PostgreSQL Instance Vulnerability in VPS.org Supabase Template Deployment
CVE-2026-16503
Currently unrated
What is CVE-2026-16503?
The VPS.org one-click Supabase template deployment unintentionally exposes a PostgreSQL instance to all network interfaces (0.0.0.0:5432) with a default password of 'postgres'. This creates a significant security risk, as it allows unauthorized access to the database. Furthermore, Docker's automated iptables configurations override standard host firewall rules, leading to vulnerabilities that may not be mitigated by conventional firewall settings. Administrators must ensure secure configurations to prevent unauthorized database access and potential data breaches.
Affected Version(s)
Supabase template
