As we wrap up 2025 and prepare for another exciting year of 2026, HexaCluster is back again with our annual Summary of PostgreSQL, continuing the tradition we set in 2024.
PostgreSQL has evolved far beyond its roots, cementing itself as the universal powerhouse that defines the modern data stack. This journey would not be possible without the tireless contributions of global community, sponsors, and individual contributors who invest in the excellence of open-source technology. Together, we have built more than just a database; we have cultivated an enduring legacy of transparency and technical brilliance.
Here is a recap of PostgreSQL’s key achievements, developments, and critical updates in 2025.

The database landscape is competitive, but PostgreSQL continues to stand tall. According to DB-Engines, which tracks database popularity by comparing scores at the start and end of the year, PostgreSQL remains a top contender.
While Snowflake saw the highest growth score in 2024, PostgreSQL ranked second, proving its continued relevance in a cloud-native world. It is worth remembering PostgreSQL’s dominant run in previous years:
This consistent ranking reflects an amazing ecosystem where global contributors regularly introduce new features, optimizations, and bug fixes like clockwork.
Released in late 2025, PostgreSQL 18 has set a new benchmark for what an open-source database can achieve. This major release focused heavily on modernizing the core architecture and improving developer quality of life.
A quick Architecture Audit can save hours of troubleshooting later.
Try it Now!Let HexaRocket simplify it - migrate smarter, faster, and stress-free.
Contact us Today!HexaRocket performs end-to-end database migrations and replication seamlessly between Oracle, SQL Server, MySQL, MariaDB, and PostgreSQL.
Try Today!1. The Era of Asynchronous I/O for Performance
The standout feature of PostgreSQL 18 is the introduction of a native asynchronous I/O (AIO) subsystem.
2. Schema & Developer Enhancements
PostgreSQL 18 brings features that simplify schema design and reduce storage overhead.
3. Security Hardening
Security was a major theme in 2025, with several enterprise-grade additions.
4. Observability & Utility
While specialized vector databases had their moment, 2025 was the year PostgreSQL solidified its position as the default choice for vector workloads via pgvector.The focus shifted from "can Postgres do vectors?" to "how fast can it scale?"
pgvector 0.8.x: The Maturity Release
The release of pgvector 0.8.1 in September 2025 brought critical production-grade improvements that addressed the biggest complaints of previous years.
The PostgreSQL community maintained its rigorous release schedule this year. Below is the summary of minor versions released across supported branches in 2025.
| Version | 2025 Releases | Status |
|---|---|---|
| PostgreSQL 18 | 18.0, 18.1 | Current |
| PostgreSQL 17 | 17.3, 17.4, 17.5, 17.6, 17.7 | Supported |
| PostgreSQL 16 | 16.7, 16.8, 16.9, 16.10, 16.11 | Supported |
| PostgreSQL 15 | 15.11, 15.12, 15.13, 15.14, 15.15 | Supported |
| PostgreSQL 14 | 14.16, 14.17, 14.18, 14.19, 14.20 | Supported |
| PostgreSQL 13 | 13.23 | End of Life |
Our Recommendation
If you are running PostgreSQL 12 or 13, it is important to upgrade to a supported version immediately to ensure the security and stability of your data. Hexacluster provides advanced support and expert guidance for PostgreSQL Consulting in addition to application and database migrations. If you need help planning or executing your transition, explore our PostgreSQL DBA Services for professional assistance.
Security is a continuous battle, and 2025 was no exception. The PostgreSQL community was vigilant, identifying and patching several critical vulnerabilities throughout the year.
1. The libpq Client Risks (Integer Wraparound)
CVE-2025-12818
The Issue: A vulnerability was discovered in libpq, the underlying C library used by many PostgreSQL clients. The issue involved an "integer wraparound," where very large values could trick the library into allocating too little memory for a task.
The Impact: This mismatch between the memory needed and the memory allocated could lead to data being written outside the allowed bounds. In the best-case scenario, this causes the application to crash (Denial of Service). In the worst case, it could be exploited to compromise the client application.
Fixed In: 18.1, 17.7, 16.11, 15.15, 14.20
2. The pg_dump Injection Flaws
Two separate vulnerabilities were found in pg_dump, the standard tool for backing up databases. Both highlighted the danger of trusting data coming from a compromised or malicious server.
CVE-2025-8714
The Issue: This flaw allowed a superuser on the source database server to construct malicious data that, when dumped, could execute arbitrary code on the client's machine running pg_dump.
The Impact: This is a "rogue server" attack. If you backed up a compromised database, the attacker could theoretically take control of your backup machine.
CVE-2025-8715 (Newline Injection)
The Issue: Specifically involving object names, this vulnerability allowed attackers to embed newline characters in such a way that they were interpreted as commands during the restore process.
The Impact: Similar to SQL injection, this could trick the psql client or the target server into executing unauthorized commands during a restore.
Fixed In: 17.6, 16.10, 15.14, 14.19
3. Privilege & Data Leakage (Core Server)
CVE-2025-12817 (CREATE STATISTICS Bypass)
The Issue: The CREATE STATISTICS command failed to properly check if the user actually had permission to create objects in the target schema.
The Impact: This allowed users to bypass authorization checks, potentially cluttering schemas they shouldn't access or blocking legitimate owners from creating their own statistics.
Fixed In: 18.1, 17.7, 16.11, 15.15, 14.20
CVE-2025-8713 (Data Leak via Optimizer)
The Issue: The query optimizer uses statistical data to plan the fastest way to run a query. However, a flaw was found where these statistics could inadvertently reveal actual data snippets from views, partitions, or child tables to users who didn't have permission to see that data.
The Impact: This is a data privacy leak, allowing restricted data to be inferred through system statistics.
Fixed In: 17.6, 16.10, 15.14, 14.19
Recommendation
If your production systems are running on any version lower than the "Fixed In" versions listed above, you are vulnerable. We strongly recommend scheduling a minor version upgrade during your next maintenance window.
To stay ahead of these threats, you can use our security assessment tool, pgdsat, to identify critical vulnerabilities and verify CIS compliance benchmarks. For organizations requiring a deeper dive, Hexacluster can also perform a full security audit on your database infrastructure to ensure you are fully protected.
In 2025, the boundary between the application layer and the database blurred. We saw a surge of new extensions designed to integrate LLM capabilities directly into PostgreSQL, making the database not just a storage engine, but an intelligent processing unit.
Talking to Your Data using pg_ai_query
One of the standout experimental projects of 2025 was pg_ai_query. This extension exemplifies the shift toward "Conversational Databases."
SELECT ai_query('Show me the top 5 sales regions from last month');, and the extension handles the translation and execution.Beyond querying, 2025 saw the standardization of "AI-as-a-Function." Developers are now using simple SQL wrappers to run sentiment analysis, text summarization, and translation directly within the database. This year proved that you don't always need a separate ML infrastructure; sometimes, all you need is a simple CREATE EXTENSION.
2025 has been another stellar year for PostgreSQL, defined by growth, innovation, and an unwavering commitment to excellence. With PostgreSQL 18 setting new benchmarks through Async I/O and rich developer features, the database remains the most trusted and versatile choice for businesses worldwide.
As the community gears up for 2026, we at Hexacluster look forward to more groundbreaking advancements in this ever-evolving database ecosystem.
If you need expert support migrating legacy or complex Oracle, SQL Server, MySQL, or MariaDB databases to PostgreSQL or distributed databases, we’re here to help. HexaCluster provides end-to-end migration and modernization services, including application migration and modernization, database migration, and PostgreSQL consulting such as performance tuning, health audits, managed DBA services, and 24/7/265 support. To start a conversation or explore how we can support your migration journey, please contact us at connect@hexacluster.ai
Subscribe to our Newsletters and Stay tuned for more interesting topics.

Pavan is a PostgreSQL Database Engineer and Developer at HexaCluster. With expertise in database migrations, performance tuning, and highly scalable PostgreSQL deployments, Pavan is considered one of the most loved PostgreSQL DBA and Developer by the Customers of HexaCluster. His expertise is not limited to PostgreSQL administration, development and migrations. Pavan is a seasoned developer who can build scalable applications using Golang, Java and Python languages.

Goutham is a Senior Database Developer and Administrator, who graduated from one of the reputed universities like IIIT. He is passionate about Open Source and building solutions for Highly Available and Scalable PostgreSQL clusters. Goutham has supported several Customers in deploying PostgreSQL efficiently and migrating from Oracle, SQL Server and MongoDB to PostgreSQL.
Start your migration journey 🚀
start your migration journey with our expert team
Database & Application Migration Assessment Tool
End-to-End Database Migration & Modernization Tool
Database Code Object Conversion to PostgreSQL
MyBatis Mapper Conversion to PostgreSQL
Enterprise Data Replication & Live CDC
Oracle Compatibility Layer for PostgreSQL