PostgreSQL 17
支持中 · 记录构建 17.11 · 2026-08-13
- 首次正式发布
- 2024-09-26
- 支持结束
- 2029-11-08
- 已收录发布版本
- 12
- 原始发布说明条目
- 727
手册与来源
PostgreSQL 17 本站手册 · 已加载 1146 页。
手册加载时间:2026-09-27T00:10:45.258078。
发布说明快照:2026-09-26。安全证据快照:2026-09-26。PDF 链接按本地文件是否存在提供,历史版本的语言与 HTML 手册可能不同。生命周期参见官方版本政策。
升级注意事项
跨大版本升级需要导出/恢复或 pg_upgrade 等迁移方式,应阅读沿途大版本的发布说明与目标版本手册。小版本更新也可能要求额外操作,请核对对应发布的迁移说明。官方升级政策。
17.0 的原始迁移说明
对于希望从任何以前的版本迁移数据的人来说,需要使用pg_dumpall进行转储/恢复,或者使用pg_upgrade或逻辑复制。有关迁移到新主要版本的通用信息,请参阅第 18.6 节。
版本 17 包含许多可能影响与以前版本兼容性的更改。请注意以下不兼容项:
发布历史
每次发布的原始变更均独立保留。CVE 数量表示发布说明中的提及,可能包含后续纠正,不等于本次新修复漏洞数。
| 版本 | 日期/快照截止时间 | 全部变化 | BUG 修复 | 迁移条目 | 提及 CVE |
|---|---|---|---|---|---|
| 17.11 | 2026-08-13 | 109 | 49 | 0 | 31 |
| 17.10 | 2026-05-14 | 58 | 24 | 0 | 10 |
| 17.9 | 2026-02-26 | 6 | 5 | 0 | 1 |
| 17.8 | 2026-02-12 | 52 | 23 | 0 | 4 |
| 17.7 | 2025-11-13 | 65 | 35 | 0 | 2 |
| 17.6 | 2025-08-14 | 71 | 25 | 0 | 5 |
| 17.5 | 2025-05-08 | 61 | 28 | 0 | 1 |
| 17.4 | 2025-02-20 | 3 | 2 | 0 | 1 |
| 17.3 | 2025-02-13 | 71 | 37 | 0 | 1 |
| 17.2 | 2024-11-21 | 8 | 4 | 0 | 1 |
| 17.1 | 2024-11-14 | 41 | 21 | 0 | 4 |
| 17.0 | 2024-09-26 | 182 | 2 | 17 | 0 |
首次发布变化
17.0 的原始条目,包含功能和兼容性变化。类别用于浏览,不是上游原始分类。
匹配 182 / 182 条原始变更。
更改函数,使其在维护操作期间使用安全的search_path · 兼容性变化 · 迁移说明
更改函数,使其在维护操作期间使用安全的search_path(Jeff Davis)§ §
这可防止维护操作(
ANALYZE、CLUSTER、CREATE INDEX、CREATE MATERIALIZED VIEW、REFRESH MATERIALIZED VIEW、REINDEX或VACUUM)执行不安全的访问。表达式索引和物化视图中使用、且需要引用非默认 schema 的函数,必须在创建函数时指定 search path。原始发布条目 ·
17.0/migration/001更改 SET SESSION AUTHORIZATION 对初始会话用户超级用户状态的处理方式 · 兼容性变化 · 迁移说明
更改
SET SESSION AUTHORIZATION对初始会话用户超级用户状态的处理方式(Joseph Koshakow)§新行为基于发出
SET SESSION AUTHORIZATION命令时会话用户的超级用户状态,而不是其连接建立时的超级用户状态。原始发布条目 ·
17.0/migration/004在 Windows 上移除wal_sync_method的 fsync_writethrough 值 · 兼容性变化 · 迁移说明
在 Windows 上移除wal_sync_method的
fsync_writethrough值(Thomas Munro)§该值在 Windows 上与
fsync相同。原始发布条目 ·
17.0/migration/007更改两个 WAL 文件名函数对文件边界的处理方式 · 兼容性变化 · 迁移说明
更改两个 WAL 文件名函数对文件边界的处理方式(Kyotaro Horiguchi, Andres Freund, Bruce Momjian)§
当 LSN 位于文件段边界时,
pg_walfile_name()和pg_walfile_name_offset()过去会报告前一个 LSN 段号;现在则返回当前的 LSN 段。原始发布条目 ·
17.0/migration/008移除 information schema 列 element_types.domain_default · 兼容性变化 · 迁移说明
移除 information schema 列
element_types.domain_default(Peter Eisentraut)§原始发布条目 ·
17.0/migration/010更改 pgrowlocks 的锁模式输出标签 · 兼容性变化 · 迁移说明
更改 pgrowlocks 的锁模式输出标签(Bruce Momjian)§
原始发布条目 ·
