PostgreSQL 13.x — End of Life

EOL High risk
EOL: Nov 13, 20251 release in this series9 CVEs

PostgreSQL 13.x reached end of life on Nov 13, 2025, 328 days ago, and no longer receives security fixes. The most recent release in this series is 13.23. 9 CVEs are tracked for this series. 8 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is PostgreSQL 14. See PostgreSQL 14 →

PostgreSQL 13.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
13Sep 24, 2020—Nov 13, 202513.23EOL

CVEs affecting PostgreSQL 13.x (9)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-6637HIGH8.80.37%—13Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as th…May 14, 2026
CVE-2026-6479HIGH7.50.59%—13Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX …May 14, 2026
CVE-2026-6478MEDIUM6.50.55%—13Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover us…May 14, 2026
CVE-2026-6477HIGH8.80.45%—13Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lsee…May 14, 2026
CVE-2026-6475HIGH8.80.32%—13Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite loca…May 14, 2026
CVE-2026-6474MEDIUM4.30.31%—13Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server…May 14, 2026
CVE-2026-6473HIGH8.81.00%—13Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to un…May 14, 2026
CVE-2026-6472MEDIUM5.40.23%—13Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to…May 14, 2026
CVE-2023-39417HIGH7.51.67%—13IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @e…Aug 11, 2023

PostgreSQL 13.x is EOL — migrate to PostgreSQL 14.x

PostgreSQL 14.x is the next major release. Plan your upgrade before PostgreSQL 13.x stops receiving security patches.

See PostgreSQL 14.x

Add a PostgreSQL 13 EOL badge to your README

Show your users which PostgreSQL version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

PostgreSQL 13 EOL status
[![PostgreSQL 13 EOL status](https://eolcanary.com/badge/postgresql/13.svg)](https://eolcanary.com/explore/postgresql/13)

Frequently asked questions

Is PostgreSQL 13 end of life?

Yes. All PostgreSQL 13.x releases have reached end of life and no longer receive security patches. There are 9 known CVEs affecting PostgreSQL 13.x. Migrate to PostgreSQL 14.x as soon as possible.

What CVEs affect PostgreSQL 13?

There are 9 CVEs tracked for PostgreSQL 13.x. See the full list above with CVSS and EPSS scores.

What is the latest PostgreSQL 13 version?

The latest PostgreSQL 13.x patch release is 13.23, released on November 10, 2025. Always run the latest patch to benefit from all security fixes.

How to migrate from PostgreSQL 13 to PostgreSQL 14?

To migrate from PostgreSQL 13 to PostgreSQL 14: (1) review the official PostgreSQL 14 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run PostgreSQL 13 in production?

No. PostgreSQL 13 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA