CVE-2026-16503
VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities
CVSS Score
9.1
EPSS Score
0.1%
EPSS Percentile
4th
Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.
| Vendor | vps.org |
| Product | supabase template |
| Published | Jul 31, 2026 |
| Last Updated | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for vps.org supabase template
Be the first to know when new critical vulnerabilities affecting vps.org supabase template are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
VPS.org / Supabase template
N/A