PT-2026-33483 · Firebirdsql · Firebird

Published

2026-04-17

·

Updated

2026-04-17

·

CVE-2026-34232

CVSS v3.1

7.5

High

AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr status vector() function does not handle the isc arg cstring type when decoding an op response packet, causing a server crash when one is encountered in the status vector. An unauthenticated attacker can exploit this by sending a crafted op response packet to the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-34232

Affected Products

Firebird