Intel

AIKIDO-2025-10230

@supabase/postgres-meta is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource Consumption Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

20

Low Risk

This Affects:

JS@supabase/postgres-meta
0.81.2 - 0.88.4
Fixed in 0.88.5

TL;DR

Affected versions of this package are vulnerable to denial-of-service (DoS) attacks due to improper query timeout handling. Attackers can exploit this by submitting long-running or complex queries, consuming excessive database resources, and causing service degradation or unavailability. This lack of timeout enforcement allows malicious actors to exhaust CPU, memory, or connection limits, disrupting legitimate users' access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@supabase/postgres-meta is vulnerable to Uncontrolled Resource Consumption in versions 0.81.2 - 0.88.4.

How to fix this

Upgrade the @supabase/postgres-meta library to the patch version.