CVE-2026-16504 PUBLISHED

VPS.org one-click Zulip template deployment instance contains multiple vulnerabilities

Assigner: certcc
Reserved: 21.07.2026 Published: 31.07.2026 Updated: 31.07.2026

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

Product Status

Vendor VPS.org
Product Zulip template
Versions
  • Version N/A is affected

References

Problem Types

  • CWE-1188: Initialization of a Resource with an Insecure Default
  • CWE-321: Use of Hard-coded Cryptographic Key
  • CWE-1393: Use of Default Password