HexaCluster LogoHexaCluster Logo
  • Services
  • Products
  • HexaRocket
  • Blog
  • Resources
  • Company
  • Contact Us
Schedule a Demo
Stay Updated

Subscribe to Newsletters

Be the first to know! Stay updated with the latest insights, database migration benchmarks, and technical updates from HexaCluster.

HexaCluster LogoHexaCluster Logo

Enterprise-grade Database migration, modernization, and tooling for teams moving off legacy databases.

  • One Dundas Street West, Suite 2500, Toronto, Ontario, M5G 1Z3, Canada
  • HexaCluster DMCC, Plot No: JLT-PH2-RET-R6 Jumeirah Lakes Towers, Dubai, UAE
connect@hexacluster.ai+1 (902) 221-5976

Security & Compliance

SOC 2 Type 1 reportSOC 2 Type 2 report, monitored by Comp AIGDPR compliantISO 27001AICPA SOC for Service Organizations

Products

  • DMAT
  • HexaRocket
  • HexaBridge
  • HexaTranspile
  • MyBatis2Pg
  • HexaReplicate
  • Download Products

HexaRocket

  • Supported Database Migrations
  • Migrate to Yugabyte
  • About HexaRocket
  • Migrate to Oracle
  • Migrate to PostgreSQL
  • Migrate to MariaDB

Services

  • Database Migration to PostgreSQL
  • Application Migration and Modernization
  • AI/ML and MLOps
  • Architectural Health Audit
  • Managed DBA Services
  • Performance Tuning
  • PostgreSQL Development
  • Training for DBAs & Developers
  • 24/7 Support
  • Supported Tools and Extensions

Company

  • Blog
  • Case Studies
  • Webinars
  • Announcements
  • About Us
  • Referral Program
  • Events
  • Contact Us

© HexaCluster 2026. All rights reserved. Privacy PolicyThis site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

HEXACLUSTERHEXACLUSTERHEXACLUSTER

Summary of PostgreSQL in the year 2025

Pavan Chary,Goutham Banala
Jan 07, 2026
postgresql#Summary of PostgreSQL#Postgres#PostgreSQL+1 more

As we wrap up 2025 and prepare for another exciting year of 2026, HexaCluster is back again with our annual Summary of PostgreSQL, continuing the tradition we set in 2024.

PostgreSQL has evolved far beyond its roots, cementing itself as the universal powerhouse that defines the modern data stack. This journey would not be possible without the tireless contributions of global community, sponsors, and individual contributors who invest in the excellence of open-source technology. Together, we have built more than just a database; we have cultivated an enduring legacy of transparency and technical brilliance.

Here is a recap of PostgreSQL’s key achievements, developments, and critical updates in 2025.


image


PostgreSQL’s Unstoppable Popularity

The database landscape is competitive, but PostgreSQL continues to stand tall. According to DB-Engines, which tracks database popularity by comparing scores at the start and end of the year, PostgreSQL remains a top contender.

While Snowflake saw the highest growth score in 2024, PostgreSQL ranked second, proving its continued relevance in a cloud-native world. It is worth remembering PostgreSQL’s dominant run in previous years:

  • DBMS of the Year: 2023, 2020, 2018, 2017

This consistent ranking reflects an amazing ecosystem where global contributors regularly introduce new features, optimizations, and bug fixes like clockwork.

Released in late 2025, PostgreSQL 18 has set a new benchmark for what an open-source database can achieve. This major release focused heavily on modernizing the core architecture and improving developer quality of life.

🧠 Fine-tune Your PostgreSQL

A quick Architecture Audit can save hours of troubleshooting later.

Try it Now!

🚀 Planning a Database Migration?

Let HexaRocket simplify it - migrate smarter, faster, and stress-free.

Contact us Today!

🚀 Try HexaRocket

HexaRocket performs end-to-end database migrations and replication seamlessly between Oracle, SQL Server, MySQL, MariaDB, and PostgreSQL.

Try Today!

Major versions Released in 2025 - PostgreSQL 18


1. The Era of Asynchronous I/O for Performance

The standout feature of PostgreSQL 18 is the introduction of a native asynchronous I/O (AIO) subsystem.

  • What it does: It allows the database to overlap disk operations with query processing rather than waiting for one to finish before starting the other.
  • The Impact: This significantly improves throughput for I/O-heavy workloads, such as sequential scans, VACUUM, and bitmap heap scans, especially when utilizing io_uring on Linux.

2. Schema & Developer Enhancements

PostgreSQL 18 brings features that simplify schema design and reduce storage overhead.

  • Native UUIDv7: Support for time-ordered UUIDs (version 7) is now built-in, offering better indexing performance than random UUIDs.
  • Virtual Generated Columns: By default, generated columns are now "virtual" (computed on read), saving disk space by not storing redundant data.
  • Flexible Constraints: You can now add NOT NULL constraints as NOT VALID for large tables, allowing you to enforce the rule for new data immediately without locking the table to validate old rows.
  • Retaining Data Visibility: The RETURNING clause now supports OLD and NEW references, making data modification queries much more powerful.

