PostgreSQL 18
当前稳定版 · 记录构建 18.6 · 2026-08-13
- 首次正式发布
- 2025-09-25
- 支持结束
- 2030-11-14
- 已收录发布版本
- 6
- 原始发布说明条目
- 561
手册与来源
PostgreSQL 18 本站手册 · 已加载 1151 页。
手册加载时间:2026-09-27T00:10:45.258078。
发布说明快照:2026-09-26。安全证据快照:2026-09-26。PDF 链接按本地文件是否存在提供,历史版本的语言与 HTML 手册可能不同。生命周期参见官方版本政策。
升级注意事项
跨大版本升级需要导出/恢复或 pg_upgrade 等迁移方式,应阅读沿途大版本的发布说明与目标版本手册。小版本更新也可能要求额外操作,请核对对应发布的迁移说明。官方升级政策。
18.0 的原始迁移说明
对于希望从任何以前的版本迁移数据的人来说,需要使用pg_dumpall进行转储/恢复,或者使用pg_upgrade或逻辑复制。有关迁移到新主要版本的通用信息,请参阅第 18.6 节。
版本 18 包含许多可能影响与以前版本兼容性的更改。请注意以下不兼容项:
发布历史
每次发布的原始变更均独立保留。CVE 数量表示发布说明中的提及,可能包含后续纠正,不等于本次新修复漏洞数。
首次发布变化
18.0 的原始条目,包含功能和兼容性变化。类别用于浏览,不是上游原始分类。
匹配 210 / 210 条原始变更。
将initdb默认更改为启用数据校验和 · 兼容性变化 · 迁移说明
将initdb默认更改为启用数据校验和(Greg Sabino Mullane)§
可以使用新的 initdb 选项
--no-data-checksums禁用校验和。pg_upgrade要求匹配集簇校验和设置,因此这个新选项对于升级不带校验和的旧集簇很有用。原始发布条目 ·
18.0/migration/001更改时区缩写处理 · 兼容性变化 · 迁移说明
更改时区缩写处理(Tom Lane)§
系统现在将优先考虑当前会话的时区缩写,然后检查服务器变量timezone_abbreviations。以前是先检查
timezone_abbreviations。原始发布条目 ·
18.0/migration/002弃用 MD5 密码认证 · 兼容性变化 · 迁移说明
对 MD5 密码的支持将在未来的主要版本中移除。CREATE ROLE和ALTER ROLE现在在设置 MD5 密码时会发出弃用警告。可以通过将md5_password_warnings参数设置为
off来禁用这些警告。原始发布条目 ·
18.0/migration/003禁止不记录 WAL 的分区表 · 兼容性变化 · 迁移说明
禁止不记录 WAL 的分区表(Michael Paquier)§
以前
ALTER TABLE SET [UN]LOGGED不执行任何操作,并且创建不记录 WAL 的分区表也不会导致其子表不记录 WAL。原始发布条目 ·
18.0/migration/006移除列 pg_backend_memory_contexts.parent · 兼容性变化 · 迁移说明
移除列
pg_backend_memory_contexts.parent(Melih Mutlu)§由于添加了
pg_backend_memory_contexts.path,不再需要此列。原始发布条目 ·
18.0/migration/009将 pg_backend_memory_contexts.level 和 pg_log_backend_memory_contexts() 更改为从1开始 · 兼容性变化 · 迁移说明
将
pg_backend_memory_contexts.level和pg_log_backend_memory_contexts()更改为从1开始(Melih Mutlu, Atsushi Torikoshi, David Rowley, Fujii Masao)§ § §这些以前是从零开始的。
原始发布条目 ·
18.0/migration/010更改全文检索,使其使用数据库集簇默认排序规则提供程序来读取配置文件和词典,而不再始终使用 libc · 兼容性变化 · 迁移说明
更改全文检索,使其使用数据库集簇默认排序规则提供程序来读取配置文件和词典,而不再始终使用 libc(Peter Eisentraut)§
如果数据库集簇默认使用的非 libc 排序规则提供程序(例如 ICU、builtin)对 LC_CTYPE 所处理字符的处理方式与 libc 不同,那么某些全文检索函数以及pg_trgm扩展的行为可能会发生变化。使用pg_upgrade升级此类数据库集簇时,建议在升级后重新索引所有与全文检索和pg_trgm相关的索引。
原始发布条目 ·
18.0/migration/011自动删除一些不必要的表自连接 · 新功能
自动删除一些不必要的表自连接(Andrey Lepikhov, Alexander Kuzmenkov, Alexander Korotkov, Alena Rybakina)§
可以使用服务器变量enable_self_join_elimination禁用此优化。
原始发布条目 ·
18.0/changes/001将一些 IN (VALUES ...) 转换为 x = ANY ... 以获得更好的优化器统计信息 · 新功能
将一些
IN (VALUES ...)转换为x = ANY ...以获得更好的优化器统计信息(Alena Rybakina, Andrei Lepikhov)§原始发布条目 ·
18.0/changes/002允许 SELECT DISTINCT 的键在内部重新排序以避免排序 · 新功能
允许
SELECT DISTINCT的键在内部重新排序以避免排序(Richard Guo)§可以使用enable_distinct_reordering禁用此优化。
原始发布条目 ·
18.0/changes/005添加异步 I/O 子系统 · 性能改进
添加异步 I/O 子系统(Andres Freund, Thomas Munro, Nazir Bilal Yavuz, Melanie Plageman)§ § § § § § § § § § §
此功能允许后端排队多个读取请求,从而实现更高效的顺序扫描、位图堆扫描、清理等。这由服务器变量io_method启用,并添加了服务器变量io_combine_limit和io_max_combine_limit来控制它。这还使得不支持
fadvise()的系统也可以将effective_io_concurrency和maintenance_io_concurrency设为大于零的值。新的系统视图pg_aios显示用于异步 I/O 的文件句柄。原始发布条目 ·
18.0/changes/020允许普通清理冻结某些页面,即使它们都是可见的 · 性能改进
允许普通清理冻结某些页面,即使它们都是可见的(Melanie Plageman)§ §
这减少了后期全关系冻结的开销。其激进性可以通过服务器变量和每表设置vacuum_max_eager_freeze_failure_rate控制。以前,在需要冻结之前,清理从不处理所有可见页面。
原始发布条目 ·
18.0/changes/023添加服务器变量vacuum_truncate以控制VACUUM期间的文件截断 · 性能改进
添加服务器变量vacuum_truncate以控制VACUUM期间的文件截断(Nathan Bossart, Gurjeet Singh)§
已经存在一个具有相同名称和行为的存储级别参数。
原始发布条目 ·
18.0/changes/024将服务器变量effective_io_concurrency和maintenance_io_concurrency的默认值增加到 16 · 性能改进
将服务器变量effective_io_concurrency和maintenance_io_concurrency的默认值增加到 16(Melanie Plageman)§ §
这更准确地反映了现代硬件。
原始发布条目 ·
18.0/changes/025增加服务器变量log_connections的日志记录粒度 · 新功能
