VYPR
Unrated severityNVD Advisory· Published Jul 31, 2026· Updated Aug 3, 2026

VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities

CVE-2026-16503

Description

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

1