CVE-2026-2004: require superuser to install non-built-in selectivity
estimators and harden intarray intmatchsel() against wrong operator type
CVE-2026-2005: fix heap buffer overflow in pgcrypto PGP public-key
decryption by validating session key length
CVE-2026-2006: fix multibyte character handling vulnerabilities in wchar
conversion, EUCCN encoding length, and replace pgmblen() with
bounds-checked versions across all call sites