeff Davis) §Original release occurrence ·
18.0/changes/142Add option --no-policies to disable row level security policy processing in pg_dump, pg_dumpall, pg_restore Features
Add option
--no-policiesto disable row level security policy processing in pg_dump, pg_dumpall, pg_restore (Nikolay Samokhvalov) §This is useful for migrating to systems with different policies.
Original release occurrence ·
18.0/changes/143Allow pg_upgrade to preserve optimizer statistics Features
Allow pg_upgrade to preserve optimizer statistics (Corey Huinker, Jeff Davis, Nathan Bossart) § § § §
Extended statistics are not preserved. Also add pg_upgrade option
--no-statisticsto disable statistics preservation.Original release occurrence ·
18.0/changes/144Add pg_upgrade option --swap to swap directories rather than copy, clone, or link files Features
Add pg_upgrade option
--swapto swap directories rather than copy, clone, or link files (Nathan Bossart) §This mode is potentially the fastest.
Original release occurrence ·
18.0/changes/146Add pg_upgrade option --set-char-signedness to set the default char signedness of new cluster Features
Add pg_upgrade option
--set-char-signednessto set the defaultcharsignedness of new cluster (Masahiko Sawada) § §This is to handle cases where a pre-PostgreSQL 18 cluster's default CPU signedness does not match the new cluster.
Original release occurrence ·
18.0/changes/147Add pg_createsubscriber option --all to create logical replicas for all databases Features
Add pg_createsubscriber option
--allto create logical replicas for all databases (Shubham Khanna) §Original release occurrence ·
18.0/changes/148Add pg_createsubscriber option --clean to remove publications Features
Original release occurrence ·
18.0/changes/149Add pg_createsubscriber option --enable-two-phase to enable prepared transactions Features
Add pg_createsubscriber option
--enable-two-phaseto enable prepared transactions (Shubham Khanna) §Original release occurrence ·
18.0/changes/150Add pg_recvlogical option --enable-failover to specify failover slots Features
Add pg_recvlogical option
--enable-failoverto specify failover slots (Hayato Kuroda) §Also add option
--enable-two-phaseas a synonym for--two-phase, and deprecate the latter.Original release occurrence ·
18.0/changes/151Allow pg_recvlogical --drop-slot to work without --dbname Features
Allow pg_recvlogical
--drop-slotto work without--dbname(Hayato Kuroda) §Original release occurrence ·
18.0/changes/152Separate the loading and running of injection points Features
Separate the loading and running of injection points (Michael Paquier, Heikki Linnakangas) § §
Injection points can now be created, but not run, via
INJECTION_POINT_LOAD(), and such injection points can be run viaINJECTION_POINT_CACHED().Original release occurrence ·
18.0/changes/153Support runtime arguments in injection points Features
Support runtime arguments in injection points (Michael Paquier) §
Original release occurrence ·
18.0/changes/154Allow inline injection point test code with IS_INJECTION_POINT_ATTACHED() Features
Allow inline injection point test code with
IS_INJECTION_POINT_ATTACHED()(Heikki Linnakangas) §Original release occurrence ·
18.0/changes/155Improve the performance of processing long JSON strings using SIMD (Single Instruction Multiple Data) Performance
Improve the performance of processing long
JSONstrings using SIMD (Single Instruction Multiple Data) (David Rowley) §Original release occurrence ·
18.0/changes/156Speed up CRC32C calculations using x86 AVX-512 instructions Performance
Speed up CRC32C calculations using x86 AVX-512 instructions (Raghuveer Devulapalli, Paul Amonson) §
Original release occurrence ·
18.0/changes/157Add ARM Neon and SVE CPU intrinsics for popcount (integer bit counting) Features
Add ARM Neon and SVE CPU intrinsics for popcount (integer bit counting) (Chiranmoy Bhattacharya, Devanga Susmitha, Rama Malladi) § §
Original release occurrence ·
18.0/changes/158Improve the speed of numeric multiplication and division Features
Original release occurrence ·
18.0/changes/159Add configure option --with-libnuma to enable NUMA awareness Features
Add configure option
--with-libnumato enable NUMA awareness (Jakub Wartak, Bertrand Drouvot) § § §The function
pg_numa_available()reports on NUMA awareness, and system viewspg_shmem_allocations_numaandpg_buffercache_numawhich report on shared memory distribution across NUMA nodes.Original release occurrence ·
18.0/changes/160Add TOAST table to pg_index to allow for very large expression indexes Features
Original release occurrence ·
18.0/changes/161Remove column pg_attribute.attcacheoff Features
Remove column
pg_attribute.attcacheoff(David Rowley) §Original release occurrence ·
18.0/changes/162Add column pg_class.relallfrozen Features
Original release occurrence ·
18.0/changes/163Add amgettreeheight, amconsistentequality, and amconsistentordering to the index access method API Features
Add
amgettreeheight,amconsistentequality, andamconsistentorderingto the index access method API (Mark Dilger) § §Original release occurrence ·
18.0/changes/164Add GiST support function stratnum() Features
Add GiST support function
stratnum()(Paul A. Jungwirth) §Original release occurrence ·
18.0/changes/165Record the default CPU signedness of char in pg_controldata Features
Record the default CPU signedness of
charin pg_controldata (Masahiko Sawada) §Original release occurrence ·
18.0/changes/166Add support for Python "Limited API" in PL/Python Features
Add support for Python "Limited API" in PL/Python (Peter Eisentraut) § §
This helps prevent problems caused by Python 3.x version mismatches.
