Home
About
Download
Documentation
Community
Developers
Support
Donate
Your account
July 16, 2026: PostgreSQL 19 Beta 2 Released!
Quick Links
Support
Versioning Policy
Security
Professional Services
Hosting Solutions
Report a Bug
Security Information
The PostgreSQL Global Development Group (PGDG) takes security seriously. This
allows our users to place their trust in PostgreSQL for protecting their
mission-critical data.
The PostgreSQL Global Development Group follows a model that shares
responsibility between PostgreSQL itself and its deployment environment,
including hardware, operating system, and the application layer
(programming language, frameworks and client libraries). The PostgreSQL
documentation provides info on the inherent security features of PostgreSQL
and how to securely configure and run PostgreSQL.
Security vulnerabilities can exist both in PostgreSQL and software within the
PostgreSQL ecosystem, including client libraries, extensions, installers,
and other utilities. This page walks through what is considered a security
vulnerability in PostgreSQL, how to report PostgreSQL security
vulnerabilities, and how fixes for security vulnerabilities are released.
Please note that the PostgreSQL Project does not offer bug bounties.
CVE Numbering Authority
The PostgreSQL Project is a CVE Numbering Authority (CNA), working with Red Hat
as our CNA Root. This allows us to assign our own CVE numbers and publish CVE
records for PostgreSQL and closely related projects.
We will currently assign CVE numbers for the following projects upon request to
[email protected]:
PostgreSQL
PostgreSQL RPM packaging
PostgreSQL DEB packaging
PostgreSQL Windows/macOS installers (EDB)
pgJDBC
psqlODBC
pgAdmin
PgBouncer
PostgreSQL Anonymizer
pgvector
Additional projects may request inclusion on the list above by emailing
[email protected].
NOTE: The security team will only assign CVEs to projects
when requested by members of the project. If you think you've found a security
issue in a project other than PostgreSQL or its packages and installers,
please contact the security team for that project. See below for more details.
What is a Security Vulnerability in PostgreSQL?
A security vulnerability in PostgreSQL is an issue that allows a user to gain
access to privileges or data that they do not have permission to use, or
allows a user to execute arbitrary code through a PostgreSQL process.
The PostgreSQL Security Team does not consider reports on actions a PostgreSQL
superuser takes to be a security vulnerability. However, a report on an
unprivileged user escalating to superuser generally qualifies as valid.
The PostgreSQL Security Team typically does not consider a denial-of-service
on a PostgreSQL server from an authenticated, valid SQL statement to be a
security vulnerability. A denial-of-service issue of this nature could still
be a bug, and we encourage you to report it
on the Report a Bug page.
Please do not report the lack of DMARC on postgresql.org mailing lists. This
is by design.
Reporting a PostgreSQL Security Vulnerability
For security vulnerabilities in PostgreSQL or any of the installers linked
from the PostgreSQL download page, please email
[email protected].
For reporting non-security bugs, please visit the
Report a Bug page.
If you are unsure if an issue is a security vulnerability, please err on the
side of caution and email
[email protected].
Once a vulnerability is validated, the PostgreSQL Security Team works to fix
it. Our goal is to try to include any fixes as part of the next scheduled
PostgreSQL update release (see "PostgreSQL Security Releases"). Based on
factors like the timing of the report, the severity of the issues, or
complexity of the fix, the PostgreSQL Security Team may decide to include the
fix in a subsequent release, or in exceptional circumstances, issue an
"out-of-cycle" release.
We expect that no vulnerability is prematurely disclosed until the PostgreSQL
Project has made it available as part of its release and disclosure process.
Reporting non-PostgreSQL Security Vulnerabilities
Please see below for how you can report security vulnerabilities in
PostgreSQL-related projects:
For security vulnerabilities in the PostgreSQL JDBC Driver,
please email
[email protected].
For security vulnerabilities in pgAdmin,
please email
[email protected].
For security vulnerabilities in pgvector,
please email
[email protected].
If you wish to report a security vulnerability for any other open source project in
the PostgreSQL ecosystem (e.g. a driver, an extension, or an installer) and
need a secure communication channel, please email
[email protected].
PostgreSQL Security Releases
The PostgreSQL Project releases security fixes as part of
minor version updates. You are always
advised to use the latest minor version available, as it will contain other
non-security related fixes.
A new PostgreSQL major release, which contains new features, has every prior
security fix.
If you find a security vulnerability in PostgreSQL, the PostgreSQL Security
Team will credit you in the release notes and register a CVE for the
vulnerability. Please do not register a CVE independently of the
PostgreSQL Security Team.
PostgreSQL Security Notifications
To receive notifications about security releases or other security
related news, you can subscribe to
the pgsql-announce mailing list. If you set your
subscription to only include the tag Security, it will
exclude all other announcements that are sent to this list.
