11 Security Issues | Scaling Postgres 417

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 have been released, addressing an unusually high 11 security vulnerabilities — four to five times the typical count — with the highest CVSS base score at 8.8. Issues include integer wrap-around, SQL injections, buffer overflows, memory disclosure, and denial-of-service via uncontrolled recursion, many affecting all versions back to 14. PgBouncer 1.25.2 also patches 4 CVEs. AI-assisted bug discovery is speculated as the driver behind the spike. Additional topics covered include: querying JSONB data using GIN indexes, expression indexes, and generated columns with performance and storage trade-offs; pitfalls of nested PostgreSQL views and schema migration complexity; Postgres 19's dynamic WAL level based on replication slot presence; a survey of alternative PostgreSQL storage engines (OrioleDB, columnar TAMs, Lakehouse-backed TAMs); challenges blocking 64-bit transaction IDs in Postgres; and a guide to migrating from Crunchy PGO to CloudNativePG.

19m watch time
3 Impressions