CRITICAL 9.1 NVD
CVE-2026-16503
Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database p
Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.
References
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-07-31 via NVD.
Risk Timeline
CVE Disclosed2026-07-31 · 3 days ago
Remediation Resources
Official Advisory
kb.cert.org/vuls/id/243636
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.