Back to blog

// OSSeva Blog

Security

PostgreSQL Vulnerabilities by Version: CVEs for PostgreSQL 11, 12, 13, 14 and Later

Randall McClure9 min read

The short answer

PostgreSQL supports each major version for five years and then ships one final minor release. Versions 18, 17, 16, 15 and 14 are supported today, and 14 is next: the project has said it stops receiving fixes on 12 November 2026. PostgreSQL 13 reached end of life on 13 November 2025 with 13.23, 12 on 21 November 2024 with 12.22, and 11 on 9 November 2023 with 11.22. The three sets of minor releases in 2026, on 12 February, 14 May and 13 August, fixed 44 CVEs, and PostgreSQL scored 28 of them 7.0 or higher. None of those fixes has a release for 13 or older.

PostgreSQL versions and their 2026 CVEs

Dates and minor versions are from postgresql.org's versioning page. The CVE counts are the 2026 entries on its security page that list each major version as affected.

VersionStatusCurrent or final minor2026 CVEs listing itOf those, 7.0 or higherUpstream fix on this line
18Supported until 14 November 203018.6442818.6
17Supported until 8 November 202917.11392517.11
16Supported until 9 November 202816.15382416.15
15Supported until 11 November 202715.19362415.19
14Supported until 12 November 202614.24362414.24; one final release is due
13End of life 13 November 202513.23Not assessedNot assessedNo upstream fix on this line
12End of life 21 November 202412.22Not assessedNot assessedNo upstream fix on this line
11End of life 9 November 202311.22Not assessedNot assessedNo upstream fix on this line

The 2026 announcements describe the affected range as "Supported, Vulnerable Versions: 14 - 18". The project checks supported versions only, so "not assessed" is the accurate entry for 13 and older. It is not a finding that they are safe. postgresql.org also states that no further security patches are made available for end-of-life versions. See the PostgreSQL end of life tracker for every version.

The 2026 minor releases

ReleasedVersionsCVEs fixed7.0 or higher
12 February 202618.2, 17.8, 16.12, 15.16, 14.2154
14 May 202618.4, 17.10, 16.14, 15.18, 14.23116
13 August 202618.6, 17.11, 16.15, 15.19, 14.242818

The August release skipped 18.5, which was not shipped because of a regression, and it asks some users to take extra steps after updating for parallel GIN index builds, btree_gist and ltree. Of the 44 CVEs, 27 are in the core server, 10 in contrib modules and 7 in client programs and libraries such as libpq, psql and pg_dump. Contrib modules are not installed by default from source, but many binary packages include them.

Notable PostgreSQL CVEs by version

PostgreSQL is its own CVE numbering authority and scores its records with CVSS 3.1. NVD has not added its own score to the 2026 records cited here, so those scores are PostgreSQL's; for older records the score is NVD's own. None is in CISA's Known Exploited Vulnerabilities catalogue.

CVEIssueCVSSFixed inLines with no fix
CVE-2026-14680Gaps in blocking SQL calls to functions with "internal" arguments let any user run code as the server's OS user8.818.6, 17.11, 16.15, 15.19, 14.2413 and older not assessed
CVE-2026-16239Re-creating a cursor with different types causes type confusion and code execution8.818.6, 17.11, 16.15, 15.19, 14.2413 and older not assessed
CVE-2026-15741EXTRACT() deparse lets an object owner inject SQL that runs as a superuser, including through pg_dump8.818.6, 17.11, 16.15, 15.19, 14.2413 and older not assessed
CVE-2026-19385A crafted transform list overflows a heap buffer in pg_dump and runs code as the pg_dump user8.818.6, 17.11, 16.15, 15.19, 14.2413 and older not assessed
CVE-2026-6473Integer wraparound undersizes server allocations8.818.4, 17.10, 16.14, 15.18, 14.2313 and older not assessed
CVE-2026-6477libpq large object functions let a server superuser overwrite client stack memory8.818.4, 17.10, 16.14, 15.18, 14.2313 and older not assessed
CVE-2026-2006Missing multibyte length validation lets a database user overrun a buffer and run code8.818.2, 17.8, 16.12, 15.16, 14.2113 and older not assessed
CVE-2026-6479Uncontrolled recursion in SSL and GSS negotiation lets a client that reaches the Unix socket, or the TCP port when SSL and GSS are off, keep the server down7.518.4, 17.10, 16.14, 15.18, 14.2313 and older not assessed
CVE-2025-8714A superuser of the origin server can run code in psql through a pg_dump file8.817.6, 16.10, 15.14, 14.19, 13.2212 and older not assessed
CVE-2025-8715A newline in an object name runs code in psql and on the restore target server8.817.6, 16.10, 15.14, 14.19, 13.2212 and older not assessed
CVE-2025-1094libpq quoting functions miss quoting syntax in invalidly encoded text, allowing SQL injection through psql8.117.3, 16.7, 15.11, 14.16, 13.1912 and older not assessed
CVE-2024-10979PL/Perl environment variable changes let an unprivileged user run code8.8 (NVD)17.1, 16.5, 15.9, 14.14, 13.17, 12.2111 not assessed
CVE-2024-7348Replacing a relation while pg_dump runs executes arbitrary SQL as the pg_dump user7.5 (NVD); 8.8 (PostgreSQL)16.4, 15.8, 14.13, 13.16, 12.2011 not assessed
CVE-2023-5869Integer overflow in array modification overruns a buffer and allows code execution8.8 (NVD)16.1, 15.5, 14.10, 13.13, 12.17, 11.22Fixed on every line in this guide