17.0/migration/011从 pg_stat_bgwriter 中移除 buffers_backend 和 buffers_backend_fsync · 兼容性变化 · 迁移说明
从
pg_stat_bgwriter中移除buffers_backend和buffers_backend_fsync(Bharath Rupireddy)§这些字段被认为与
pg_stat_io中的类似列重复。原始发布条目 ·
17.0/migration/012重命名 pg_stat_statements 的 I/O 块读/写耗时统计列 · 兼容性变化 · 迁移说明
重命名 pg_stat_statements 的 I/O 块读/写耗时统计列(Nazir Bilal Yavuz)§
即将
blk_read_time重命名为shared_blk_read_time,并将blk_write_time重命名为shared_blk_write_time。原始发布条目 ·
17.0/migration/013将 pg_attribute.attstattarget 和 pg_statistic_ext.stxstattarget 表示默认统计目标的方式更改为 NULL · 兼容性变化 · 迁移说明
将
pg_attribute.attstattarget和pg_statistic_ext.stxstattarget表示默认统计目标的方式更改为NULL(Peter Eisentraut)§ §原始发布条目 ·
17.0/migration/014将 pg_collation.colliculocale 重命名为 colllocale,并将 pg_database.daticulocale 重命名为 datlocale · 兼容性变化 · 迁移说明
将
pg_collation.colliculocale重命名为colllocale,并将pg_database.daticulocale重命名为datlocale(Jeff Davis)§原始发布条目 ·
17.0/migration/015将 pg_stat_progress_vacuum 的列 max_dead_tuples 重命名为 max_dead_tuple_bytes,将 num_dead_tuples 重命名为 num_dead_item_ids,并新增 dead_tuple_bytes · 兼容性变化 · 迁移说明
将
pg_stat_progress_vacuum的列max_dead_tuples重命名为max_dead_tuple_bytes,将num_dead_tuples重命名为num_dead_item_ids,并新增dead_tuple_bytes(Masahiko Sawada)§ §原始发布条目 ·
17.0/migration/016重命名系统视图 pg_stat_slru 中的 SLRU 列 · 兼容性变化 · 迁移说明
重命名系统视图
pg_stat_slru中的 SLRU 列(Alvaro Herrera)§pg_stat_reset_slru()接受的列名也随之更改。原始发布条目 ·
17.0/migration/017允许在内部重新排列 GROUP BY 列,以匹配 ORDER BY · 新功能
允许在内部重新排列
GROUP BY列,以匹配ORDER BY(Andrei Lepikhov, Teodor Sigaev)§这可使用服务器变量enable_group_by_reordering禁用。
原始发布条目 ·
17.0/changes/008允许 vacuum 更高效地存储元组引用 · 性能改进
允许 vacuum 更高效地存储元组引用(Masahiko Sawada, John Naylor)§ § § §
此外,当maintenance_work_mem或autovacuum_work_mem更高时,vacuum 不再被静默限制为最多使用 1 GB 内存。
原始发布条目 ·
17.0/changes/016将vacuum_buffer_usage_limit的默认值提高到 2MB · 性能改进
将vacuum_buffer_usage_limit的默认值提高到 2MB(Thomas Munro)§
原始发布条目 ·
17.0/changes/018允许使用新的系统变量io_combine_limit对文件系统读取进行分组 · 性能改进
允许使用新的系统变量io_combine_limit对文件系统读取进行分组(Thomas Munro, Andres Freund, Melanie Plageman, Nazir Bilal Yavuz)§ § §
原始发布条目 ·
17.0/changes/022创建系统视图 pg_stat_checkpointer · 新功能
创建系统视图
pg_stat_checkpointer(Bharath Rupireddy, Anton A. Melnikov, Alexander Korotkov)§ § §已将相关列从
pg_stat_bgwriter中移除,并加入这个新系统视图。原始发布条目 ·
17.0/changes/023改进对重置统计信息的控制 · 新功能
改进对重置统计信息的控制(Atsushi Torikoshi, Bharath Rupireddy)§ § §
允许