3. Security Hardening

Security was a major theme in 2025, with several enterprise-grade additions.

  • OAuth 2.0 Support: PostgreSQL 18 now natively supports OAuth 2.0 authentication.
  • Checksums by Default: initdb now enables data checksums by default, a massive win for detecting data corruption (though it can still be disabled if desired).
  • Modern Encryption: pgcrypto now adds SHA-2 encryption for password hashing.
  • Wider SCRAM Support: postgres_fdw and dblink now fully support SCRAM authentication.
  • MD5 Deprecation: The system now generates warnings when creating MD5 passwords, signaling the final push toward safer authentication methods.

4. Observability & Utility

  • Better Explain Plans: EXPLAIN ANALYZE now includes BUFFERS output automatically, saving DBAs that extra keystroke.
  • Vacuum Visibility: pg_stat_all_tables now tracks the duration of VACUUM, ANALYZE, AUTO_VACUUM, and AUTO_ANALYZE.
  • Robust Data Loading: The COPY command now supports a REJECT_LIMIT. In PostgreSQL 17, on_error='ignore' would skip errors, but now you can set a threshold (e.g., "stop after 100 bad rows"), giving you finer control over bulk loads.

Vector Database Advancements in 2025

While specialized vector databases had their moment, 2025 was the year PostgreSQL solidified its position as the default choice for vector workloads via pgvector.The focus shifted from "can Postgres do vectors?" to "how fast can it scale?"

pgvector 0.8.x: The Maturity Release

The release of pgvector 0.8.1 in September 2025 brought critical production-grade improvements that addressed the biggest complaints of previous years.

  • Iterative Index Scans: In the past, strict filtering (e.g., "find vectors for User A") could yield zero results if the index scan limit was hit before finding a match. The new iterative scan capability automatically continues searching until it finds enough matches to satisfy the LIMIT clause, solving the "missing recall" issue in RAG applications.
  • Binary & Scalar Quantization: 2025 saw massive adoption of quantization (compressing vectors). With improved support for halfvec (2-byte floats) and sparsevec, developers are now storing 2x to 4x more vectors in the same RAM footprint with negligible accuracy loss.
  • Parallel Index Builds: Building HNSW indexes on large datasets became significantly faster, utilizing all available CPU cores more effectively.

2025 Release Lifecycle

The PostgreSQL community maintained its rigorous release schedule this year. Below is the summary of minor versions released across supported branches in 2025.

Version2025 ReleasesStatus
PostgreSQL 1818.0, 18.1Current
PostgreSQL 1717.3, 17.4, 17.5, 17.6, 17.7Supported
PostgreSQL 1616.7, 16.8, 16.9, 16.10, 16.11Supported
PostgreSQL 1515.11, 15.12, 15.13, 15.14, 15.15Supported
PostgreSQL 1414.16, 14.17, 14.18, 14.19, 14.20Supported
PostgreSQL 1313.23End of Life

Saying Goodbye - End of Life (EOL)

  • PostgreSQL 13 reached its official End of Life on November 13, 2025. No further security fixes or updates will be released.
  • PostgreSQL 12 has been EOL since November 2024.
  • Let us know if you need help upgrading seamlessly.

Our Recommendation

If you are running PostgreSQL 12 or 13, it is important to upgrade to a supported version immediately to ensure the security and stability of your data. Hexacluster provides advanced support and expert guidance for PostgreSQL Consulting in addition to application and database migrations. If you need help planning or executing your transition, explore our PostgreSQL DBA Services for professional assistance.


Security Vulnerabilities Fixed in 2025

Security is a continuous battle, and 2025 was no exception. The PostgreSQL community was vigilant, identifying and patching several critical vulnerabilities throughout the year.


1. The libpq Client Risks (Integer Wraparound)

CVE-2025-12818

The Issue: A vulnerability was discovered in libpq, the underlying C library used by many PostgreSQL clients. The issue involved an "integer wraparound," where very large values could trick the library into allocating too little memory for a task.

The Impact: This mismatch between the memory needed and the memory allocated could lead to data being written outside the allowed bounds. In the best-case scenario, this causes the application to crash (Denial of Service). In the worst case, it could be exploited to compromise the client application.

Fixed In: 18.1, 17.7, 16.11, 15.15, 14.20


2. The pg_dump Injection Flaws

Two separate vulnerabilities were found in pg_dump, the standard tool for backing up databases. Both highlighted the danger of trusting data coming from a compromised or malicious server.

CVE-2025-8714

The Issue: This flaw allowed a superuser on the source database server to construct malicious data that, when dumped, could execute arbitrary code on the client's machine running pg_dump.

The Impact: This is a "rogue server" attack. If you backed up a compromised database, the attacker could theoretically take control of your backup machine.

CVE-2025-8715 (Newline Injection)

The Issue: Specifically involving object names, this vulnerability allowed attackers to embed newline characters in such a way that they were interpreted as commands during the restore process.

The Impact: Similar to SQL injection, this could trick the psql client or the target server into executing unauthorized commands during a restore.

