PostgreSQL Instance Vulnerability in VPS.org Supabase Template Deployment
CVE-2026-16503

Currently unrated

Key Information:

Vendor

Vps.org

Vendor
CVE Published:
31 July 2026

What is CVE-2026-16503?

The VPS.org one-click Supabase template deployment unintentionally exposes a PostgreSQL instance to all network interfaces (0.0.0.0:5432) with a default password of 'postgres'. This creates a significant security risk, as it allows unauthorized access to the database. Furthermore, Docker's automated iptables configurations override standard host firewall rules, leading to vulnerabilities that may not be mitigated by conventional firewall settings. Administrators must ensure secure configurations to prevent unauthorized database access and potential data breaches.

Affected Version(s)

Supabase template

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.