Robert Haas discovered that some selectivity estimators did not validate user privileges which could result in information disclosure (CVE-2017-7484).
Daniel Gustafsson discovered that the PGREQUIRESSL environment variable did no longer enforce a TLS connection (CVE-2017-7485).
Andrew Wheelwright discovered that user mappings were insufficiently restricted (CVE-2017-7486).