Fixed In: 17.6, 16.10, 15.14, 14.19


3. Privilege & Data Leakage (Core Server)

CVE-2025-12817 (CREATE STATISTICS Bypass)

The Issue: The CREATE STATISTICS command failed to properly check if the user actually had permission to create objects in the target schema.

The Impact: This allowed users to bypass authorization checks, potentially cluttering schemas they shouldn't access or blocking legitimate owners from creating their own statistics.

Fixed In: 18.1, 17.7, 16.11, 15.15, 14.20

CVE-2025-8713 (Data Leak via Optimizer)

The Issue: The query optimizer uses statistical data to plan the fastest way to run a query. However, a flaw was found where these statistics could inadvertently reveal actual data snippets from views, partitions, or child tables to users who didn't have permission to see that data.

The Impact: This is a data privacy leak, allowing restricted data to be inferred through system statistics.

Fixed In: 17.6, 16.10, 15.14, 14.19


Recommendation

If your production systems are running on any version lower than the "Fixed In" versions listed above, you are vulnerable. We strongly recommend scheduling a minor version upgrade during your next maintenance window.

To stay ahead of these threats, you can use our security assessment tool, pgdsat, to identify critical vulnerabilities and verify CIS compliance benchmarks. For organizations requiring a deeper dive, Hexacluster can also perform a full security audit on your database infrastructure to ensure you are fully protected.


AI-Powered Extensions and the Rise of In-Database Intelligence

In 2025, the boundary between the application layer and the database blurred. We saw a surge of new extensions designed to integrate LLM capabilities directly into PostgreSQL, making the database not just a storage engine, but an intelligent processing unit.

Talking to Your Data using pg_ai_query

One of the standout experimental projects of 2025 was pg_ai_query. This extension exemplifies the shift toward "Conversational Databases."

  • The Concept: Instead of writing complex JOINs and aggregations, pg_ai_query allows users to query the database using plain English.
  • How it works: By leveraging LLMs (either via external APIs or local models), the extension translates natural language prompts into valid SQL execution plans on the fly.
  • The Impact: This lowers the barrier to entry for data analysis. A non-technical user can simply run a command like SELECT ai_query('Show me the top 5 sales regions from last month');, and the extension handles the translation and execution.

Beyond querying, 2025 saw the standardization of "AI-as-a-Function." Developers are now using simple SQL wrappers to run sentiment analysis, text summarization, and translation directly within the database. This year proved that you don't always need a separate ML infrastructure; sometimes, all you need is a simple CREATE EXTENSION.


Conclusion

2025 has been another stellar year for PostgreSQL, defined by growth, innovation, and an unwavering commitment to excellence. With PostgreSQL 18 setting new benchmarks through Async I/O and rich developer features, the database remains the most trusted and versatile choice for businesses worldwide.

As the community gears up for 2026, we at Hexacluster look forward to more groundbreaking advancements in this ever-evolving database ecosystem.

If you need expert support migrating legacy or complex Oracle, SQL Server, MySQL, or MariaDB databases to PostgreSQL or distributed databases, we’re here to help. HexaCluster provides end-to-end migration and modernization services, including application migration and modernization, database migration, and PostgreSQL consulting such as performance tuning, health audits, managed DBA services, and 24/7/265 support. To start a conversation or explore how we can support your migration journey, please contact us at connect@hexacluster.ai


Subscribe to our Newsletters and Stay tuned for more interesting topics.


Authors

Pavan Chary

Pavan Chary

PostgreSQL Database Engineer and Developer

Pavan is a PostgreSQL Database Engineer and Developer at HexaCluster. With expertise in database migrations, performance tuning, and highly scalable PostgreSQL deployments, Pavan is considered one of the most loved PostgreSQL DBA and Developer by the Customers of HexaCluster. His expertise is not limited to PostgreSQL administration, development and migrations. Pavan is a seasoned developer who can build scalable applications using Golang, Java and Python languages.

Goutham Banala

Goutham Banala

Senior Database Developer and Administrator

Goutham is a Senior Database Developer and Administrator, who graduated from one of the reputed universities like IIIT. He is passionate about Open Source and building solutions for Highly Available and Scalable PostgreSQL clusters. Goutham has supported several Customers in deploying PostgreSQL efficiently and migrating from Oracle, SQL Server and MongoDB to PostgreSQL.

Start your migration journey 🚀

start your migration journey with our expert team

Products

DMAT

Database & Application Migration Assessment Tool

HexaRocket

End-to-End Database Migration & Modernization Tool

HexaTranspile

Database Code Object Conversion to PostgreSQL

MyBatis2Pg

MyBatis Mapper Conversion to PostgreSQL

HexaReplicate

Enterprise Data Replication & Live CDC

HexaBridge

Oracle Compatibility Layer for PostgreSQL

HexaRocket 🚀

Oracle to PostgreSQLSQL Server to PostgreSQLMySQL to PostgreSQLMariaDB to PostgreSQLAny to Any databases

Migration Services

Database MigrationsApplication Modernization

PostgreSQL Consulting

Architectural AuditsPerformance TuningTraining & Support