pg_stat_reset_shared()(无参数)和 pg_stat_reset_shared(NULL) 重置所有共享统计信息。允许 pg_stat_reset_shared('slru') 和pg_stat_reset_slru()(无参数)重置 SLRU 统计信息,而这在以前只能通过 pg_stat_reset_slru(NULL) 实现。原始发布条目 ·
17.0/changes/024为 trust 连接添加log_connections日志行 · 新功能
为
trust连接添加log_connections日志行(Jacob Champion)§原始发布条目 ·
17.0/changes/026添加日志消息以报告 walsender 获取和释放复制槽 · 新功能
添加日志消息以报告 walsender 获取和释放复制槽(Bharath Rupireddy)§
这由服务器变量log_replication_commands启用。
原始发布条目 ·
17.0/changes/027添加用于报告等待事件类型的系统视图 pg_wait_events · 新功能
添加用于报告等待事件类型的系统视图
pg_wait_events(Bertrand Drouvot)§这有助于为
pg_stat_activity中报告的等待事件补充描述。原始发布条目 ·
17.0/changes/028允许 vacuum 报告索引处理进度 · 新功能
允许 vacuum 报告索引处理进度(Sami Imseih)§
这显示在系统视图
pg_stat_progress_vacuum的indexes_total和indexes_processed列中。原始发布条目 ·
17.0/changes/030允许授予执行维护操作的权限 · 新功能
允许授予执行维护操作的权限(Nathan Bossart)§
该权限可以通过
MAINTAIN权限按表授予,也可以通过预定义角色pg_maintain按角色授予。允许的操作包括VACUUM、ANALYZE、REINDEX、REFRESH MATERIALIZED VIEW、CLUSTER和LOCK TABLE。原始发布条目 ·
17.0/changes/031允许拥有 pg_monitor 成员资格的角色执行 pg_current_logfile() · 新功能
允许拥有
pg_monitor成员资格的角色执行pg_current_logfile()(Pavlo Golub, Nathan Bossart)§原始发布条目 ·
17.0/changes/032添加系统变量allow_alter_system,以禁止 ALTER SYSTEM · 新功能
添加系统变量allow_alter_system,以禁止
ALTER SYSTEM(Jelte Fennema-Nio, Gabriele Bartolini)§原始发布条目 ·
17.0/changes/033允许 ALTER SYSTEM 设置未识别的自定义服务器变量 · 新功能
允许
ALTER SYSTEM设置未识别的自定义服务器变量(Tom Lane)§这也可以通过
GRANT ON PARAMETER实现。原始发布条目 ·
17.0/changes/034添加服务器变量transaction_timeout,以限制事务持续时间 · 新功能
添加服务器变量transaction_timeout,以限制事务持续时间(Andrey Borodin, Japin Li, Junwang Zhao, Alexander Korotkov)§ § §
原始发布条目 ·
17.0/changes/035添加服务器变量huge_pages_status,用于报告 Postgres 对 huge pages 的使用情况 · 新功能
添加服务器变量huge_pages_status,用于报告 Postgres 对 huge pages 的使用情况(Justin Pryzby)§
当huge_pages设置为
try时,这很有用。原始发布条目 ·
17.0/changes/037添加用于禁用事件触发器的服务器变量 · 新功能
添加用于禁用事件触发器的服务器变量(Daniel Gustafsson)§
该设置event_triggers允许为调试目的临时禁用事件触发器。
原始发布条目 ·
17.0/changes/038允许配置 SLRU 缓存大小 · 新功能
允许配置 SLRU 缓存大小(Andrey Borodin, Dilip Kumar, Alvaro Herrera)§
新的服务器变量包括commit_timestamp_buffers、multixact_member_buffers、multixact_offset_buffers、notify_buffers、serializable_buffers、subtransaction_buffers和transaction_buffers。commit_timestamp_buffers、transaction_buffers以及subtransaction_buffers会随着shared_buffers自动扩展。
原始发布条目 ·
17.0/changes/039添加对增量文件系统备份的支持 · 新功能
添加对增量文件系统备份的支持(Robert Haas, Jakub Wartak, Tomas Vondra)§ §
可使用pg_basebackup的新
--incremental选项创建增量备份。新的应用程序pg_combinebackup允许处理基础和增量文件系统备份。原始发布条目 ·
17.0/changes/040允许创建 WAL 摘要文件 · 新功能
允许创建 WAL 摘要文件(Robert Haas, Nathan Bossart, Hubert Depesz Lubaczewski)§ § § §
这些文件记录某个 LSN 范围内发生变化的块号,对增量文件系统备份很有用。这由服务器变量summarize_wal和wal_summary_keep_time控制,并可通过
pg_available_wal_summaries()、pg_wal_summary_contents()和pg_get_wal_summarizer_state()进行查看。原始发布条目 ·
17.0/changes/041将系统标识符添加到文件系统 backup manifest 文件中 · 新功能
将系统标识符添加到文件系统 backup manifest 文件中(Amul Sul)§
这有助于检测无效的 WAL 使用。
原始发布条目 ·
17.0/changes/042允许在pg_basebackup将连接信息写入 postgresql.auto.conf 时写入连接字符串值 dbname · 新功能
允许在pg_basebackup将连接信息写入
postgresql.auto.conf时写入连接字符串值dbname(Vignesh C, Hayato Kuroda)§原始发布条目 ·
17.0/changes/043添加列 pg_replication_slots.invalidation_reason,用于报告复制槽失效的原因 · 新功能
添加列
pg_replication_slots.invalidation_reason,用于报告复制槽失效的原因(Shveta Malik, Bharath Rupireddy)§ §原始发布条目 ·
17.0/changes/044添加列 pg_replication_slots.inactive_since,用于报告复制槽的不活动持续时间 · 新功能
添加列
pg_replication_slots.inactive_since,用于报告复制槽的不活动持续时间(Bharath Rupireddy)§ § §原始发布条目 ·
17.0/changes/045添加函数 pg_sync_replication_slots(),用于同步逻辑复制槽 · 新功能
添加函数
pg_sync_replication_slots(),用于同步逻辑复制槽(Hou Zhijie, Shveta Malik, Ajin Cherian, Peter Eisentraut)§ §原始发布条目 ·
17.0/changes/046添加应用程序pg_createsubscriber,用于从物理备库创建逻辑副本 · 新功能
添加应用程序pg_createsubscriber,用于从物理备库创建逻辑副本(Euler Taveira)§
原始发布条目 ·
17.0/changes/048让pg_upgrade迁移有效的逻辑槽和订阅 · 新功能
让pg_upgrade迁移有效的逻辑槽和订阅(Hayato Kuroda, Hou Zhijie, Vignesh C, Julien Rouhaud, Shlok Kyal)§ §
这使逻辑复制能够在升级后快速继续。此功能仅适用于版本为 17 或更高的旧 PostgreSQL 集簇。
原始发布条目 ·
17.0/changes/049启用逻辑槽的故障切换 · 新功能
启用逻辑槽的故障切换(Hou Zhijie, Shveta Malik, Ajin Cherian)§
这由
pg_create_logical_replication_slot()的可选第五个参数控制。原始发布条目 ·
17.0/changes/050添加服务器变量sync_replication_slots,以启用故障切换逻辑槽同步 · 新功能
添加服务器变量sync_replication_slots,以启用故障切换逻辑槽同步(Shveta Malik, Hou Zhijie, Peter Smith)§ §
原始发布条目 ·
17.0/changes/051为 CREATE/ALTER SUBSCRIPTION 添加逻辑复制故障切换控制 · 新功能
为
CREATE/ALTER SUBSCRIPTION添加逻辑复制故障切换控制(Shveta Malik, Hou Zhijie, Ajin Cherian)§ §原始发布条目 ·
17.0/changes/052为 pg_logical_emit_message() 添加 flush 选项 · 新功能
为
pg_logical_emit_message()添加flush选项(Michael Paquier)§这会使该消息具有持久性。
原始发布条目 ·
17.0/changes/056允许指定在对订阅者可见之前必须先完成同步的物理备库 · 新功能
允许指定在对订阅者可见之前必须先完成同步的物理备库(Hou Zhijie, Shveta Malik)§ §
新的服务器变量是synchronized_standby_slots。
原始发布条目 ·
17.0/changes/057为 pg_stat_subscription 添加工作进程类型列 · 新功能
为
pg_stat_subscription添加工作进程类型列(Peter Smith)§原始发布条目 ·
17.0/changes/058允许 COPY FROM 在处理期间报告被跳过的行数 · 新功能
允许
COPY FROM在处理期间报告被跳过的行数(Atsushi Torikoshi)§这显示在系统视图列
pg_stat_progress_copy.tuples_skipped中。原始发布条目 ·
17.0/changes/061为将列设置为默认统计目标添加更清晰的 ALTER TABLE 方法 · 新功能
为将列设置为默认统计目标添加更清晰的
ALTER TABLE方法(Peter Eisentraut)§新语法是
ALTER TABLE ... SET STATISTICS DEFAULT;仍然支持使用SET STATISTICS -1。原始发布条目 ·
17.0/changes/065如果该类型是在同一事务中创建的,则允许使用通过 ALTER TYPE 新增的 ENUM 值 · 新功能
如果该类型是在同一事务中创建的,则允许使用通过
ALTER TYPE新增的ENUM值(Tom Lane)§这在以前是不允许的。
原始发布条目 ·
17.0/changes/078添加函数 JSON_TABLE(),用于将 JSON 数据转换为表表示形式 · 新功能
添加函数
JSON_TABLE(),用于将JSON数据转换为表表示形式(Nikita Glukhov, Teodor Sigaev, Oleg Bartunov, Alexander Korotkov, Andrew Dunstan, Amit Langote, Jian He)§ §该函数可在
SELECT查询的FROM子句中用作元组源。原始发布条目 ·
17.0/changes/082为 to_timestamp() 添加时区格式说明符 · 新功能
为
to_timestamp()添加时区格式说明符(Tom Lane)§TZ接受时区缩写或数字偏移,而OF只接受数字偏移。原始发布条目 ·
17.0/changes/086添加函数 uuid_extract_timestamp() 和 uuid_extract_version(),用于返回 UUID 信息 · 新功能
添加函数
uuid_extract_timestamp()和uuid_extract_version(),用于返回 UUID 信息(Andrey Borodin)§原始发布条目 ·
17.0/changes/088添加用于在指定范围内生成随机数的函数 · 新功能
添加用于在指定范围内生成随机数的函数(Dean Rasheed)§
这些函数是
random(min, max),其参数可为integer、bigint和numeric类型的值。原始发布条目 ·
17.0/changes/089添加 Unicode 信息函数 · 新功能
添加 Unicode 信息函数(Jeff Davis)§
函数
unicode_version()返回 Unicode 版本,icu_unicode_version()返回 ICU 版本,而unicode_assigned()返回字符是否已分配 Unicode 代码点。原始发布条目 ·
17.0/changes/091添加函数 to_regtypemod(),用于返回类型说明的类型修饰符 · 新功能
添加函数
to_regtypemod(),用于返回类型说明的类型修饰符(David Wheeler, Erik Wienhold)§原始发布条目 ·
17.0/changes/093添加函数 pg_basetype(),用于返回域的基础类型 · 新功能
添加函数
pg_basetype(),用于返回域的基础类型(Steve Chavez)§原始发布条目 ·
17.0/changes/094添加函数 pg_column_toast_chunk_id(),用于返回某个值的 TOAST 标识符 · 新功能
添加函数
pg_column_toast_chunk_id(),用于返回某个值的 TOAST 标识符(Yugo Nagata)§如果该值未存储在 TOAST 中,则返回
NULL。原始发布条目 ·
17.0/changes/095添加用于更改角色密码的 libpq 函数 · 新功能
添加用于更改角色密码的 libpq 函数(Joe Conway)§
新函数
PQchangePassword()会在将新密码发送到服务器之前先对其进行 hash 运算。原始发布条目 ·
17.0/changes/098添加用于关闭 portal 和预备语句的 libpq 函数 · 新功能
添加用于关闭 portal 和预备语句的 libpq 函数(Jelte Fennema-Nio)§
这些函数是
PQclosePrepared()、PQclosePortal()、PQsendClosePrepared()以及PQsendClosePortal()。原始发布条目 ·
17.0/changes/099添加 libpq 函数 PQsocketPoll(),以允许对网络套接字进行轮询 · 新功能
添加 libpq 函数
PQsocketPoll(),以允许对网络套接字进行轮询(Tristan Partin, Tom Lane)§ §原始发布条目 ·
17.0/changes/101添加 libpq 函数 PQsendPipelineSync(),用于发送管道同步点 · 新功能
添加 libpq 函数
PQsendPipelineSync(),用于发送管道同步点(Anton Kirilov)§这与
PQpipelineSync()类似,但除非达到输出缓冲区的大小阈值,否则不会将数据刷新到服务器。原始发布条目 ·
17.0/changes/102添加 libpq 函数 PQsetChunkedRowsMode(),以允许分块获取结果 · 新功能
添加 libpq 函数
