tlder@devPostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 Released
tlder@dev:~$
Data/Databases

PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 Released

  • Shipped
  • Action required
  • High importance

PostgreSQL has released versions 18.4, 17.10, 16.14, 15.18, and 14.23 in a coordinated multi-branch update addressing 11 CVEs — among them integer wraparound flaws rated CVSS 8.8, SQL injection vulnerabilities in replication tooling, and memory disclosure issues. Beyond security fixes, the releases resolve over 60 bugs covering query result accuracy with collations, foreign key deferrability, and parallel query execution. Timezone data has been refreshed to the 2026b standard, which accounts for permanent DST changes in British Columbia starting November 2026. Teams running any supported PostgreSQL major version are affected and should update promptly given the high-severity CVE ratings. Administrators managing PostgreSQL 14 deployments should also note that this is likely among the final maintenance releases for that branch, with end-of-support scheduled for November 12, 2026. Planning an upgrade path to a newer supported major version is now time-sensitive.