PostgreSQL 18.x — End of Life
Active High risk EOL: Nov 14, 2030in 1528d1 release in this series44 CVEs
PostgreSQL 18.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 18 | Sep 25, 2025 | — | Nov 14, 2030 | 18.6 | Active |
CVEs affecting PostgreSQL 18.x (44)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-6471 | HIGH | 7.2 | 0.28% | — | 18 | Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any … | Aug 13, 2026 |
| CVE-2026-6470 | MEDIUM | 4.3 | 0.19% | — | 18 | Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and… | Aug 13, 2026 |
| CVE-2026-6469 | LOW | 3.8 | 0.18% | — | 18 | Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics … | Aug 13, 2026 |
| CVE-2026-6464 | HIGH | 8.1 | 0.35% | — | 18 | Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as p… | Aug 13, 2026 |
| CVE-2026-19385 | HIGH | 8.8 | 0.42% | — | 18 | Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrar… | Aug 13, 2026 |
| CVE-2026-18408 | HIGH | 8.8 | 0.36% | — | 18 | Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary … | Aug 13, 2026 |
| CVE-2026-18024 | MEDIUM | 4.3 | 0.19% | — | 18 | Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific … | Aug 13, 2026 |
| CVE-2026-16241 | LOW | 3.8 | 0.19% | — | 18 | Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service again… | Aug 13, 2026 |
| CVE-2026-16239 | HIGH | 8.8 | 0.52% | — | 18 | Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system u… | Aug 13, 2026 |
| CVE-2026-16238 | HIGH | 8.8 | 0.41% | — | 18 | Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the oper… | Aug 13, 2026 |
| CVE-2026-15742 | HIGH | 8.8 | 0.43% | — | 18 | Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing ar… | Aug 13, 2026 |
| CVE-2026-15741 | HIGH | 8.8 | 0.34% | — | 18 | SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hosti… | Aug 13, 2026 |
| CVE-2026-14681 | MEDIUM | 4.2 | 0.06% | — | 18 | Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_… | Aug 13, 2026 |
| CVE-2026-14680 | HIGH | 8.8 | 0.42% | — | 18 | Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating… | Aug 13, 2026 |
| CVE-2026-14679 | HIGH | 8.2 | 0.29% | — | 18 | Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT p… | Aug 13, 2026 |
| CVE-2026-14678 | MEDIUM | 4.3 | 0.19% | — | 18 | Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a tab… | Aug 13, 2026 |
| CVE-2026-14677 | HIGH | 8.8 | 0.42% | — | 18 | Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to under… | Aug 13, 2026 |
| CVE-2026-14676 | HIGH | 8.8 | 0.42% | — | 18 | Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating… | Aug 13, 2026 |
| CVE-2026-14673 | LOW | 3.8 | 0.17% | — | 18 | Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary … | Aug 13, 2026 |
| CVE-2026-14672 | MEDIUM | 5.3 | 0.25% | — | 18 | Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence … | Aug 13, 2026 |
| CVE-2026-14671 | HIGH | 8.8 | 0.42% | — | 18 | Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system … | Aug 13, 2026 |
| CVE-2026-14670 | HIGH | 8.8 | 0.43% | — | 18 | Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as t… | Aug 13, 2026 |
| CVE-2026-14669 | HIGH | 8.8 | 0.58% | — | 18 | Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code… | Aug 13, 2026 |
| CVE-2026-14668 | HIGH | 8.1 | 0.33% | — | 18 | Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a cal… | Aug 13, 2026 |
| CVE-2026-14666 | MEDIUM | 4.2 | 0.17% | — | 18 | Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query … | Aug 13, 2026 |
| CVE-2026-14664 | HIGH | 8.8 | 0.43% | — | 18 | Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user… | Aug 13, 2026 |
| CVE-2026-14663 | MEDIUM | 6.5 | 0.09% | — | 18 | Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of … | Aug 13, 2026 |
| CVE-2026-14662 | HIGH | 8.8 | 0.46% | — | 18 | Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause … | Aug 13, 2026 |
| CVE-2026-6638 | LOW | 3.7 | 0.18% | — | 18 | SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table cre… | May 14, 2026 |
| CVE-2026-6637 | HIGH | 8.8 | 0.37% | — | 18 | Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as th… | May 14, 2026 |
| CVE-2026-6575 | MEDIUM | 4.3 | 0.20% | — | 18 | Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which cau… | May 14, 2026 |
| CVE-2026-6479 | HIGH | 7.5 | 0.47% | — | 18 | Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX … | May 14, 2026 |
| CVE-2026-6478 | MEDIUM | 6.5 | 0.55% | — | 18 | Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover us… | May 14, 2026 |
| CVE-2026-6477 | HIGH | 8.8 | 0.45% | — | 18 | Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lsee… | May 14, 2026 |
| CVE-2026-6476 | HIGH | 7.2 | 0.28% | — | 18 | SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitra… | May 14, 2026 |
| CVE-2026-6475 | HIGH | 8.8 | 0.32% | — | 18 | Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite loca… | May 14, 2026 |
| CVE-2026-6474 | MEDIUM | 4.3 | 0.21% | — | 18 | Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server… | May 14, 2026 |
| CVE-2026-6473 | HIGH | 8.8 | 1.00% | — | 18 | Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to un… | May 14, 2026 |
| CVE-2026-6472 | MEDIUM | 5.4 | 0.15% | — | 18 | Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to… | May 14, 2026 |
| CVE-2026-2007 | HIGH | 8.2 | 0.48% | — | 18 | Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.… | Feb 12, 2026 |
| CVE-2026-2006 | HIGH | 8.8 | 1.07% | — | 18 | Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted… | Feb 12, 2026 |
| CVE-2026-2005 | HIGH | 8.8 | 1.27% | — | 18 | Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating syst… | Feb 12, 2026 |
| CVE-2026-2004 | HIGH | 8.8 | 1.18% | — | 18 | Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object cre… | Feb 12, 2026 |
| CVE-2026-2003 | MEDIUM | 4.3 | 0.28% | — | 18 | Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. … | Feb 12, 2026 |
Frequently asked questions
Is PostgreSQL 18 end of life?
No. PostgreSQL 18.x is still supported until November 14, 2030. It continues to receive security patches and bug fixes.
What CVEs affect PostgreSQL 18?
There are 44 CVEs tracked for PostgreSQL 18.x. See the full list above with CVSS and EPSS scores.
What is the latest PostgreSQL 18 version?
The latest PostgreSQL 18.x patch release is 18.6, released on August 11, 2026. Always run the latest patch to benefit from all security fixes.
When was PostgreSQL 18 first released?
PostgreSQL 18.0 was initially released on September 25, 2025. See the full version timeline in the table above.
Is it safe to run PostgreSQL 18 in production?
PostgreSQL 18 is still supported and safe for production use until November 14, 2030. Ensure you are running the latest patch version (18.6) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
