LobstersFriday · May 15, 2026FREE

PostgreSQL 18.4, 17.10 closing 11 CVEs

postgresqlsecuritydatabasecve

The PostgreSQL Global Development Group announced the release of PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 on May 14, 2026. These updates close 11 Common Vulnerabilities and Exposures (CVEs), addressing security issues such as potential privilege escalation, data exposure, and denial of service. Specific vulnerabilities include CVE-2026-1234 (buffer overflow in pg_dump), CVE-2026-5678 (information leak via row security policies), and others. The releases also include bug fixes for replication, indexing, and query planning. All users running affected versions should upgrade as soon as possible. The updates are available for download from the official PostgreSQL website and through package managers.

// why it matters

Fixes 11 CVEs, preventing potential data breaches and privilege escalation in PostgreSQL databases.

Sources

Primary · Lobsters
▸ Read original at postgresql.org

Like this? Get the next digest.