Original release occurrence ·
18.0/changes/167Change the minimum supported Python version to 3.6.8 Features
Change the minimum supported Python version to 3.6.8 (Jacob Champion) §
Original release occurrence ·
18.0/changes/168Remove support for OpenSSL versions older than 1.1.1 Features
Original release occurrence ·
18.0/changes/169If LLVM is enabled, require version 14 or later Features
If LLVM is enabled, require version 14 or later (Thomas Munro) §
Original release occurrence ·
18.0/changes/170Add macro PG_MODULE_MAGIC_EXT to allow extensions to report their name and version Features
Add macro
PG_MODULE_MAGIC_EXTto allow extensions to report their name and version (Andrei Lepikhov) §This information can be access via the new function
pg_get_loaded_modules().Original release occurrence ·
18.0/changes/171Document that SPI_connect()/SPI_connect_ext() always returns success (SPI_OK_CONNECT) Features
Document that
SPI_connect()/SPI_connect_ext()always returns success (SPI_OK_CONNECT) (Stepan Neretin) §Errors are always reported via
ereport().Original release occurrence ·
18.0/changes/172Add documentation section about API and ABI compatibility Features
Add documentation section about API and ABI compatibility (David Wheeler, Peter Eisentraut) §
Original release occurrence ·
18.0/changes/173Remove the experimental designation of Meson builds on Windows Features
Remove the experimental designation of Meson builds on Windows (Aleksander Alekseev) §
Original release occurrence ·
18.0/changes/174Remove configure options --disable-spinlocks and --disable-atomics Features
Remove configure options
--disable-spinlocksand--disable-atomics(Thomas Munro) § §Thirty-two-bit atomic operations are now required.
Original release occurrence ·
18.0/changes/175Remove support for the HPPA/PA-RISC architecture Features
Remove support for the HPPA/PA-RISC architecture (Tom Lane) §
Original release occurrence ·
18.0/changes/176Add extension pg_logicalinspect to inspect logical snapshots Features
Add extension pg_logicalinspect to inspect logical snapshots (Bertrand Drouvot) §
Original release occurrence ·
18.0/changes/177Add extension pg_overexplain which adds debug details to EXPLAIN output Features
Add extension pg_overexplain which adds debug details to
EXPLAINoutput (Robert Haas) §Original release occurrence ·
18.0/changes/178Add output columns to postgres_fdw_get_connections() Features
Add output columns to
postgres_fdw_get_connections()(Hayato Kuroda, Sagar Dilip Shedge) § § § §New output column
used_in_xactindicates if the foreign data wrapper is being used by a current transaction,closedindicates if it is closed,user_nameindicates the user name, andremote_backend_pidindicates the remote backend process identifier.Original release occurrence ·
18.0/changes/179Allow SCRAM authentication from the client to be passed to postgres_fdw servers Features
Allow SCRAM authentication from the client to be passed to postgres_fdw servers (Matheus Alcantara, Peter Eisentraut) §
This avoids storing postgres_fdw authentication information in the database, and is enabled with the postgres_fdw
use_scram_passthroughconnection option. libpq uses new connection parameters scram_client_key and scram_server_key.Original release occurrence ·
18.0/changes/180Allow SCRAM authentication from the client to be passed to dblink servers Features
Original release occurrence ·
18.0/changes/181Add on_error and log_verbosity options to file_fdw Features
Add
on_errorandlog_verbosityoptions to file_fdw (Atsushi Torikoshi) §These control how file_fdw handles and reports invalid file rows.
Original release occurrence ·
18.0/changes/182Add reject_limit to control the number of invalid rows file_fdw can ignore Features
Add
reject_limitto control the number of invalid rows file_fdw can ignore (Atsushi Torikoshi) §This is active when
ON_ERROR = 'ignore'.Original release occurrence ·
18.0/changes/183Add configurable variable min_password_length to passwordcheck Features
Add configurable variable
min_password_lengthto passwordcheck (Emanuele Musella, Maurizio Boriani) §This controls the minimum password length.
