PT-2026-66762 · Vps.Org · Supabase Template

CVE-2026-16503

·

Published

2026-07-31

·

Updated

2026-07-31

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-16503

Affected Products

Supabase Template