CVE-2026-16503 PUBLISHED

VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities

Assigner: certcc
Reserved: 21.07.2026 Published: 31.07.2026 Updated: 31.07.2026

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.

Product Status

Vendor VPS.org
Product Supabase template
Versions
  • Version N/A is affected

References

Problem Types

  • CWE-1327: Binding to an Unrestricted IP Address
  • CWE-1393: Use of Default Password
  • CWE-1188: Initialization of a Resource with an Insecure Default