DATABASES Signal 396
PostgreSQL 18.6, 17.11, 16.15, 15.19, 14.24 and 19 Beta 3 Released!
The PostgreSQL Global Development Group released updates for versions 18.6, 17.11, 16.15, 15.19, 14.24 and PostgreSQL 19 Beta 3, closing 28 security vulnerabilities and over 110 bugs.
Multiple CVEs rated CVSS 8.8 enable arbitrary code execution through heap buffer overflows in regexp, to_char, plperl, pg_stat_statements, pg_dump, and type confusion paths. Operators on any supported PostgreSQL version should upgrade immediately, and those on PostgreSQL 14 must plan a migration before its November 12, 2026 end-of-life.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
Twenty-eight security vulnerabilities were fixed, with many rated CVSS 8.8 for arbitrary code execution via heap buffer overflows and type confusion.
PostgreSQL 18.5 was skipped due to a regression, so the release jumps from 18.4 directly to 18.6.
Three changes involving parallel GIN index builds, btree_gist, and ltree may require extra steps after updating.
THE CLUSTER
↗