Original release occurrence ·
18.0/changes/184Have pgbench report the number of failed, retried, or skipped transactions in per-script reports Features
Have pgbench report the number of failed, retried, or skipped transactions in per-script reports (Yugo Nagata) §
Original release occurrence ·
18.0/changes/185Add isn server variable weak to control invalid check digit acceptance Features
Add isn server variable
weakto control invalid check digit acceptance (Viktor Holmberg) §This was previously only controlled by function
isn_weak().Original release occurrence ·
18.0/changes/186Allow values to be sorted to speed btree_gist index builds Features
Allow values to be sorted to speed btree_gist index builds (Bernd Helmle, Andrey Borodin) §
Original release occurrence ·
18.0/changes/187Add amcheck check function gin_index_check() to verify GIN indexes Features
Add amcheck check function
gin_index_check()to verifyGINindexes (Grigory Kryachko, Heikki Linnakangas, Andrey Borodin) §Original release occurrence ·
18.0/changes/188Add functions pg_buffercache_evict_relation() and pg_buffercache_evict_all() to evict unpinned shared buffers Features
Add functions
pg_buffercache_evict_relation()andpg_buffercache_evict_all()to evict unpinned shared buffers (Nazir Bilal Yavuz) §The existing function
pg_buffercache_evict()now returns the buffer flush status.Original release occurrence ·
18.0/changes/189Allow extensions to install custom EXPLAIN options Features
Original release occurrence ·
18.0/changes/190Allow extensions to use the server's cumulative statistics API Features
Original release occurrence ·
18.0/changes/191Allow the queries of CREATE TABLE AS and DECLARE to be tracked by pg_stat_statements Features
Allow the queries of CREATE TABLE AS and DECLARE to be tracked by pg_stat_statements (Anthonin Bonnefoy) §
They are also now assigned query ids.
Original release occurrence ·
18.0/changes/192Allow the parameterization of SET values in pg_stat_statements Features
Allow the parameterization of SET values in pg_stat_statements (Greg Sabino Mullane, Michael Paquier) §
This reduces the bloat caused by
SETstatements with differing constants.Original release occurrence ·
18.0/changes/193Add pg_stat_statements columns to report parallel activity Features
Add
pg_stat_statementscolumns to report parallel activity (Guillaume Lelarge) §The new columns are
parallel_workers_to_launchandparallel_workers_launched.Original release occurrence ·
18.0/changes/194Add pg_stat_statements.wal_buffers_full to report full WAL buffers Features
Add
pg_stat_statements.wal_buffers_fullto report full WAL buffers (Bertrand Drouvot) §Original release occurrence ·
18.0/changes/195Add pgcrypto algorithms sha256crypt and sha512crypt Features
Add pgcrypto algorithms
sha256cryptandsha512crypt(Bernd Helmle) §Original release occurrence ·
18.0/changes/196Add CFB mode to pgcrypto encryption and decryption Features
Original release occurrence ·
18.0/changes/197Add function fips_mode() to report the server's FIPS mode Features
Add function
fips_mode()to report the server's FIPS mode (Daniel Gustafsson) §Original release occurrence ·
18.0/changes/198Add pgcrypto server variable builtin_crypto_enabled to allow disabling builtin non-FIPS mode cryptographic functions Features
Add pgcrypto server variable
builtin_crypto_enabledto allow disabling builtin non-FIPS mode cryptographic functions (Daniel Gustafsson, Joe Conway) §This is useful for guaranteeing FIPS mode behavior.
Original release occurrence ·
18.0/changes/199
Security evidence
47 records from the official security matrix and release-note mentions. A fixed version is shown only when the security snapshot explicitly names this branch. A mention alone does not establish applicability or a new fix.
CVE-2026-6638 · PostgreSQL REFRESH PUBLICATION allows SQL injection via table name CVSS 3.7
SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.
Fixed in this branch: 18.4. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-6637 · PostgreSQL refint allows stack buffer overflow and SQL injection CVSS 8.8
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 18.4. Component: contrib module.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6575 · PostgreSQL pg_restore_attribute_stats accepts values that cause query planning to read past end of stats array CVSS 4.3
Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor versions before PostgreSQL 18.4 are affected. Versions before PostgreSQL 18 are unaffected.
Fixed in this branch: 18.4. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-6479 · PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion CVSS 7.5
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 18.4. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2026-6478 · PostgreSQL discloses MD5-hashed passwords via covert timing channel CVSS 6.5
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 18.4. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-6477 · PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory CVSS 8.8
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 18.4. Component: client.