Known PostgreSQL Security Vulnerabilities
The PostgreSQL Global Development Group believes that accuracy, completeness
and availability of security information is essential for our users. We choose
to pool all information on this one page, allowing easy searching for security
vulnerabilities over a range of criteria. This includes:
Which major versions a security vulnerability is present in
Which minor version update releases a security vulnerability is fixed in
Whether an exploit requires a valid login
CVSS score
You can find more detailed information about a security vulnerability by
clicking on the links in the table below.
Known PostgreSQL Security Vulnerabilities in
Supported Versions
You can filter the view of patches to show just patches for version:
18 -
17 -
16 -
15 -
14
- all
Reference
Affected
Fixed
Component & CVSS v3 Base Score
Description
CVE-2026-6638
Announcement
18, 17, 16
18.4, 17.10, 16.14
core server
3.7
AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
PostgreSQL REFRESH PUBLICATION allows SQL injection via table name
more details
CVE-2026-6637
Announcement
18, 17, 16, 15, 14
18.4, 17.10, 16.14, 15.18, 14.23
contrib module
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PostgreSQL refint allows stack buffer overflow and SQL injection
more details
CVE-2026-6575
Announcement
18
18.4
core server
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
PostgreSQL pg_restore_attribute_stats accepts values that cause query planning to read past end of stats array
more details
CVE-2026-6479
Announcement
18, 17, 16, 15, 14
18.4, 17.10, 16.14, 15.18, 14.23
core server
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion
more details
CVE-2026-6478
Announcement
18, 17, 16, 15, 14
18.4, 17.10, 16.14, 15.18, 14.23
core server
6.5
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
PostgreSQL discloses MD5-hashed passwords via covert timing channel
more details
CVE-2026-6477
Announcement
18, 17, 16, 15, 14
18.4, 17.10, 16.14, 15.18, 14.23
client
8.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
more details
CVE-2026-6476
Announcement
18, 17
18.4, 17.10
client
7.2
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
PostgreSQL pg_createsubscriber allows SQL injection via subscription name
more details
CVE-2026-6475
Announcement
18, 17, 16, 15, 14
18.4, 17.10, 16.14, 15.18, 14.23
client
8.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice
more details
CVE-2026-6474
Announcement
18, 17, 16, 15, 14
18.4, 17.10, 16.14, 15.18, 14.23
core server
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
PostgreSQL timeofday() can disclose portions of server memory
more details
CVE-2026-6473
Announcement
18, 17, 16, 15, 14
18.4, 17.10, 16.14, 15.18, 14.23
core server
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PostgreSQL server undersizes allocations, via integer wraparound
more details
CVE-2026-6472
Announcement
18, 17, 16, 15, 14
18.4, 17.10, 16.14, 15.18, 14.23
core server
5.4
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege
more details
CVE-2026-2007
Announcement
18
18.2
contrib module
8.2
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
more details
CVE-2026-2006
Announcement
18, 17, 16, 15, 14
18.2, 17.8, 16.12, 15.16, 14.21
core server
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PostgreSQL missing validation of multibyte character length executes arbitrary code
more details
CVE-2026-2005
Announcement
18, 17, 16, 15, 14
18.2, 17.8, 16.12, 15.16, 14.21
contrib module
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PostgreSQL pgcrypto heap buffer overflow executes arbitrary code
more details
CVE-2026-2004
Announcement
18, 17, 16, 15, 14
18.2, 17.8, 16.12, 15.16, 14.21
contrib module
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code
more details
CVE-2026-2003
Announcement
18, 17, 16, 15, 14
18.2, 17.8, 16.12, 15.16, 14.21
core server
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
PostgreSQL oidvector discloses a few bytes of memory
more details
CVE-2025-12818
Announcement
18, 17, 16, 15, 14
18.1, 17.7, 16.11, 15.15, 14.20
core server
5.9
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
PostgreSQL libpq undersizes allocations, via integer wraparound
more details
CVE-2025-12817
Announcement
18, 17, 16, 15, 14
18.1, 17.7, 16.11, 15.15, 14.20
core server
3.1
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege
more details
CVE-2025-8715
Announcement
17, 16, 15, 14
17.6, 16.10, 15.14, 14.19
core server
8.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server
more details
CVE-2025-8714
Announcement
17, 16, 15, 14
17.6, 16.10, 15.14, 14.19
core server
8.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client
more details
CVE-2025-8713
Announcement
17, 16, 15, 14
17.6, 16.10, 15.14, 14.19
core server
3.1
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table
more details
CVE-2025-4207
Announcement
17, 16, 15, 14
17.5, 16.9, 15.13, 14.18
core server
5.9
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation
more details
CVE-2025-1094
Announcement
17, 16, 15, 14
17.3, 16.7, 15.11, 14.16
core server
8.1
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation
more details
CVE-2024-10979