增加服务器变量log_connections的日志记录粒度(Melanie Plageman)§
此服务器变量以前仅接受布尔值;布尔值用法仍受支持。
原始发布条目 ·
18.0/changes/026添加log_line_prefix转义 %L 以输出客户端IP地址 · 新功能
添加log_line_prefix转义
%L以输出客户端IP地址(Greg Sabino Mullane)§原始发布条目 ·
18.0/changes/028添加服务器变量log_lock_failures以记录锁获取失败 · 新功能
添加服务器变量log_lock_failures以记录锁获取失败(Yuki Seino, Fujii Masao)§ §
具体来说,它报告
SELECT ... NOWAIT锁失败。原始发布条目 ·
18.0/changes/029向VACUUM和ANALYZE添加延迟时间报告 · 新功能
向VACUUM和ANALYZE添加延迟时间报告(Bertrand Drouvot, Nathan Bossart)§ §
此信息出现在服务器日志、系统视图
pg_stat_progress_vacuum和pg_stat_progress_analyze以及VACUUM和ANALYZE在VERBOSE模式下的输出中;必须使用服务器变量track_cost_delay_timing启用跟踪。原始发布条目 ·
18.0/changes/031添加每后端 I/O 统计信息报告 · 新功能
添加每后端 I/O 统计信息报告(Bertrand Drouvot)§ §
统计信息通过
pg_stat_get_backend_io()访问。每后端 I/O 统计信息可以通过pg_stat_reset_backend_stats()清除。原始发布条目 ·
18.0/changes/034添加 pg_stat_io 列以字节报告 I/O 活动 · 新功能
添加
pg_stat_io列以字节报告 I/O 活动(Nazir Bilal Yavuz)§新列是
read_bytes、write_bytes和extend_bytes。op_bytes列(始终等于BLCKSZ)已移除。原始发布条目 ·
18.0/changes/035更改服务器变量track_wal_io_timing以控制在pg_stat_io而不是 pg_stat_wal中跟踪WAL计时 · 新功能
更改服务器变量track_wal_io_timing以控制在
pg_stat_io而不是pg_stat_wal中跟踪WAL计时(Bertrand Drouvot)§原始发布条目 ·
18.0/changes/037添加函数 pg_stat_get_backend_wal() 以返回每后端WAL统计信息 · 新功能
添加函数
pg_stat_get_backend_wal()以返回每后端WAL统计信息(Bertrand Drouvot)§每后端WAL统计信息可以通过
pg_stat_reset_backend_stats()清除。原始发布条目 ·
18.0/changes/039添加函数 pg_ls_summariesdir() 以专门列出 PGDATA/pg_wal/summaries 的内容 · 新功能
添加函数
pg_ls_summariesdir()以专门列出PGDATA/pg_wal/summaries的内容(Yushi Ogiwara)§原始发布条目 ·
18.0/changes/040添加列 pg_stat_checkpointer.num_done 以报告已完成的检查点数量 · 新功能
添加列
pg_stat_checkpointer.num_done以报告已完成的检查点数量(Anton A. Melnikov)§列
num_timed和num_requested同时统计已完成和已跳过的检查点。原始发布条目 ·
18.0/changes/041添加列到 pg_stat_database 以报告并行工作者活动 · 新功能
添加列到
pg_stat_database以报告并行工作者活动(Benoit Lobréau)§新列是
parallel_workers_to_launch和parallel_workers_launched。原始发布条目 ·
18.0/changes/043添加列 pg_backend_memory_contexts.type 以报告内存上下文的类型 · 新功能
添加列
pg_backend_memory_contexts.type以报告内存上下文的类型(David Rowley)§原始发布条目 ·
18.0/changes/046添加函数 pg_get_acl() 以检索数据库访问控制详细信息 · 新功能
添加函数
pg_get_acl()以检索数据库访问控制详细信息(Joel Jacobson)§ §原始发布条目 ·
18.0/changes/048添加函数 has_largeobject_privilege() 以检查大型对象权限 · 新功能
添加函数
has_largeobject_privilege()以检查大型对象权限(Yugo Nagata)§原始发布条目 ·
18.0/changes/049允许ALTER DEFAULT PRIVILEGES定义大型对象默认权限 · 新功能
允许ALTER DEFAULT PRIVILEGES定义大型对象默认权限(Takatsuka Haruka, Yugo Nagata, Laurenz Albe)§
原始发布条目 ·
18.0/changes/050添加预定义角色 pg_signal_autovacuum_worker · 新功能
添加预定义角色
pg_signal_autovacuum_worker(Kirill Reshke)§这允许向自动清理工作者发送信号。
原始发布条目 ·
18.0/changes/051添加对 OAuth 认证方法的支持 · 新功能
添加对 OAuth 认证方法的支持(Jacob Champion, Daniel Gustafsson, Thomas Munro)§
这为
pg_hba.conf添加了oauth认证方法、libpq OAuth 选项、一个用于加载令牌验证库的服务器变量oauth_validator_libraries,以及一个--with-libcurl配置标志,用于添加所需的编译时库。原始发布条目 ·
18.0/changes/052添加服务器变量ssl_tls13_ciphers以允许指定多个以冒号分隔的 TLSv1.3 密码套件 · 新功能
添加服务器变量ssl_tls13_ciphers以允许指定多个以冒号分隔的 TLSv1.3 密码套件(Erica Zhang, Daniel Gustafsson)§
原始发布条目 ·
18.0/changes/053将服务器变量ssl_groups的默认值更改为包含椭圆曲线 X25519 · 新功能
将服务器变量ssl_groups的默认值更改为包含椭圆曲线 X25519(Daniel Gustafsson, Jacob Champion)§
原始发布条目 ·
18.0/changes/054将服务器变量 ssl_ecdh_curve 重命名为ssl_groups,并允许指定多个以冒号分隔的ECDH曲线 · 新功能
将服务器变量
ssl_ecdh_curve重命名为ssl_groups,并允许指定多个以冒号分隔的ECDH曲线(Erica Zhang, Daniel Gustafsson)§以前的名称仍然有效。
原始发布条目 ·
18.0/changes/055添加服务器变量autovacuum_worker_slots以指定后台工作者的最大数量 · 新功能
添加服务器变量autovacuum_worker_slots以指定后台工作者的最大数量(Nathan Bossart)§
设置此变量后,autovacuum_max_workers可以在运行时调整到此最大值,而无需重新启动服务器。
原始发布条目 ·
18.0/changes/057允许指定触发 autovacuum 的死元组的固定数量 · BUG 修复
允许指定触发 autovacuum 的死元组的固定数量(Nathan Bossart, Frédéric Yhuel)§
