CVE-2026-16503: Vps.org Supabase Template
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.
Affected products
- Vps.org Supabase Template: affected versions not specified
Published 2026-07-31. Last modified 2026-09-08.