The WarehousePG documentation describes the latest version of WarehousePG 6.
| Version | Release date |
|---|---|
| 6.27.6-WHPG | 25 September 2026 |
| 6.27.5-WHPG | 10 June 2026 |
| 6.27.4-WHPG | 7 April 2026 |
| 6.27.3-WHPG | 28 January 2026 |
| 6.27.2-WHPG | 8 December 2025 |
WarehousePG 6.27.6-WHPG
Released: 25 September 2026
WarehousePG 6.27.6-WHPG is a security-focused release. It includes the following bug fixes and other changes:
Note
WarehousePG 6.27.6 changes several behaviors that can affect existing scripts and configurations, including dump output format, CREATE OPERATOR privileges, and pgcrypto and psql behavior. Review Upgrading to 6.27.6: Behavior changes to review before you upgrade.
Bug fixes
- Fixed
gploadto pass arguments through its shell wrapper without word splitting, so control-file paths with spaces work, and to fall back to$HOME/gpAdminLogswhen the-llog file is unusable. - Fixed PL/Perl array and tied-container handling for non-rectangular arrays, forged
ARRAYobjects, tiedSETOFarray references, andNULLSV *values. - Fixed
pgcryptoto reset the global debug handler after a PGP pipeline error, so later calls no longer emit straydbg:notices.
Security
- Fixed a
pg_dumpprivilege-escalation race by adding therestrict_nonsystem_relation_kindconfiguration parameter (view,foreign-table), whichpg_dumpsets for the duration of a dump to stop the backend from expanding non-system views or accessing non-system foreign tables, for CVE-2024-7348. - Wrapped plain-text output from
pg_dump,pg_dumpall, andpg_restoreinpsql\restrictand\unrestrictmarkers, so a hostile server can't inject meta-commands executed at restore time, and added the--restrict-keyoption, for CVE-2025-8714. - Fixed a one-byte overread in GB18030 multibyte character handling, replaced unbounded
pg_mblen()call sites with length-checked variants across the server, fixed an out-of-bounds read in JSON parse error messages for incomplete byte sequences, and fixedtranslate()reading one byte past the end of itstoargument, for CVE-2025-4207 and CVE-2026-2006. - Required superuser to attach a non-built-in
RESTRICTorJOINselectivity estimator inCREATE OPERATOR, and hardenedtsmatchsel()against a non-tsvectoroperand, for CVE-2026-2004. - Fixed a buffer overflow in
pgcrypto'spgp_pub_decrypt_bytea()function by bounding the session key length, for CVE-2026-2005. - Stopped
psqlfrom executing in-lineCOPY ... FROM STDINdata as SQL after theCOPYcommand fails, including WarehousePG 6's legacyCOPY ... WITH OIDS FROM STDINsyntax, for CVE-2026-6464. - Hardened
tsvectorandtsqueryconstruction against integer overflows intsvectorrecv(),make_tsvector(),parsetext(),tsvectorout(), andQTN2QT(), for CVE-2026-14662. - Fixed
pgcryptoto fail cipher operations during PGP encryption instead of emitting effectively unencrypted data, and added theignore-cipher-failuredecryption option to read back data mis-encrypted by affected builds, for CVE-2026-14663. - Fixed a buffer overrun in
regexp_matches(),regexp_split_to_table(), andregexp_split_to_array()on invalidly encoded input, for CVE-2026-14664. - Fixed
ascii()to validate multibyte input length before reading continuation bytes, with related fixes toEUC_CNlength handling,mb2wchar()on short input, PGP-decrypted text encoding validation, andSUBSTRING()on toasted multibyte values, bounded the copy of overlength time zone abbreviations into_char(), and fixed PL/Perl to read a tied array's length only once inplperl_array_to_datum(), for CVE-2026-18024, CVE-2026-14669, and CVE-2026-14670. - Removed a stale per-backend plan cache in
contrib/spi/refint'scheck_foreign_key()function that caused type confusion, and fixed aNULL-key segfault, for CVE-2026-14671. - Used overflow-safe array allocation in
pltclandplperl, and guarded fixed-size argument arrays in the parser, fmgr, PL/pgSQL,plperl,plpython, andpltclagainst extreme argument counts, for CVE-2026-14677 and CVE-2026-14679. - Fixed
pg_trgm'sgtrgm_picksplit()function reading past the end of the signature buffer for all-true datums, for CVE-2026-14678. - Rejected SQL-level calls to functions that take or return the
internaltype, including operator and cast syntax, fixednumeric_avg_combine()andnumeric_combine()to handle aNaNcount correctly, and made aggregate combine functions returnNULLhonestly, for CVE-2026-14680. - Fixed integer overflow and out-of-bounds writes in
fuzzystrmatch's Levenshtein distance functions by computing distances in 64-bit arithmetic, for CVE-2026-15742. - Fixed a memory disclosure and possible remote code execution vulnerability from a mismatch between a portal's tuple descriptor and the query's actual output during
EXECUTEorFETCH, for CVE-2026-16239.
WarehousePG 6.27.5-WHPG
Released: 10 June 2026
WarehousePG 6.27.5-WHPG includes the following bug fixes and other changes:
Bug fixes
- Fixed
GPHOME_CLIENTSresolution ingreenplum_clients_path.shto correctly locate client binaries.
Security
- Hardened multiple modules against integer overflow vulnerabilities for CVE-2026-6473, including ltree,
ts_headline, intarray, the regex engine,unicode_normalize,formatting.c,array_agg, and the hstore PL/Perl and PL/Python extensions. - Fixed a format-string vulnerability in
timeofday()for CVE-2026-6474 where a crafted time zone setting could abuse thepg_strftime()%Zformat specifier to cause crashes or corrupt server memory. - Fixed a path traversal vulnerability in
pg_rewindfor CVE-2026-6475 where paths received from a rogue endpoint could overwrite files outside the target directory. - Fixed a buffer overrun in the frontend large object interface (
libpq) for CVE-2026-6477 wherePQfn()could write beyond the end of the result buffer when the server returned more data than requested. - Added timing-safe comparisons for secret material in all authentication paths for CVE-2026-6478, covering SCRAM, MD5, RADIUS, and plain authentication methods.
- Fixed a stack overflow vulnerability in
ProcessStartupPacket()for CVE-2026-6479 where a malicious client could alternate SSL and GSS negotiation requests indefinitely to exhaust server stack space. - Fixed an SQL injection and buffer overrun vulnerability in the
refintcontrib module for CVE-2026-6637.
WarehousePG 6.27.4-WHPG
Released: 7 April 2026
WarehousePG 6.27.4-WHPG includes the following new features, enhancements, bug fixes, and other changes:
Bug fixes
- Resolved critical stability issues in the ORCA optimizer including fixes for segmentation faults and infinite recursion.
- Fixed an issue where unnecessary motion was created on query executor slices.
- Corrected behavior and stability when running the
execute on initplanfunction. - Removed role assertions in
get_ao_compression_ratio()andaorow_compression_ratio_internalto allow the function to execute on query executors, enabling the use ofgp_dist_random()to retrieve compression statistics from all segments.
Security
- Fixed a heap buffer overflow vulnerability in libpq for CVE-2025-12818 by hardening memory allocation against integer overflows. This change implements stricter
size_tcalculations for large, untrusted inputs to ensure allocated buffers are sufficient for their contents.
WarehousePG 6.27.3-WHPG
Released: 28 January 2026
WarehousePG 6.27.3-WHPG includes the following new features, enhancements, bug fixes, and other changes:
Bug fixes
- Made the
ReScanForeignScancallback optional for Foreign Data Wrappers (FDWs) to simplify the implementation and improve compatibility for external data sources. - Removed the
GUC_NO_SHOW_ALLflag for thearchive_timeoutconfiguration parameter to ensure the setting is correctly displayed in all system configuration views.
WarehousePG 6.27.2-WHPG
Released: 8 December 2025
WarehousePG 6.27.2-WHPG includes the following new features, enhancements, bug fixes, and other changes:
Enhancements
- Restored the functionality of
greenplum-abi-teststo ensure ongoing development stability and interface compatibility. - Adjusted
ftsprobelogging to useWARNINGseverity for failure and retry exhaustion events, ensuring these critical messages are always visible regardless ofgp_log_ftssettings.
Bug fixes
- Resolved mirror promotion failures and fixed assertion failures caused by the incorrect application of the
fmtId()function. - Improved error detection reliability in
status_checkcases and implemented checks for MergeAppend nodes in the share input mutator. - Optimized internal performance by transitioning to
LWLocksfor instrumentation headers and using pipes instead of sockets for immediate poll termination. - Fixed an issue where tables with corrupted
reloptionscould not be dropped due to compression validation errors being incorrectly raised during non-validation code paths.
Security
- Included a fix for CVE-2025-1094.
- Included a fix for CVE-2024-10979.
- Included a fix for CVE-2024-10977.
- Included a fix for CVE-2024-0985.
- Included a fix for CVE-2020-14343.