服务器变量是autovacuum_vacuum_max_threshold。百分比仍用于触发。
原始发布条目 ·
18.0/changes/058更改服务器变量max_files_per_process以仅限制后端打开的文件 · 新功能
更改服务器变量max_files_per_process以仅限制后端打开的文件(Andres Freund)§
以前,postmaster 打开的文件也计入此限制。
原始发布条目 ·
18.0/changes/059添加服务器变量num_os_semaphores以报告所需信号量的数量 · 新功能
添加服务器变量num_os_semaphores以报告所需信号量的数量(Nathan Bossart)§
这对于操作系统配置很有用。
原始发布条目 ·
18.0/changes/060添加服务器变量extension_control_path以指定扩展控制文件的位置 · 新功能
添加服务器变量extension_control_path以指定扩展控制文件的位置(Peter Eisentraut, Matheus Alcantara)§ §
原始发布条目 ·
18.0/changes/061允许使用服务器变量idle_replication_slot_timeout自动使非活动复制槽失效 · 新功能
允许使用服务器变量idle_replication_slot_timeout自动使非活动复制槽失效(Nisha Moond, Bharath Rupireddy)§
原始发布条目 ·
18.0/changes/062添加服务器变量max_active_replication_origins以控制最大活动复制源 · 新功能
添加服务器变量max_active_replication_origins以控制最大活动复制源(Euler Taveira)§
这以前由max_replication_slots控制,但这个新设置允许在需要较少槽位的情况下具有更高的源计数。
原始发布条目 ·
18.0/changes/063将CREATE SUBSCRIPTION流式选项的默认值从 off 更改为 parallel · 新功能
将CREATE SUBSCRIPTION流式选项的默认值从
off更改为parallel(Vignesh C)§原始发布条目 ·
18.0/changes/065允许ALTER SUBSCRIPTION更改复制槽的两阶段提交行为 · 新功能
允许ALTER SUBSCRIPTION更改复制槽的两阶段提交行为(Hayato Kuroda, Ajin Cherian, Amit Kapila, Zhijie Hou)§ §
原始发布条目 ·
18.0/changes/066添加内置排序规则提供程序 PG_UNICODE_FAST · 新功能
添加内置排序规则提供程序
PG_UNICODE_FAST(Jeff Davis)§此区域设置支持大小写映射,但按代码点顺序排序,而非自然语言顺序。
原始发布条目 ·
18.0/changes/073添加函数以修改每关系和每列优化器统计信息 · 新功能
添加函数以修改每关系和每列优化器统计信息(Corey Huinker)§ § §
这些函数是
pg_restore_relation_stats()、pg_restore_attribute_stats()、pg_clear_relation_stats()和pg_clear_attribute_stats()。原始发布条目 ·
18.0/changes/075添加服务器变量file_copy_method以控制文件复制方法 · 新功能
添加服务器变量file_copy_method以控制文件复制方法(Nazir Bilal Yavuz)§
这控制
CREATE DATABASE ... STRATEGY=FILE_COPY和ALTER DATABASE ... SET TABLESPACE是使用文件复制还是克隆。原始发布条目 ·
18.0/changes/076要求主键/外键关系使用确定性排序规则或相同的非确定性排序规则 · 新功能
要求主键/外键关系使用确定性排序规则或相同的非确定性排序规则(Peter Eisentraut)§
如果这些要求不满足,pg_dump的恢复(pg_upgrade也使用)将失败;必须对模式进行更改才能使这些升级方法成功。
原始发布条目 ·
18.0/changes/079将列 NOT NULL 规范存储在 pg_constraint 中 · 新功能
将列
NOT NULL规范存储在pg_constraint中(Álvaro Herrera, Bernd Helmle)§ §这允许为
NOT NULL约束指定名称。这还向外部表添加了NOT NULL约束,并向本地表添加了NOT NULL继承控制。原始发布条目 ·
18.0/changes/080允许ALTER TABLE设置 NOT NULL 约束的 NOT VALID 属性 · 新功能
允许ALTER TABLE设置
NOT NULL约束的NOT VALID属性(Rushabh Lathia, Jian He)§原始发布条目 ·
18.0/changes/081向 json{b}_strip_nulls 添加可选参数,以允许删除数组中的空值元素 · 新功能
向
json{b}_strip_nulls添加可选参数,以允许删除数组中的空值元素(Florents Tselai)§原始发布条目 ·
18.0/changes/099添加函数 array_sort(),它对数组的第一维进行排序 · 新功能
添加函数
array_sort(),它对数组的第一维进行排序(Junwang Zhao, Jian He)§原始发布条目 ·
18.0/changes/100添加函数 array_reverse(),它反转数组的第一维 · 新功能
添加函数
array_reverse(),它反转数组的第一维(Aleksander Alekseev)§原始发布条目 ·
18.0/changes/101添加函数 casefold() 以允许更复杂的忽略大小写匹配 · 新功能
添加函数
casefold()以允许更复杂的忽略大小写匹配(Jeff Davis)§这允许更准确的比较,即一个字符可以有多个大写或小写等价物,或者大写或小写转换会改变字符的数量。
原始发布条目 ·
18.0/changes/107向 to_number() 添加罗马数字支持 · 新功能
向
to_number()添加罗马数字支持(Hunaid Sohail)§这通过
RN模式访问。原始发布条目 ·
18.0/changes/111允许 regexp_match[es]()/regexp_like()/regexp_replace()/regexp_count()/regexp_instr()/regexp_substr()/regexp_split_to_table()/regexp_split_to_array() 使用命名参数 · 新功能
允许
regexp_match[es]()/regexp_like()/regexp_replace()/regexp_count()/regexp_instr()/regexp_substr()/regexp_split_to_table()/regexp_split_to_array()使用命名参数(Jian He)§原始发布条目 ·
18.0/changes/116添加函数 PQfullProtocolVersion() 以报告完整的(包括次要版本)协议版本号 · 新功能
添加函数
PQfullProtocolVersion()以报告完整的(包括次要版本)协议版本号(Jacob Champion, Jelte Fennema-Nio)§原始发布条目 ·
18.0/changes/117向客户端报告search_path更改 · 新功能
向客户端报告search_path更改(Alexander Kukushkin, Jelte Fennema-Nio, Tomas Vondra)§ §
原始发布条目 ·
