diff --git a/doc/src/sgml/release-9.5.sgml b/doc/src/sgml/release-9.5.sgml
index 95213333a25..a3e8a5ac5fc 100644
--- a/doc/src/sgml/release-9.5.sgml
+++ b/doc/src/sgml/release-9.5.sgml
@@ -41,6 +41,39 @@
+
+ Make contrib modules' installation scripts more secure (Tom Lane)
+
+
+
+ Attacks similar to those described in CVE-2018-1058 could be carried
+ out against an extension installation script, if the attacker can
+ create objects in either the extension's target schema or the schema
+ of some prerequisite extension. Since extensions often require
+ superuser privilege to install, this can open a path to obtaining
+ superuser privilege. To mitigate this risk, be more careful about
+ the search_path used to run an installation
+ script; disable check_function_bodies within the
+ script; and fix catalog-adjustment queries used in some contrib
+ modules to ensure they are secure. Also provide documentation to
+ help third-party extension authors make their installation scripts
+ secure. This is not a complete solution; extensions that depend on
+ other extensions can still be at risk if installed carelessly.
+ (CVE-2020-14350)
+
+
+
+
+