AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Postgres Crashes On Permission Denied For RPC Functions Due To Exit_on_error Misconfiguration

Calling an RPC function without EXECUTE privilege for the anonymous role causes a backend crash and database restart in Supabase's Postgres 17.6.1.111, allowing unauthenticated denial-of-service. The crash is caused by the PostgreSQL configuration parameter exit_on_error being enabled, which forces the backend to terminate on any ERROR instead of returning a normal error response.

criticalConfidence 75%PostgresAffected V17.6.1.111

Origin Analysis

The PostgreSQL configuration parameter exit_on_error is set to on in Supabase's patched build (17.6.1.111). This causes any ERROR, including permission denied for function execution, to terminate the backend process immediately instead of raising a catchable exception. As a result, a simple permission check failure crashes the entire Postgres instance.
1. Create a Postgres function without granting EXECUTE to the anon role. 2. Call that function via the Supabase REST API using only the public anon key (no auth session). 3. Observe that the Postgres backend crashes and the database restarts (~10 seconds downtime). 4. Check the PostgreSQL configuration: SHOW exit_on_error; it returns 'on'.

Fixing Code Block

Edge Case Audit

Changing exit_on_error from on to off is a low-risk change and is the default behaviour in standard PostgreSQL. However, if any application or monitoring system was intentionally relying on backend termination on error (which is extremely unusual and not recommended), it would be affected. Rollback: ALTER SYSTEM SET exit_on_error = on; SELECT pg_reload_conf();. Note that existing connections will retain the old setting until they reconnect; a full restart may be required if immediate effect is needed.

Ecosystem Topology