18.0/changes/119添加 libpq 连接参数 sslkeylogfile,该参数会转储SSL密钥材料 · 新功能
添加 libpq 连接参数
sslkeylogfile,该参数会转储SSL密钥材料(Abhishek Chanda, Daniel Gustafsson)§这对于调试很有用。
原始发布条目 ·
18.0/changes/121允许 psql 解析、绑定和关闭命名预处理语句 · 新功能
允许 psql 解析、绑定和关闭命名预处理语句(Anthonin Bonnefoy, Michael Paquier)§ §
这通过新命令
\parse、\bind_named和\close_prepared完成。原始发布条目 ·
18.0/changes/123添加 psql 反斜杠命令以允许发出管道查询 · 新功能
添加 psql 反斜杠命令以允许发出管道查询(Anthonin Bonnefoy)§ § §
新命令是
\startpipeline、\syncpipeline、\sendpipeline、\endpipeline、\flushrequest、\flush和\getresults。原始发布条目 ·
18.0/changes/124允许将管道状态添加到 psql 提示符并添加相关状态变量 · 新功能
允许将管道状态添加到 psql 提示符并添加相关状态变量(Anthonin Bonnefoy)§
新的提示符字符是
%P,新的 psql 变量是PIPELINE_SYNC_COUNT、PIPELINE_COMMAND_COUNT和PIPELINE_RESULT_COUNT。原始发布条目 ·
18.0/changes/125添加 psql 变量WATCH_INTERVAL以设置默认的 \watch 等待时间 · 新功能
添加 psql 变量
WATCH_INTERVAL以设置默认的\watch等待时间(Daniel Gustafsson)§原始发布条目 ·
18.0/changes/132添加pg_combinebackup选项 -k/--link 以启用硬链接 · 新功能
添加pg_combinebackup选项
-k/--link以启用硬链接(Israel Barth Rubio, Robert Haas)§只有某些文件可以硬链接。如果备份将独立使用,则不应使用此功能。
原始发布条目 ·
18.0/changes/136添加pg_resetwal选项 --char-signedness 以更改默认的 char 有符号性 · 新功能
添加pg_resetwal选项
--char-signedness以更改默认的char有符号性(Masahiko Sawada)§原始发布条目 ·
18.0/changes/139添加 pg_dump 和pg_dumpall选项 --sequence-data 以转储通常会被排除的序列数据 · 新功能
添加 pg_dump 和pg_dumpall选项
--sequence-data以转储通常会被排除的序列数据(Nathan Bossart)§ §原始发布条目 ·
18.0/changes/141添加pg_dump、pg_dumpall和pg_restore选项 --statistics-only、--no-statistics、--no-data 和 --no-schema · 新功能
添加pg_dump、pg_dumpall和pg_restore选项
--statistics-only、--no-statistics、--no-data和--no-schema(Corey Huinker, Jeff Davis)§原始发布条目 ·
18.0/changes/142添加选项 --no-policies 以禁用pg_dump、pg_dumpall、pg_restore中的行级安全策略处理 · 新功能
添加选项
--no-policies以禁用pg_dump、pg_dumpall、pg_restore中的行级安全策略处理(Nikolay Samokhvalov)§这对于迁移到具有不同策略的系统很有用。
原始发布条目 ·
18.0/changes/143添加pg_createsubscriber选项 --all 以创建所有数据库的逻辑副本 · 新功能
添加pg_createsubscriber选项
--all以创建所有数据库的逻辑副本(Shubham Khanna)§原始发布条目 ·
18.0/changes/148添加pg_recvlogical选项 --enable-failover 以指定故障切换槽 · 新功能
添加pg_recvlogical选项
--enable-failover以指定故障切换槽(Hayato Kuroda)§还添加选项
--enable-two-phase作为--two-phase的同义词,并弃用后者。原始发布条目 ·
18.0/changes/151分离注入点的加载和运行 · 新功能
分离注入点的加载和运行(Michael Paquier, Heikki Linnakangas)§ §
现在可以通过
INJECTION_POINT_LOAD()创建注入点但不运行,并且可以通过INJECTION_POINT_CACHED()运行这些注入点。原始发布条目 ·
18.0/changes/153允许使用 IS_INJECTION_POINT_ATTACHED() 的内联注入点测试代码 · 新功能
允许使用
IS_INJECTION_POINT_ATTACHED()的内联注入点测试代码(Heikki Linnakangas)§原始发布条目 ·
18.0/changes/155添加配置选项--with-libnuma以启用NUMA感知功能 · 新功能
添加配置选项
--with-libnuma以启用NUMA感知功能(Jakub Wartak, Bertrand Drouvot)§ § §函数
pg_numa_available()报告是否具备NUMA感知能力;系统视图pg_shmem_allocations_numa和pg_buffercache_numa报告共享内存在NUMA节点之间的分布。原始发布条目 ·
18.0/changes/160移除列pg_attribute.attcacheoff · 新功能
移除列
pg_attribute.attcacheoff(David Rowley)§原始发布条目 ·
18.0/changes/162将amgettreeheight、amconsistentequality和amconsistentordering添加到索引访问方法API · 新功能
将
amgettreeheight、amconsistentequality和amconsistentordering添加到索引访问方法API(Mark Dilger)§ §原始发布条目 ·
18.0/changes/164在pg_controldata中记录CPU对char类型的默认有符号性 · 新功能
在pg_controldata中记录CPU对
char类型的默认有符号性(Masahiko Sawada)§原始发布条目 ·
18.0/changes/166添加宏PG_MODULE_MAGIC_EXT以允许扩展报告其名称和版本 · 新功能
添加宏
PG_MODULE_MAGIC_EXT以允许扩展报告其名称和版本(Andrei Lepikhov)§此信息可以通过新函数
pg_get_loaded_modules()访问。原始发布条目 ·
18.0/changes/171文档指出SPI_connect()/SPI_connect_ext()总是返回成功(SPI_OK_CONNECT) · 新功能
文档指出
SPI_connect()/SPI_connect_ext()总是返回成功(SPI_OK_CONNECT)(Stepan Neretin)§错误总是通过
ereport()报告。原始发布条目 ·
18.0/changes/172添加扩展pg_logicalinspect以检查逻辑快照 · 新功能
添加扩展pg_logicalinspect以检查逻辑快照(Bertrand Drouvot)§
原始发布条目 ·
18.0/changes/177添加扩展pg_overexplain,它向EXPLAIN输出添加调试细节 · 新功能