Most of the 2026 code execution CVEs need only a database login. A user who can connect and run SQL can reach CVE-2026-2006, CVE-2026-6473, CVE-2026-14680 and CVE-2026-16239, and the result is code running as the operating system user that runs the database. The pg_dump and psql issues work the other way: a hostile object definition or a compromised origin server attacks the person or job running the dump, which makes backup hosts part of the exposure.

What each version gets

PostgreSQL 15 to 18

These versions get every fix above that applies to them in the August 2026 releases, 18.6, 17.11, 16.15 and 15.19. A minor release needs no dump and restore: stop the server, install the new binaries and start it again, after reading the release notes for extra steps. PostgreSQL 15 is the next to reach end of life, on 11 November 2027. See PostgreSQL 15 end of life.

PostgreSQL 14

14.24 carries the 36 fixes from 2026 that list 14. The project's announcements say 14 stops receiving fixes on 12 November 2026, and the versioning policy says a final minor release ships at that point. After that, 14 will be where 13 is now. See PostgreSQL 14 end of life and the PostgreSQL 14 upgrade guide.

PostgreSQL 13

13.23, released on 13 November 2025, was the final release, and it fixed CVE-2025-12818 and CVE-2025-12817. Earlier 13 releases fixed the 2025 pg_dump CVEs in 13.22 and CVE-2025-1094 in 13.19, so a server on an older 13.x minor is missing those as well. None of the 44 CVEs from 2026 has a 13 release. See PostgreSQL 13 end of life.

PostgreSQL 12 and 11

12 ended with 12.22, and its last security fixes were the November 2024 set in 12.21, including CVE-2024-10979. 11 ended with 11.22 in November 2023, which fixed CVE-2023-5869. Neither has any fix from 2025 or 2026, including CVE-2025-1094 and the pg_dump CVEs. See PostgreSQL 12 end of life and PostgreSQL 11 end of life.

What to do on each version

  • 15 to 18. Take each quarterly minor release. They are low-risk by design and carry the security fixes.
  • 14. Move to 14.24 now, and take the final 14 release in November. Plan the major upgrade to 17 or 18, or arrange patched builds before 12 November 2026.
  • 13, 12 and 11. Upgrade to 17 or 18 with pg_upgrade or logical replication, or take patched builds. Until then, limit who can log in and create objects, remove untrusted procedural languages and contrib modules you do not use, and run pg_dump and psql restores from current client binaries, which you can install alongside an older server.

For the upgrade itself, see the PostgreSQL major version upgrade guide, and for why these CVE classes matter after end of life, PostgreSQL security after EOL.

Where OSSeva fits

OSSeva backports PostgreSQL security and data-corruption fixes to 11, 12 and 13 now, and to 14 once community support ends on 12 November 2026. Patched builds install like a minor release, on the same data directory and under Patroni or repmgr, and ship as signed DEB and RPM packages, tarballs and container images with the contrib modules rebuilt and tested. They are available now on the Patch, Assure and Operate tiers, and PostgreSQL 15 is covered on Assure and Operate today. Assure adds migration planning to 17 or 18 and a compliance attestation package, and Operate adds 24/7 replication and failover monitoring with a 15-minute P1 response. See PostgreSQL extended support.

Tags

PostgreSQLCVEPostgreSQL 13PostgreSQL 14End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.