PT-2026-33475 · Firebird+1 · Firebird Client Library+1

CVE-2025-65104

·

Published

2026-04-17

·

Updated

2026-05-15

CVSS v3.1

7.9

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Firebird client library version FB3
Description The FB3 client library places incorrect data length values into XSQLDA fields when communicating with Firebird servers version FB4 or higher, which leads to an information leak.
Recommendations Upgrade to the FB4 client or higher.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07785
CVE-2025-65104
GHSA-MFPR-9886-XJHG
OESA-2026-2013
OESA-2026-2014
OESA-2026-2015
OESA-2026-2016
OESA-2026-2017
SUSE-SU-2026:1868-1

Affected Products

Firebird Client Library
Red Os