Announcement
17, 16, 15, 14
17.1, 16.5, 15.9, 14.14
core server
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PostgreSQL PL/Perl environment variable changes execute arbitrary code
more details
CVE-2024-10978
Announcement
17, 16, 15, 14
17.1, 16.5, 15.9, 14.14
core server
4.2
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID
more details
CVE-2024-10977
Announcement
17, 16, 15, 14
17.1, 16.5, 15.9, 14.14
client
3.1
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
PostgreSQL libpq retains an error message from man-in-the-middle
more details
CVE-2024-10976
Announcement
17, 16, 15, 14
17.1, 16.5, 15.9, 14.14
core server
4.2
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
PostgreSQL row security below e.g. subqueries disregards user ID changes
more details
CVE-2024-7348
Announcement
16, 15, 14
16.4, 15.8, 14.13
core server
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PostgreSQL relation replacement during pg_dump executes arbitrary SQL
more details
CVE-2024-4317
Announcement
16, 15, 14
16.3, 15.7, 14.12
core server
3.1
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Restrict visibility of "pg_stats_ext" and "pg_stats_ext_exprs" entries to the table owner
more details
CVE-2024-0985
Announcement
16, 15, 14
16.2, 15.6, 14.11
core server
8.0
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL
more details
CVE-2023-39418
Announcement
15
15.4
core server
3.1
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
MERGE fails to enforce UPDATE or SELECT row security policies
more details
CVE-2023-39417
Announcement
15, 14
15.4, 14.9
core server
7.5
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Extension script @substitutions@ within quoting allow SQL injection
more details
CVE-2023-5870
Announcement
16, 15, 14
16.1, 15.5, 14.10
core server
2.2
AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
Role "pg_signal_backend" can signal certain superuser processes
more details
CVE-2023-5869
Announcement
16, 15, 14
16.1, 15.5, 14.10
core server
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Buffer overrun from integer overflow in array modification
more details
CVE-2023-5868
Announcement
16, 15, 14
16.1, 15.5, 14.10
core server
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Memory disclosure in aggregate function calls
more details
CVE-2023-2455
Announcement
15, 14
15.3, 14.8
core server
4.2
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Row security policies disregard user ID changes after inlining
more details
CVE-2023-2454
Announcement
15, 14
15.3, 14.8
core server
7.2
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CREATE SCHEMA ... schema_element defeats protective search_path changes
more details
CVE-2022-41862
Announcement
15, 14
15.2, 14.7
client
3.7
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Client memory disclosure when connecting, with Kerberos, to modified server
more details
CVE-2022-2625
Announcement
14
14.5
core server
7.1
AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Extension scripts replace objects not belonging to the extension
more details
CVE-2022-1552
Announcement
14
14.3
core server
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Autovacuum, REINDEX, and others omit "security restricted operation" sandbox
more details
CVE-2021-23222
Announcement
14
14.1
client
3.7
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
libpq processes unencrypted bytes from man-in-the-middle
more details
CVE-2021-23214
Announcement
14
14.1
core server
8.1
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Server processes unencrypted bytes from man-in-the-middle
more details
Unsupported versions
You can also view archived security patches for unsupported versions. Note that no further
security patches are made available for these versions as they are end of life.
13 -
12 -
11 -
10 -
9.6 -
9.5 -
9.4 -
9.3 -
9.2 -
9.1 -
9.0 -
8.4 -
8.3 -
8.2 -
8.1 -
8.0 -
7.4 -
7.3
Components
The following component references are used in the above table:
Component
Description
core server
This vulnerability exists in the core server product.
client
This vulnerability exists in a client library or client application only.
contrib module
This vulnerability exists in a contrib module. Contrib modules are not installed by default when PostgreSQL is installed from source. They may be installed by binary packages.
client contrib module
This vulnerability exists in a contrib module used on the client only.
packaging
This vulnerability exists in PostgreSQL binary packaging, e.g. an installer or RPM.
The PostgreSQL Security Team
The PostgreSQL Security Team is made up of a group of contributors to the
PostgreSQL project who have experience in different aspects of database and
information security.
You can find a list of members on the security team here:
Álvaro Herrera
Andres Freund
Andrew Dunstan
Bruce Momjian
Dave Page
Greg Stark
Heikki Linnakangas
Jacob Champion
Joe Conway
Jonathan Katz
Magnus Hagander
Michael Paquier
Nathan Bossart
Noah Misch
Peter Eisentraut
Robert Haas
Stefan Kaltenbrunner
Tom Lane
Policies |
Code of Conduct |
About PostgreSQL |
Contact
Copyright © 1996-2026 The PostgreSQL Global Development Group