添加扩展pg_overexplain,它向
EXPLAIN输出添加调试细节(Robert Haas)§原始发布条目 ·
18.0/changes/178允许将客户端的SCRAM认证传递给postgres_fdw服务器 · 新功能
允许将客户端的SCRAM认证传递给postgres_fdw服务器(Matheus Alcantara, Peter Eisentraut)§
这避免了在数据库中存储postgres_fdw认证信息,并通过postgres_fdw
use_scram_passthrough连接选项启用。libpq使用新的连接参数scram_client_key和scram_server_key。原始发布条目 ·
18.0/changes/180向passwordcheck添加可配置变量min_password_length · 新功能
向passwordcheck添加可配置变量
min_password_length(Emanuele Musella, Maurizio Boriani)§这控制最小密码长度。
原始发布条目 ·
18.0/changes/184添加isn服务器变量weak以控制是否接受无效的校验位 · 新功能
添加isn服务器变量
weak以控制是否接受无效的校验位(Viktor Holmberg)§这以前仅由函数
isn_weak()控制。原始发布条目 ·
18.0/changes/186允许对值进行排序以加快btree_gist索引的构建 · 新功能
允许对值进行排序以加快btree_gist索引的构建(Bernd Helmle, Andrey Borodin)§
原始发布条目 ·
18.0/changes/187添加amcheck检查函数gin_index_check()以验证GIN索引 · 新功能
添加amcheck检查函数
gin_index_check()以验证GIN索引(Grigory Kryachko, Heikki Linnakangas, Andrey Borodin)§原始发布条目 ·
18.0/changes/188添加函数pg_buffercache_evict_relation()和pg_buffercache_evict_all()以逐出未钉住的共享缓冲区 · 新功能
添加函数
pg_buffercache_evict_relation()和pg_buffercache_evict_all()以逐出未钉住的共享缓冲区(Nazir Bilal Yavuz)§现有函数
pg_buffercache_evict()现在返回缓冲区刷新状态。原始发布条目 ·
18.0/changes/189允许CREATE TABLE AS和DECLARE的查询被pg_stat_statements跟踪 · 新功能
允许CREATE TABLE AS和DECLARE的查询被pg_stat_statements跟踪(Anthonin Bonnefoy)§
它们现在也被分配了查询ID。
原始发布条目 ·
18.0/changes/192添加pg_stat_statements列以报告并行活动 · 新功能
添加
pg_stat_statements列以报告并行活动(Guillaume Lelarge)§新列是
parallel_workers_to_launch和parallel_workers_launched。原始发布条目 ·
18.0/changes/194添加pgcrypto算法sha256crypt和sha512crypt · 新功能
添加pgcrypto算法
sha256crypt和sha512crypt(Bernd Helmle)§原始发布条目 ·
18.0/changes/196添加函数fips_mode()以报告服务器的FIPS模式 · 新功能
添加函数
fips_mode()以报告服务器的FIPS模式(Daniel Gustafsson)§原始发布条目 ·
18.0/changes/198添加pgcrypto服务器变量builtin_crypto_enabled以允许禁用内置非FIPS模式密码学函数 · 新功能
添加pgcrypto服务器变量
builtin_crypto_enabled以允许禁用内置非FIPS模式密码学函数(Daniel Gustafsson, Joe Conway)§这对于保证FIPS模式行为很有用。
原始发布条目 ·
18.0/changes/199
安全证据
共 47 条记录,来自官方安全矩阵及发布说明的提及。只有安全快照明确列出此分支时才显示修复版本;仅有提及不能确定漏洞适用性或新修复。
CVE-2026-6638 · PostgreSQL REFRESH PUBLICATION allows SQL injection via table name · CVSS 3.7
SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table creator to execute arbitrary SQL with the subscription's publication-side credentials. The attack takes effect at the next REFRESH PUBLICATION. Within major versions 16, 17, and 18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected. Versions before PostgreSQL 16 are unaffected.
以上保留官方英文漏洞说明。
本分支修复于:18.4。组件:core server。
官方受影响分支记录:18。
AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-6637 · PostgreSQL refint allows stack buffer overflow and SQL injection · CVSS 8.8
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.4。组件:contrib module。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-6575 · PostgreSQL pg_restore_attribute_stats accepts values that cause query planning to read past end of stats array · CVSS 4.3
Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which causes query planning to read past end of one array. This allows a table maintainer to infer memory values past that array end. Within major version 18, minor versions before PostgreSQL 18.4 are affected. Versions before PostgreSQL 18 are unaffected.
以上保留官方英文漏洞说明。
本分支修复于:18.4。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2026-6479 · PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion · CVSS 7.5
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.4。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
发布说明中的提及:
CVE-2026-6478 · PostgreSQL discloses MD5-hashed passwords via covert timing channel · CVSS 6.5
