{"id":"RHSA-2026:67280","summary":"Red Hat Security Advisory: postgresql18 security update","modified":"2026-09-16T10:31:49.616760045Z","published":"2026-09-15T10:17:05Z","upstream":["CVE-2026-14662","CVE-2026-14664","CVE-2026-14668","CVE-2026-14669","CVE-2026-14670","CVE-2026-14671","CVE-2026-14676","CVE-2026-14677","CVE-2026-14679","CVE-2026-14680","CVE-2026-15741","CVE-2026-15742","CVE-2026-16238","CVE-2026-16239","CVE-2026-18408","CVE-2026-19385","CVE-2026-6464","CVE-2026-6471","CVE-2026-6476"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:67280"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/#important"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2477437"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515302"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515303"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515306"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515307"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515308"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515311"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515313"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515314"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515316"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515317"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515319"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515321"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515322"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515324"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515325"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515326"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515328"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515332"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67280.json"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-6464"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-6464"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6464"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-6464/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-6471"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-6471"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6471"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-6471/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-6476"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-6476"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6476"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-6476/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14662"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-14662"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14662"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-14662/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14664"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-14664"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14664"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-14664/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14668"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-14668"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14668"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-14668/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14669"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-14669"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14669"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-14669/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14670"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-14670"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14670"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-14670/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14671"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-14671"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14671"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-14671/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14676"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-14676"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14676"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-14676/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14677"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-14677"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14677"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-14677/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14679"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-14679"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14679"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-14679/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-14680"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-14680"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14680"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-14680/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-15741"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-15741"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15741"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-15741/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-15742"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-15742"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15742"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-15742/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16238"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-16238"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16238"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-16238/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-16239"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-16239"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16239"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-16239/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-18408"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-18408"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18408"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-18408/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-19385"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-19385"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19385"},{"type":"ARTICLE","url":"https://www.postgresql.org/support/security/CVE-2026-19385/"}],"affected":[{"package":{"name":"postgresql18","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-contrib","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-contrib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-contrib-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-contrib-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-debugsource","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-debugsource"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-docs","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-docs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-docs-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-docs-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-plperl","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-plperl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-plperl-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-plperl-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-plpython3","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-plpython3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-plpython3-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-plpython3-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-pltcl-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-pltcl-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-private-devel","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-private-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-private-libs","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-private-libs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-private-libs-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-private-libs-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-server","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-server-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-server-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-server-devel","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-server-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-server-devel-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-server-devel-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-static","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-static"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-test","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-test"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-test-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-test-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-upgrade","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-upgrade"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-upgrade-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-upgrade-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-upgrade-devel","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-upgrade-devel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-upgrade-devel-debuginfo","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-upgrade-devel-debuginfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}},{"package":{"name":"postgresql18-test-rpm-macros","ecosystem":"Red Hat:enterprise_linux:10.2","purl":"pkg:rpm/redhat/postgresql18-test-rpm-macros"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:18.6-1.el10_2"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:67280.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}