Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.
References
| Link | Resource |
|---|---|
| https://kb.cert.org/vuls/id/243636 |
Configurations
No configuration.
History
03 Aug 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-1188 CWE-1327 CWE-1393 |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
31 Jul 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-31 16:16
Updated : 2026-08-03 18:16
NVD link : CVE-2026-16503
Mitre link : CVE-2026-16503
CVE.ORG link : CVE-2026-16503
JSON object : View
Products Affected
No product.
