PostgreSQL 18

Soportada

PostgreSQL 18 es una versión estable, publicada el 25 de septiembre de 2025. Recibe parches de seguridad hasta el 14 de noviembre de 2030. La última versión puntual publicada es la 18.6, del 11 de agosto de 2026.

Avisos de seguridad

Seguimos 29 avisos que afectan a PostgreSQL. Son los avisos del producto: no están filtrados por versión.

CVE-2025-8714 Sin clasificar 2026-08-20

PostgreSQL

postgresql-14, postgresql-16, postgresql-18 vulnerabilities

Corregida en Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14662 Alta 8.8 2026-08-13

PostgreSQL

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14663 Media 6.5 2026-08-13

PostgreSQL

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14664 Alta 8.8 2026-08-13

PostgreSQL

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14666 Media 4.2 2026-08-13

PostgreSQL

Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query to continue using cached row-level security policies after those changes…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

CVE-2026-14668 Alta 8.1 2026-08-13

PostgreSQL

Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a…

Corregida en Debian 12, Debian 13, Debian 14, Ubuntu 22.04, Ubuntu 24.04 y Ubuntu 26.04.

Ver los 29 avisos de PostgreSQL

Fechas de endoflife.date, publicadas bajo licencia CC BY 4.0. Esta ficha se genera automáticamente y no sustituye al calendario oficial del proyecto; así se elabora la lista.

Si lo instalaste desde tu distribución, esta fecha no es la tuya

Estas son las fechas del proyecto original. Debian, Ubuntu y RHEL congelan una versión al publicar cada release y le retroportan los parches de seguridad durante todo el ciclo de la distribución, así que un paquete que aquí figura fuera de soporte puede seguir recibiendo correcciones por la vía de tu distribución. Lo que manda entonces es el calendario de la distribución.