WarehousePG 6.x release notes v6.27.6

The WarehousePG documentation describes the latest version of WarehousePG 6.

VersionRelease date
6.27.6-WHPG25 September 2026
6.27.5-WHPG10 June 2026
6.27.4-WHPG7 April 2026
6.27.3-WHPG28 January 2026
6.27.2-WHPG8 December 2025

WarehousePG 6.27.6-WHPG

Released: 25 September 2026

WarehousePG 6.27.6-WHPG is a security-focused release. It includes the following bug fixes and other changes:

Note

WarehousePG 6.27.6 changes several behaviors that can affect existing scripts and configurations, including dump output format, CREATE OPERATOR privileges, and pgcrypto and psql behavior. Review Upgrading to 6.27.6: Behavior changes to review before you upgrade.

Bug fixes

  • Fixed gpload to pass arguments through its shell wrapper without word splitting, so control-file paths with spaces work, and to fall back to $HOME/gpAdminLogs when the -l log file is unusable.
  • Fixed PL/Perl array and tied-container handling for non-rectangular arrays, forged ARRAY objects, tied SETOF array references, and NULL SV * values.
  • Fixed pgcrypto to reset the global debug handler after a PGP pipeline error, so later calls no longer emit stray dbg: notices.

Security

  • Fixed a pg_dump privilege-escalation race by adding the restrict_nonsystem_relation_kind configuration parameter (view, foreign-table), which pg_dump sets for the duration of a dump to stop the backend from expanding non-system views or accessing non-system foreign tables, for CVE-2024-7348.
  • Wrapped plain-text output from pg_dump, pg_dumpall, and pg_restore in psql \restrict and \unrestrict markers, so a hostile server can't inject meta-commands executed at restore time, and added the --restrict-key option, for CVE-2025-8714.
  • Fixed a one-byte overread in GB18030 multibyte character handling, replaced unbounded pg_mblen() call sites with length-checked variants across the server, fixed an out-of-bounds read in JSON parse error messages for incomplete byte sequences, and fixed translate() reading one byte past the end of its to argument, for CVE-2025-4207 and CVE-2026-2006.
  • Required superuser to attach a non-built-in RESTRICT or JOIN selectivity estimator in CREATE OPERATOR, and hardened tsmatchsel() against a non-tsvector operand, for CVE-2026-2004.
  • Fixed a buffer overflow in pgcrypto's pgp_pub_decrypt_bytea() function by bounding the session key length, for CVE-2026-2005.
  • Stopped psql from executing in-line COPY ... FROM STDIN data as SQL after the COPY command fails, including WarehousePG 6's legacy COPY ... WITH OIDS FROM STDIN syntax, for CVE-2026-6464.
  • Hardened tsvector and tsquery construction against integer overflows in tsvectorrecv(), make_tsvector(), parsetext(), tsvectorout(), and QTN2QT(), for CVE-2026-14662.
  • Fixed pgcrypto to fail cipher operations during PGP encryption instead of emitting effectively unencrypted data, and added the ignore-cipher-failure decryption option to read back data mis-encrypted by affected builds, for CVE-2026-14663.
  • Fixed a buffer overrun in regexp_matches(), regexp_split_to_table(), and regexp_split_to_array() on invalidly encoded input, for CVE-2026-14664.
  • Fixed ascii() to validate multibyte input length before reading continuation bytes, with related fixes to EUC_CN length handling, mb2wchar() on short input, PGP-decrypted text encoding validation, and SUBSTRING() on toasted multibyte values, bounded the copy of overlength time zone abbreviations in to_char(), and fixed PL/Perl to read a tied array's length only once in plperl_array_to_datum(), for CVE-2026-18024, CVE-2026-14669, and CVE-2026-14670.
  • Removed a stale per-backend plan cache in contrib/spi/refint's check_foreign_key() function that caused type confusion, and fixed a NULL-key segfault, for CVE-2026-14671.
  • Used overflow-safe array allocation in pltcl and plperl, and guarded fixed-size argument arrays in the parser, fmgr, PL/pgSQL, plperl, plpython, and pltcl against extreme argument counts, for CVE-2026-14677 and CVE-2026-14679.
  • Fixed pg_trgm's gtrgm_picksplit() function reading past the end of the signature buffer for all-true datums, for CVE-2026-14678.
  • Rejected SQL-level calls to functions that take or return the internal type, including operator and cast syntax, fixed numeric_avg_combine() and numeric_combine() to handle a NaN count correctly, and made aggregate combine functions return NULL honestly, for CVE-2026-14680.
  • Fixed integer overflow and out-of-bounds writes in fuzzystrmatch's Levenshtein distance functions by computing distances in 64-bit arithmetic, for CVE-2026-15742.
  • Fixed a memory disclosure and possible remote code execution vulnerability from a mismatch between a portal's tuple descriptor and the query's actual output during EXECUTE or FETCH, for CVE-2026-16239.

WarehousePG 6.27.5-WHPG

Released: 10 June 2026

WarehousePG 6.27.5-WHPG includes the following bug fixes and other changes:

Bug fixes

  • Fixed GPHOME_CLIENTS resolution in greenplum_clients_path.sh to correctly locate client binaries.

Security

  • Hardened multiple modules against integer overflow vulnerabilities for CVE-2026-6473, including ltree, ts_headline, intarray, the regex engine, unicode_normalize, formatting.c, array_agg, and the hstore PL/Perl and PL/Python extensions.
  • Fixed a format-string vulnerability in timeofday() for CVE-2026-6474 where a crafted time zone setting could abuse the pg_strftime() %Z format specifier to cause crashes or corrupt server memory.
  • Fixed a path traversal vulnerability in pg_rewind for CVE-2026-6475 where paths received from a rogue endpoint could overwrite files outside the target directory.
  • Fixed a buffer overrun in the frontend large object interface (libpq) for CVE-2026-6477 where PQfn() could write beyond the end of the result buffer when the server returned more data than requested.
  • Added timing-safe comparisons for secret material in all authentication paths for CVE-2026-6478, covering SCRAM, MD5, RADIUS, and plain authentication methods.
  • Fixed a stack overflow vulnerability in ProcessStartupPacket() for CVE-2026-6479 where a malicious client could alternate SSL and GSS negotiation requests indefinitely to exhaust server stack space.
  • Fixed an SQL injection and buffer overrun vulnerability in the refint contrib module for CVE-2026-6637.

WarehousePG 6.27.4-WHPG

Released: 7 April 2026

WarehousePG 6.27.4-WHPG includes the following new features, enhancements, bug fixes, and other changes:

Bug fixes

  • Resolved critical stability issues in the ORCA optimizer including fixes for segmentation faults and infinite recursion.
  • Fixed an issue where unnecessary motion was created on query executor slices.
  • Corrected behavior and stability when running the execute on initplan function.
  • Removed role assertions in get_ao_compression_ratio() and aorow_compression_ratio_internal to allow the function to execute on query executors, enabling the use of gp_dist_random() to retrieve compression statistics from all segments.

Security

  • Fixed a heap buffer overflow vulnerability in libpq for CVE-2025-12818 by hardening memory allocation against integer overflows. This change implements stricter size_t calculations for large, untrusted inputs to ensure allocated buffers are sufficient for their contents.

WarehousePG 6.27.3-WHPG

Released: 28 January 2026

WarehousePG 6.27.3-WHPG includes the following new features, enhancements, bug fixes, and other changes:

Bug fixes

  • Made the ReScanForeignScan callback optional for Foreign Data Wrappers (FDWs) to simplify the implementation and improve compatibility for external data sources.
  • Removed the GUC_NO_SHOW_ALL flag for the archive_timeout configuration parameter to ensure the setting is correctly displayed in all system configuration views.

WarehousePG 6.27.2-WHPG

Released: 8 December 2025

WarehousePG 6.27.2-WHPG includes the following new features, enhancements, bug fixes, and other changes:

Enhancements

  • Restored the functionality of greenplum-abi-tests to ensure ongoing development stability and interface compatibility.
  • Adjusted ftsprobe logging to use WARNING severity for failure and retry exhaustion events, ensuring these critical messages are always visible regardless of gp_log_fts settings.

Bug fixes

  • Resolved mirror promotion failures and fixed assertion failures caused by the incorrect application of the fmtId() function.
  • Improved error detection reliability in status_check cases and implemented checks for MergeAppend nodes in the share input mutator.
  • Optimized internal performance by transitioning to LWLocks for instrumentation headers and using pipes instead of sockets for immediate poll termination.
  • Fixed an issue where tables with corrupted reloptions could not be dropped due to compression validation errors being incorrectly raised during non-validation code paths.

Security