PQsetChunkedRowsMode(),以允许分块获取结果(Daniel Vérité)§原始发布条目 ·
17.0/changes/103添加应用程序pg_walsummary,用于转储 WAL 摘要文件 · 新功能
添加应用程序pg_walsummary,用于转储 WAL 摘要文件(Robert Haas)§
原始发布条目 ·
17.0/changes/111允许pg_dump、pg_dumpall和pg_restore在文件中指定要包含或排除的对象 · 新功能
允许pg_dump、pg_dumpall和pg_restore在文件中指定要包含或排除的对象(Pavel Stehule, Daniel Gustafsson)§
该选项名为
--filter。原始发布条目 ·
17.0/changes/114为多个客户端应用程序添加 --sync-method 参数 · 新功能
为多个客户端应用程序添加
--sync-method参数(Justin Pryzby, Nathan Bossart)§这些应用程序是initdb、pg_basebackup、pg_checksums、pg_dump、pg_rewind和pg_upgrade。
原始发布条目 ·
17.0/changes/115为pg_restore添加 --transaction-size 选项,允许按事务批次恢复对象 · 新功能
为pg_restore添加
--transaction-size选项,允许按事务批次恢复对象(Tom Lane)§这既能获得事务批处理的性能收益,又能避免事务块过大的问题。
原始发布条目 ·
17.0/changes/116允许pg_archivecleanup删除备份历史文件 · 新功能
允许pg_archivecleanup删除备份历史文件(Atsushi Torikoshi)§
该选项是
--clean-backup-history。原始发布条目 ·
17.0/changes/120允许pg_basebackup和pg_receivewal在其连接字符串中使用 dbname · 新功能
允许pg_basebackup和pg_receivewal在其连接字符串中使用 dbname(Jelte Fennema-Nio)§
这对那些对数据库名敏感的连接池很有用。
原始发布条目 ·
17.0/changes/122添加pg_upgrade选项 --copy-file-range · 新功能
添加pg_upgrade选项
--copy-file-range(Thomas Munro)§这在 Linux 和 FreeBSD 上受支持。
原始发布条目 ·
17.0/changes/123允许将 EXISTS 和 IN 子查询下推到postgres_fdw外部服务器 · 新功能
允许将
EXISTS和IN子查询下推到postgres_fdw外部服务器(Alexander Pyhalov)§原始发布条目 ·
17.0/changes/146允许 ALTER OPERATOR 设置更多优化属性 · 新功能
允许
ALTER OPERATOR设置更多优化属性(Tommy Pavlicek)§这对扩展很有用。
原始发布条目 ·
17.0/changes/155添加 pg_buffercache 函数 pg_buffercache_evict(),以允许逐出共享缓冲区 · 新功能
添加 pg_buffercache 函数
pg_buffercache_evict(),以允许逐出共享缓冲区(Palak Chaturvedi, Thomas Munro)§这对测试很有用。
原始发布条目 ·
17.0/changes/157将存储在 pg_stat_statements 中的保存点名称替换为占位符 · 新功能
将存储在
pg_stat_statements中的保存点名称替换为占位符(Greg Sabino Mullane)§这会大幅减少记录
SAVEPOINT、RELEASE SAVEPOINT和ROLLBACK TO SAVEPOINT命令所需的条目数量。原始发布条目 ·
17.0/changes/159将存储在 pg_stat_statements 中的两阶段提交 GID 替换为占位符 · 新功能
将存储在
pg_stat_statements中的两阶段提交 GID 替换为占位符(Michael Paquier)§这会大幅减少记录
PREPARE TRANSACTION、COMMIT PREPARED和ROLLBACK PREPARED所需的条目数量。原始发布条目 ·
17.0/changes/160在 pg_stat_statements 中跟踪 DEALLOCATE · 新功能
在
pg_stat_statements中跟踪DEALLOCATE(Dagfinn Ilmari Mannsåker, Michael Paquier)§DEALLOCATE名称在pg_stat_statements中存储为占位符。原始发布条目 ·
17.0/changes/161
安全证据
共 55 条记录,来自官方安全矩阵及发布说明的提及。只有安全快照明确列出此分支时才显示修复版本;仅有提及不能确定漏洞适用性或新修复。
CVE-2026-6638 · PostgreSQL REFRESH PUBLICATION allows SQL injection via table name · CVSS 3.7
SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.
