Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://kb.cert.org/vuls/id/243636 |
|
Mon, 03 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1188 CWE-1327 CWE-1393 |
|
| Metrics |
cvssV3_1
|
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vps.org
Vps.org supabase Template |
|
| Vendors & Products |
Vps.org
Vps.org supabase Template |
Sun, 02 Aug 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-259 CWE-285 |
Fri, 31 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration. | |
| Title | VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-08-03T17:13:26.182Z
Reserved: 2026-07-21T19:08:29.074Z
Link: CVE-2026-16503
Updated: 2026-08-03T17:12:42.993Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-04T11:30:07Z