// OSSeva Blog
SecurityPostgreSQL Vulnerabilities by Version: CVEs for PostgreSQL 11, 12, 13, 14 and Later
The short answer
PostgreSQL supports each major version for five years and then ships one final minor release. Versions 18, 17, 16, 15 and 14 are supported today, and 14 is next: the project has said it stops receiving fixes on 12 November 2026. PostgreSQL 13 reached end of life on 13 November 2025 with 13.23, 12 on 21 November 2024 with 12.22, and 11 on 9 November 2023 with 11.22. The three sets of minor releases in 2026, on 12 February, 14 May and 13 August, fixed 44 CVEs, and PostgreSQL scored 28 of them 7.0 or higher. None of those fixes has a release for 13 or older.
PostgreSQL versions and their 2026 CVEs
Dates and minor versions are from postgresql.org's versioning page. The CVE counts are the 2026 entries on its security page that list each major version as affected.
| Version | Status | Current or final minor | 2026 CVEs listing it | Of those, 7.0 or higher | Upstream fix on this line |
|---|---|---|---|---|---|
| 18 | Supported until 14 November 2030 | 18.6 | 44 | 28 | 18.6 |
| 17 | Supported until 8 November 2029 | 17.11 | 39 | 25 | 17.11 |
| 16 | Supported until 9 November 2028 | 16.15 | 38 | 24 | 16.15 |
| 15 | Supported until 11 November 2027 | 15.19 | 36 | 24 | 15.19 |
| 14 | Supported until 12 November 2026 | 14.24 | 36 | 24 | 14.24; one final release is due |
| 13 | End of life 13 November 2025 | 13.23 | Not assessed | Not assessed | No upstream fix on this line |
| 12 | End of life 21 November 2024 | 12.22 | Not assessed | Not assessed | No upstream fix on this line |
| 11 | End of life 9 November 2023 | 11.22 | Not assessed | Not assessed | No upstream fix on this line |
The 2026 announcements describe the affected range as "Supported, Vulnerable Versions: 14 - 18". The project checks supported versions only, so "not assessed" is the accurate entry for 13 and older. It is not a finding that they are safe. postgresql.org also states that no further security patches are made available for end-of-life versions. See the PostgreSQL end of life tracker for every version.
The 2026 minor releases
| Released | Versions | CVEs fixed | 7.0 or higher |
|---|---|---|---|
| 12 February 2026 | 18.2, 17.8, 16.12, 15.16, 14.21 | 5 | 4 |
| 14 May 2026 | 18.4, 17.10, 16.14, 15.18, 14.23 | 11 | 6 |
| 13 August 2026 | 18.6, 17.11, 16.15, 15.19, 14.24 | 28 | 18 |
The August release skipped 18.5, which was not shipped because of a regression, and it asks some users to take extra steps after updating for parallel GIN index builds, btree_gist and ltree. Of the 44 CVEs, 27 are in the core server, 10 in contrib modules and 7 in client programs and libraries such as libpq, psql and pg_dump. Contrib modules are not installed by default from source, but many binary packages include them.
Notable PostgreSQL CVEs by version
PostgreSQL is its own CVE numbering authority and scores its records with CVSS 3.1. NVD has not added its own score to the 2026 records cited here, so those scores are PostgreSQL's; for older records the score is NVD's own. None is in CISA's Known Exploited Vulnerabilities catalogue.
| CVE | Issue | CVSS | Fixed in | Lines with no fix |
|---|---|---|---|---|
| CVE-2026-14680 | Gaps in blocking SQL calls to functions with "internal" arguments let any user run code as the server's OS user | 8.8 | 18.6, 17.11, 16.15, 15.19, 14.24 | 13 and older not assessed |
| CVE-2026-16239 | Re-creating a cursor with different types causes type confusion and code execution | 8.8 | 18.6, 17.11, 16.15, 15.19, 14.24 | 13 and older not assessed |
| CVE-2026-15741 | EXTRACT() deparse lets an object owner inject SQL that runs as a superuser, including through pg_dump | 8.8 | 18.6, 17.11, 16.15, 15.19, 14.24 | 13 and older not assessed |
| CVE-2026-19385 | A crafted transform list overflows a heap buffer in pg_dump and runs code as the pg_dump user | 8.8 | 18.6, 17.11, 16.15, 15.19, 14.24 | 13 and older not assessed |
| CVE-2026-6473 | Integer wraparound undersizes server allocations | 8.8 | 18.4, 17.10, 16.14, 15.18, 14.23 | 13 and older not assessed |
| CVE-2026-6477 | libpq large object functions let a server superuser overwrite client stack memory | 8.8 | 18.4, 17.10, 16.14, 15.18, 14.23 | 13 and older not assessed |
| CVE-2026-2006 | Missing multibyte length validation lets a database user overrun a buffer and run code | 8.8 | 18.2, 17.8, 16.12, 15.16, 14.21 | 13 and older not assessed |
| CVE-2026-6479 | Uncontrolled recursion in SSL and GSS negotiation lets a client that reaches the Unix socket, or the TCP port when SSL and GSS are off, keep the server down | 7.5 | 18.4, 17.10, 16.14, 15.18, 14.23 | 13 and older not assessed |
| CVE-2025-8714 | A superuser of the origin server can run code in psql through a pg_dump file | 8.8 | 17.6, 16.10, 15.14, 14.19, 13.22 | 12 and older not assessed |
| CVE-2025-8715 | A newline in an object name runs code in psql and on the restore target server | 8.8 | 17.6, 16.10, 15.14, 14.19, 13.22 | 12 and older not assessed |
| CVE-2025-1094 | libpq quoting functions miss quoting syntax in invalidly encoded text, allowing SQL injection through psql | 8.1 | 17.3, 16.7, 15.11, 14.16, 13.19 | 12 and older not assessed |
| CVE-2024-10979 | PL/Perl environment variable changes let an unprivileged user run code | 8.8 (NVD) | 17.1, 16.5, 15.9, 14.14, 13.17, 12.21 | 11 not assessed |
| CVE-2024-7348 | Replacing a relation while pg_dump runs executes arbitrary SQL as the pg_dump user | 7.5 (NVD); 8.8 (PostgreSQL) | 16.4, 15.8, 14.13, 13.16, 12.20 | 11 not assessed |
| CVE-2023-5869 | Integer overflow in array modification overruns a buffer and allows code execution | 8.8 (NVD) | 16.1, 15.5, 14.10, 13.13, 12.17, 11.22 | Fixed on every line in this guide |
Most of the 2026 code execution CVEs need only a database login. A user who can connect and run SQL can reach CVE-2026-2006, CVE-2026-6473, CVE-2026-14680 and CVE-2026-16239, and the result is code running as the operating system user that runs the database. The pg_dump and psql issues work the other way: a hostile object definition or a compromised origin server attacks the person or job running the dump, which makes backup hosts part of the exposure.
What each version gets
PostgreSQL 15 to 18
These versions get every fix above that applies to them in the August 2026 releases, 18.6, 17.11, 16.15 and 15.19. A minor release needs no dump and restore: stop the server, install the new binaries and start it again, after reading the release notes for extra steps. PostgreSQL 15 is the next to reach end of life, on 11 November 2027. See PostgreSQL 15 end of life.
PostgreSQL 14
14.24 carries the 36 fixes from 2026 that list 14. The project's announcements say 14 stops receiving fixes on 12 November 2026, and the versioning policy says a final minor release ships at that point. After that, 14 will be where 13 is now. See PostgreSQL 14 end of life and the PostgreSQL 14 upgrade guide.
PostgreSQL 13
13.23, released on 13 November 2025, was the final release, and it fixed CVE-2025-12818 and CVE-2025-12817. Earlier 13 releases fixed the 2025 pg_dump CVEs in 13.22 and CVE-2025-1094 in 13.19, so a server on an older 13.x minor is missing those as well. None of the 44 CVEs from 2026 has a 13 release. See PostgreSQL 13 end of life.
PostgreSQL 12 and 11
12 ended with 12.22, and its last security fixes were the November 2024 set in 12.21, including CVE-2024-10979. 11 ended with 11.22 in November 2023, which fixed CVE-2023-5869. Neither has any fix from 2025 or 2026, including CVE-2025-1094 and the pg_dump CVEs. See PostgreSQL 12 end of life and PostgreSQL 11 end of life.
What to do on each version
- 15 to 18. Take each quarterly minor release. They are low-risk by design and carry the security fixes.
- 14. Move to 14.24 now, and take the final 14 release in November. Plan the major upgrade to 17 or 18, or arrange patched builds before 12 November 2026.
- 13, 12 and 11. Upgrade to 17 or 18 with pg_upgrade or logical replication, or take patched builds. Until then, limit who can log in and create objects, remove untrusted procedural languages and contrib modules you do not use, and run pg_dump and psql restores from current client binaries, which you can install alongside an older server.
For the upgrade itself, see the PostgreSQL major version upgrade guide, and for why these CVE classes matter after end of life, PostgreSQL security after EOL.
Where OSSeva fits
OSSeva backports PostgreSQL security and data-corruption fixes to 11, 12 and 13 now, and to 14 once community support ends on 12 November 2026. Patched builds install like a minor release, on the same data directory and under Patroni or repmgr, and ship as signed DEB and RPM packages, tarballs and container images with the contrib modules rebuilt and tested. They are available now on the Patch, Assure and Operate tiers, and PostgreSQL 15 is covered on Assure and Operate today. Assure adds migration planning to 17 or 18 and a compliance attestation package, and Operate adds 24/7 replication and failover monitoring with a 15-minute P1 response. See PostgreSQL extended support.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.