Skip to main content

Vendor archive

supabase CVEs

Beta · best-effort

2 CVEs tagged to vendor supabase1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-31813

Published Mar 11, 2026

Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been identified that allows an attacker to issue sessions for arb…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-24213

Published Feb 8, 2024

Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1