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.4。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-6477 · PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory · CVSS 8.8
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.4。组件:client。
官方受影响分支记录:18。
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-6476 · PostgreSQL pg_createsubscriber allows SQL injection via subscription name · CVSS 7.2
SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_createsubscriber next runs. Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected. Versions before PostgreSQL 17 are unaffected.
以上保留官方英文漏洞说明。
本分支修复于:18.4。组件:client。
官方受影响分支记录:18。
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-6475 · PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice · CVSS 8.8
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account. It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to features like shared_preload_libraries. Hence, the attack has practical implications only if one takes relevant action between these commands and server start, like moving the files to a different VM or snapshotting the VM. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.4。组件:client。
官方受影响分支记录:18。
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-6474 · PostgreSQL timeofday() can disclose portions of server memory · CVSS 4.3
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.4。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2026-6473 · PostgreSQL server undersizes allocations, via integer wraparound · CVSS 8.8
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running the database. In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.4。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-6472 · PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege · CVSS 5.4
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.4。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-6471 · PostgreSQL logical decoding can dlopen arbitrary file · CVSS 7.2
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-6470 · PostgreSQL fails to check type USAGE privilege · CVSS 4.3
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
发布说明中的提及:
CVE-2026-6469 · PostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership · CVSS 3.8
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
发布说明中的提及:
CVE-2026-6464 · PostgreSQL psql COPY FROM STDIN early failure processes data lines as psql commands · CVSS 8.1
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has no inherent control over the data rows, so a complete attack requires the attacker to separately acquire control of both the server and the data rows. Alternatively, an attacker controlling data rows alone might complete an attack through a coincidental error that they don't control. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:client。
官方受影响分支记录:18。
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-2007 · PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory · CVSS 8.2
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.2。组件:contrib module。
官方受影响分支记录:18。
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
发布说明中的提及:
CVE-2026-2006 · PostgreSQL missing validation of multibyte character length executes arbitrary code · CVSS 8.8
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.2。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-2005 · PostgreSQL pgcrypto heap buffer overflow executes arbitrary code · CVSS 8.8
