PostgreSQL 11.x — End of Life

EOL High risk
EOL: Nov 9, 20231 release in this series8 CVEs

PostgreSQL 11.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatus
11Oct 18, 2018Nov 9, 202311.22EOL

CVEs affecting PostgreSQL 11.x (8)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-6637HIGH8.80.04%11Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as th…May 14, 2026
CVE-2026-6479HIGH7.50.02%11Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX …May 14, 2026
CVE-2026-6478MEDIUM6.50.08%11Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover us…May 14, 2026
CVE-2026-6477HIGH8.80.05%11Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lsee…May 14, 2026
CVE-2026-6475HIGH8.80.05%11Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite loca…May 14, 2026
CVE-2026-6474MEDIUM4.30.03%11Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server…May 14, 2026
CVE-2026-6473HIGH8.80.07%11Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to un…May 14, 2026
CVE-2026-6472MEDIUM5.40.03%11Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to…May 14, 2026

PostgreSQL 11.x is EOL — migrate to PostgreSQL 12.x

PostgreSQL 12.x is the next major release. Plan your upgrade before PostgreSQL 11.x stops receiving security patches.

See PostgreSQL 12.x

Frequently asked questions

Is PostgreSQL 11 end of life?

Yes. All PostgreSQL 11.x releases have reached end of life and no longer receive security patches. There are 8 known CVEs affecting PostgreSQL 11.x. Migrate to PostgreSQL 12.x as soon as possible.

What CVEs affect PostgreSQL 11?

There are 8 CVEs tracked for PostgreSQL 11.x. See the full list above with CVSS and EPSS scores.

What is the latest PostgreSQL 11 version?

The latest PostgreSQL 11.x patch release is 11.22, released on November 6, 2023. Always run the latest patch to benefit from all security fixes.

How to migrate from PostgreSQL 11 to PostgreSQL 12?

To migrate from PostgreSQL 11 to PostgreSQL 12: (1) review the official PostgreSQL 12 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run PostgreSQL 11 in production?

No. PostgreSQL 11 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA