๐Ÿ” CVE Alert

CVE-2026-16503

CRITICAL 9.1

VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities

CVSS Score
9.1
EPSS Score
0.1%
EPSS Percentile
4th

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.

Vendor vps.org
Product supabase template
Published Jul 31, 2026
Last Updated Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for vps.org supabase template

Be the first to know when new critical vulnerabilities affecting vps.org supabase template are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

VPS.org / Supabase template
N/A

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
kb.cert.org: https://kb.cert.org/vuls/id/243636