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.2。组件:contrib module。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-2004 · PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code · CVSS 8.8
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.2。组件:contrib module。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-2003 · PostgreSQL oidvector discloses a few bytes of memory · CVSS 4.3
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.2。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2026-19385 · PostgreSQL pg_dump heap buffer overflow executes arbitrary code · CVSS 8.8
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:client。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-18408 · PostgreSQL psql \unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client · CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient for an attack. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. Non-core use of \restrict would be affected, but we've not identified non-core use. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:client。
官方受影响分支记录:18。
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-18024 · PostgreSQL ascii() function reads past end of buffer · CVSS 4.3
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2026-16241 · PostgreSQL ECPG integer underflow can crash the client · CVSS 3.8
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but rare cases might achieve client-specific integrity impact via the write. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:client。
官方受影响分支记录:18。
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
发布说明中的提及:
CVE-2026-16239 · PostgreSQL type confusion in cursor CLOSE + DECLARE executes arbitrary code · CVSS 8.8
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-16238 · PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code · CVSS 8.8
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-15742 · PostgreSQL fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound · CVSS 8.8
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:contrib module。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-15741 · PostgreSQL expression deparse allows SQL injection via EXTRACT argument · CVSS 8.8
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14681 · PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL · CVSS 4.2
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-14680 · PostgreSQL type confusion via "internal" arguments · CVSS 8.8
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14679 · PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory · CVSS 8.2
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
发布说明中的提及:
CVE-2026-14678 · PostgreSQL pg_trgm picksplit reads past end of buffer · CVSS 4.3
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:contrib module。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2026-14677 · PostgreSQL 32-bit pltcl and plperl undersize allocations, via integer wraparound · CVSS 8.8
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14676 · PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code · CVSS 8.8
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:contrib module。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14673 · PostgreSQL amcheck does not clear untrusted search path · CVSS 3.8
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary functions as the owners of expression indexes that depend on the search path, via setting a hostile search path before calling the amcheck function. Within major versions 18, 16, 15, and 14, minor versions before PostgreSQL 18.6, 16.15, 15.19, and 14.24 are affected. PostgreSQL 17 is unaffected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:contrib module。