以上保留官方英文漏洞说明。
本分支修复于:17.10。组件:core server。
官方受影响分支记录:17。
AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-6637 · PostgreSQL refint allows stack buffer overflow and SQL injection · CVSS 8.8
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.10。组件:contrib module。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-6479 · PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion · CVSS 7.5
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.10。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
发布说明中的提及:
CVE-2026-6478 · PostgreSQL discloses MD5-hashed passwords via covert timing channel · CVSS 6.5
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.10。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-6477 · PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory · CVSS 8.8
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.10。组件:client。
官方受影响分支记录:17。
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-6476 · PostgreSQL pg_createsubscriber allows SQL injection via subscription name · CVSS 7.2
SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_createsubscriber next runs. Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected. Versions before PostgreSQL 17 are unaffected.
以上保留官方英文漏洞说明。
本分支修复于:17.10。组件:client。
官方受影响分支记录:17。
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-6475 · PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice · CVSS 8.8
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.10。组件:client。
官方受影响分支记录:17。
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-6474 · PostgreSQL timeofday() can disclose portions of server memory · CVSS 4.3
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.10。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2026-6473 · PostgreSQL server undersizes allocations, via integer wraparound · CVSS 8.8
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.10。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-6472 · PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege · CVSS 5.4
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.10。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-6471 · PostgreSQL logical decoding can dlopen arbitrary file · CVSS 7.2
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-6470 · PostgreSQL fails to check type USAGE privilege · CVSS 4.3
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
发布说明中的提及:
CVE-2026-6469 · PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership · CVSS 3.8
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
发布说明中的提及:
CVE-2026-6464 · PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands · CVSS 8.1
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:client。
官方受影响分支记录:17。
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-2006 · PostgreSQL missing validation of multibyte character length executes arbitrary code · CVSS 8.8
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.8。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-2005 · PostgreSQL pgcrypto heap buffer overflow executes arbitrary code · CVSS 8.8
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.8。组件:contrib module。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-2004 · PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code · CVSS 8.8
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.8。组件:contrib module。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-2003 · PostgreSQL oidvector discloses a few bytes of memory · CVSS 4.3
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.8。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2026-19385 · PostgreSQL pg_dump heap buffer overflow executes arbitrary code · CVSS 8.8
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:client。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-18408 · PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client · CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:client。
官方受影响分支记录:17。
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-18024 · PostgreSQL ascii() function reads past end of buffer · CVSS 4.3
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2026-16241 · PostgreSQL ECPG integer underflow can crash the client · CVSS 3.8
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:client。
官方受影响分支记录:17。
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
发布说明中的提及:
CVE-2026-16239 · PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code · CVSS 8.8
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-16238 · PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code · CVSS 8.8
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
以上保留官方英文漏洞说明。
尚未记录本分支的修复版本。组件:core server。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-15742 · PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound · CVSS 8.8
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:contrib module。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-15741 · PostgreSQL expression deparse allows SQL injection via EXTRACT argument · CVSS 8.8
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14681 · PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL · CVSS 4.2
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-14680 · PostgreSQL type confusion via "internal" arguments · CVSS 8.8
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14679 · PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory · CVSS 8.2
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
发布说明中的提及:
CVE-2026-14678 · PostgreSQL pg_trgm picksplit reads past end of buffer · CVSS 4.3
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:contrib module。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2026-14677 · PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound · CVSS 8.8
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14676 · PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code · CVSS 8.8
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
以上保留官方英文漏洞说明。
尚未记录本分支的修复版本。组件:contrib module。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14673 · PostgreSQL amcheck does not clear untrusted search path · CVSS 3.8
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.
以上保留官方英文漏洞说明。
尚未记录本分支的修复版本。组件:contrib module。
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-14672 · PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle · CVSS 5.3
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2026-14671 · PostgreSQL refint plan cache type confusion executes arbitrary code · CVSS 8.8
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:contrib module。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14670 · PostgreSQL plperl tied object heap buffer overflow executes arbitrary code · CVSS 8.8
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14669 · PostgreSQL to_char heap buffer overflow executes arbitrary code · CVSS 8.8
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14668 · PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read · CVSS 8.1
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
发布说明中的提及:
CVE-2026-14666 · PostgreSQL row security caching disregards role modifications · CVSS 4.2
Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-14664 · PostgreSQL regexp heap buffer overflow executes arbitrary code · CVSS 8.8
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14663 · PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext · CVSS 6.5
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:contrib module。
官方受影响分支记录:17。
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-14662 · PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound · CVSS 8.8
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.11。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2025-8715 · PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server · CVSS 8.8
Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands inside a purpose-crafted object name. The same attacks can achieve SQL injection as a superuser of the restore target server. pg_dumpall, pg_restore, and pg_upgrade are also affected. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected. Versions before 11.20 are unaffected. CVE-2012-0868 had fixed this class of problem, but version 11.20 reintroduced it.
以上保留官方英文漏洞说明。
本分支修复于:17.6。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client · CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.6。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2025-8713 · PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table · CVSS 3.1
PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user to read sampled data that a row security policy intended to hide. PostgreSQL maintains statistics for tables by sampling data available in columns; this data is consulted during the query planning process. Prior to this release, a user could craft a leaky operator that bypassed view access control lists (ACLs) and bypassed row security policies in partitioning or table inheritance hierarchies. Reachable statistics data notably included histograms and most-common-values lists. CVE-2017-7484 and CVE-2019-10130 intended to close this class of vulnerability, but this gap remained. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.6。组件:core server。
官方受影响分支记录:17。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2025-4207 · PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation · CVSS 5.9
Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.5。组件:core server。
官方受影响分支记录:17。
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
发布说明中的提及:
CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound · CVSS 5.9
Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.7。组件:core server。
官方受影响分支记录:17。
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
发布说明中的提及:
CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege · CVSS 3.1
Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.7。组件:core server。
官方受影响分支记录:17。
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
发布说明中的提及:
CVE-2025-1094 · PostgreSQL quoting APIs miss neutralizing quoting syntax in text that fails encoding validation · CVSS 8.1
Improper neutralization of quoting syntax in PostgreSQL libpq functions PQescapeLiteral(), PQescapeIdentifier(), PQescapeString(), and PQescapeStringConn() allows a database input provider to achieve SQL injection in certain usage patterns. Specifically, SQL injection requires the application to use the function result to construct input to psql, the PostgreSQL interactive terminal. Similarly, improper neutralization of quoting syntax in PostgreSQL command line utility programs allows a source of command line arguments to achieve SQL injection when client_encoding is BIG5 and server_encoding is one of EUC_TW or MULE_INTERNAL. Versions before PostgreSQL 17.3, 16.7, 15.11, 14.16, and 13.19 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.3。组件:core server。
官方受影响分支记录:17。
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2024-10979 · PostgreSQL PL/Perl environment variable changes execute arbitrary code · CVSS 8.8
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH ). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Coby Abrams for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:17.1。组件:core server。
官方受影响分支记录:17。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2024-10978 · PostgreSQL SET ROLE, SET SESSION AUTHORIZATION reset to wrong user ID · CVSS 4.2
Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to use SET ROLE , SET SESSION AUTHORIZATION , or an equivalent feature. The problem arises when an application query uses parameters from the attacker or conveys query results to the attacker. If that query reacts to current_setting('role') or the current user ID, it may modify or return data as though the session had not used SET ROLE or SET SESSION AUTHORIZATION . The attacker does not control which incorrect user ID applies. Query text from less-privileged sources is not a concern here, because SET ROLE and SET SESSION AUTHORIZATION are not sandboxes for unvetted queries. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Tom Lane for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:17.1。组件:core server。
官方受影响分支记录:17。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2024-10977 · PostgreSQL libpq retains an error message from man-in-the-middle · CVSS 3.1
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a human or screen-scraper user of psql mistakes for valid query results. This is probably not a concern for clients where the user interface unambiguously indicates the boundary between one error message and other text. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected. The PostgreSQL project thanks Jacob Champion for reporting this problem.
以上保留官方英文漏洞说明。
本分支修复于:17.1。组件:client。
官方受影响分支记录:17。
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
发布说明中的提及:
CVE-2024-10976 · PostgreSQL row security below e.g. subqueries disregards user ID changes · CVSS 4.2
Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 fixed most interaction between row security and user ID changes. They missed cases where a subquery, WITH query, security invoker view, or SQL-language function references a table with a row-level security policy. This has the same consequences as the two earlier CVEs. That is to say, it leads to potentially incorrect policies being applied in cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is planned initially and then re-used across multiple SET ROLEs. Applying an incorrect policy may permit a user to complete otherwise-forbidden reads and modifications. This affects only databases that have used CREATE POLICY to define a row security policy. An attacker must tailor an attack to a particular application's pattern of query plan reuse, user ID changes, and role-specific row security policies. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.
以上保留官方英文漏洞说明。
本分支修复于:17.1。组件:core server。
官方受影响分支记录:17。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及: