CVE-2026-2004: require superuser to install non-built-in selectivity
estimators and harden intarray _int_matchsel() against wrong operator type
CVE-2026-2005: fix heap buffer overflow in pgcrypto PGP public-key
decryption by validating session key length
CVE-2026-2006: fix multibyte character handling vulnerabilities in wchar
conversion, EUC_CN encoding length, and replace pg_mblen() with
bounds-checked versions across all call sites