官方受影响分支记录:18。
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-14672 · PostgreSQL observable response discrepancy with non-default scram_iterations provides user existence oracle · CVSS 5.3
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.6, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
发布说明中的提及:
CVE-2026-14671 · PostgreSQL refint plan cache type confusion executes arbitrary code · CVSS 8.8
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system user running the database. The fix for this emerged as a non-security bug report, and the fix appear in the git repository with subject "refint: Remove plan cache.", without a CVE number. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:contrib module。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14670 · PostgreSQL plperl tied object heap buffer overflow executes arbitrary code · CVSS 8.8
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14669 · PostgreSQL to_char heap buffer overflow executes arbitrary code · CVSS 8.8
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14668 · PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read · CVSS 8.1
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
发布说明中的提及:
CVE-2026-14666 · PostgreSQL row security caching disregards role modifications · CVSS 4.2
Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes require a different policy, via plan reuse. Stale policies continue until some other event invalidates the cache or connection termination ends the session. This permits a user to complete reads and modifications that were recently permitted but now forbidden. An attacker must tailor an attack to a particular application's pattern of privilege removal and role-specific row security policies. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-14664 · PostgreSQL regexp heap buffer overflow executes arbitrary code · CVSS 8.8
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2026-14663 · PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext · CVSS 6.5
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:contrib module。
官方受影响分支记录:18。
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
发布说明中的提及:
CVE-2026-14662 · PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound · CVSS 8.8
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.6。组件:core server。
官方受影响分支记录:18。
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2025-8714 · PostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql client · CVSS 8.8
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql meta-commands. pg_dumpall is also affected. pg_restore is affected when used to generate a plain-format dump. This is similar to MySQL CVE-2024-21096. Versions before PostgreSQL 17.6, 16.10, 15.14, 14.19, and 13.22 are affected.
以上保留官方英文漏洞说明。
尚未记录本分支的修复版本。组件:core server。
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
发布说明中的提及:
CVE-2025-12818 · PostgreSQL libpq undersizes allocations, via integer wraparound · CVSS 5.9
Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.1。组件:core server。
官方受影响分支记录:18。
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
发布说明中的提及:
CVE-2025-12817 · PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege · CVSS 3.1
Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
以上保留官方英文漏洞说明。
本分支修复于:18.1。组件:core server。
官方受影响分支记录:18。
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
发布说明中的提及: