Clarification on CVE 2026 impact for PostgreSQL 17.x with Citus, TimescaleDB and PostGIS - Mailing list pgadmin-support

From Gianfranco Cocco
Subject Clarification on CVE 2026 impact for PostgreSQL 17.x with Citus, TimescaleDB and PostGIS
Date
Msg-id DB3PR0202MB913102250F4B5B9826802718F468A@DB3PR0202MB9131.eurprd02.prod.outlook.com
Whole thread Raw
List pgadmin-support

Dear PostgreSQL Team,

We are currently running a production environment based on PostgreSQL 17.x with the following extensions:

Citus 13.2
TimescaleDB
PostGIS

Following the recent disclosure of CVEs for 2026 affecting PostgreSQL, we would appreciate clarification on the following points:

If the vulnerability affects the PostgreSQL core binaries only, is upgrading to the latest 17.x minor release sufficient to mitigate the issue?

Are there any known implications for extensions such as Citus, TimescaleDB, or PostGIS when upgrading PostgreSQL minor versions to address security fixes?

In your experience, are there scenarios where rebuilding or explicitly upgrading extensions (via ALTER EXTENSION UPDATE) is required after applying a security-related minor upgrade?

Are there known compatibility considerations for distributed environments (Citus) or time-series workloads (TimescaleDB) in the context of these CVEs?

We aim to minimize downtime while ensuring full mitigation of the reported vulnerabilities, and we would appreciate any guidance or best practices you can share.

Thank you for your time and for your continuous work on PostgreSQL security.

Best regards,


Gian



Gianfranco Cocco
Infrastructure Database Administration



 

vargroup.com

  

Immagine 

Questo messaggio è stato spedito da Var Group S.p.A. o da una delle aziende del Gruppo. Esso, e gli eventuali allegati, potrebbero contenere informazioni di carattere estremamente riservato e confidenziale. Qualora non foste i destinatari designati, vogliate cortesemente informarci immediatamente con lo stesso mezzo ed eliminare il messaggio e i relativi eventuali allegati, senza trattenerne copia.


Attachment

pgadmin-support by date:

Previous
From: Rogelio Villafana Sanchez
Date:
Subject: RE: pgAdmin 4 || vulnerable pip modules
Next
From: Aditya Toshniwal
Date:
Subject: Re: pgAdmin 4 || vulnerable pip modules