Official affected-branch entry: 18.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6476 · PostgreSQL pg_createsubscriber allows SQL injection via subscription name CVSS 7.2
SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_createsubscriber next runs. Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected. Versions before PostgreSQL 17 are unaffected.
Fixed in this branch: 18.4. Component: client.
Official affected-branch entry: 18.
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6475 · PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice CVSS 8.8
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 18.4. Component: client.
Official affected-branch entry: 18.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6474 · PostgreSQL timeofday() can disclose portions of server memory CVSS 4.3
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 18.4. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-6473 · PostgreSQL server undersizes allocations, via integer wraparound CVSS 8.8
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 18.4. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
- 18.6: Fix integer overflows in memory-allocation calculations in PL/Perl and PL/Tcl
- 18.4: Fix assorted integer overflows in memory-allocation calculations
- 18.4: Reject over-length options in ts_headline()
- 18.4: Guard against field overflow within contrib/intarray's query_int type and contrib/ltree's ltxtquery type
- 18.4: Guard against overly long values of contrib/ltree's lquery type
CVE-2026-6472 · PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege CVSS 5.4
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Fixed in this branch: 18.4. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-6471 · PostgreSQL logical decoding can dlopen arbitrary file CVSS 7.2
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-6470 · PostgreSQL fails to check type USAGE privilege CVSS 4.3
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
CVE-2026-6469 · PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership CVSS 3.8
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Release-note mentions:
CVE-2026-6464 · PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands CVSS 8.1
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: client.
Official affected-branch entry: 18.
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2007 · PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory CVSS 8.2
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
Fixed in this branch: 18.2. Component: contrib module.
Official affected-branch entry: 18.
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Release-note mentions:
CVE-2026-2006 · PostgreSQL missing validation of multibyte character length executes arbitrary code CVSS 8.8
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 18.2. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2005 · PostgreSQL pgcrypto heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 18.2. Component: contrib module.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2004 · PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code CVSS 8.8
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 18.2. Component: contrib module.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-2003 · PostgreSQL oidvector discloses a few bytes of memory CVSS 4.3
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Fixed in this branch: 18.2. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-19385 · PostgreSQL pg_dump heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: client.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-18408 · PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: client.
Official affected-branch entry: 18.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-18024 · PostgreSQL ascii() function reads past end of buffer CVSS 4.3
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-16241 · PostgreSQL ECPG integer underflow can crash the client CVSS 3.8
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: client.
Official affected-branch entry: 18.
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Release-note mentions:
CVE-2026-16239 · PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code CVSS 8.8
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-16238 · PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code CVSS 8.8
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-15742 · PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound CVSS 8.8
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: contrib module.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-15741 · PostgreSQL expression deparse allows SQL injection via EXTRACT argument CVSS 8.8
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14681 · PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL CVSS 4.2
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14680 · PostgreSQL type confusion via "internal" arguments CVSS 8.8
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14679 · PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory CVSS 8.2
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Release-note mentions:
CVE-2026-14678 · PostgreSQL pg_trgm picksplit reads past end of buffer CVSS 4.3
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: contrib module.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-14677 · PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound CVSS 8.8
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14676 · PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
Fixed in this branch: 18.6. Component: contrib module.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14673 · PostgreSQL amcheck does not clear untrusted search path CVSS 3.8
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.
Fixed in this branch: 18.6. Component: contrib module.
Official affected-branch entry: 18.
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14672 · PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle CVSS 5.3
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Release-note mentions:
CVE-2026-14671 · PostgreSQL refint plan cache type confusion executes arbitrary code CVSS 8.8
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: contrib module.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14670 · PostgreSQL plperl tied object heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14669 · PostgreSQL to_char heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14668 · PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read CVSS 8.1
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Release-note mentions:
CVE-2026-14666 · PostgreSQL row security caching disregards role modifications CVSS 4.2
Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14664 · PostgreSQL regexp heap buffer overflow executes arbitrary code CVSS 8.8
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2026-14663 · PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext CVSS 6.5
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: contrib module.
Official affected-branch entry: 18.
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Release-note mentions:
CVE-2026-14662 · PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound CVSS 8.8
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Fixed in this branch: 18.6. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
No fixed version for this branch is recorded. Component: core server.
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Release-note mentions:
CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound CVSS 5.9
Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
Fixed in this branch: 18.1. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Release-note mentions:
CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege CVSS 3.1
Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
Fixed in this branch: 18.1. Component: core server.
Official affected-branch entry: 18.
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Release-note mentions:
Export this branch as JSON · Compare any two indexed releases