HIGH🇵🇱 Wersja polska

CVE-2026-28224

CVSS 8.2v3.1pub. 2026-04-17upd. 2026-04-24

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, the port_server_crypt_callback handler is not initialized, resulting in a null pointer dereference and server crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
  • Firebirdsql Firebird

    APP
    Firebirdsql
    < 3.0.144.0.0 – 4.0.7 (excl.)5.0.0 – 5.0.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-40342CRITICAL9.9PL ✓same product

RCE przez path traversal w ładowaniu wtyczek zewnętrznych Firebird

CVE-2026-27890HIGH8.2same product

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14...

CVE-2026-28212HIGH7.5same product

Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and...

CVE-2025-65104HIGH7.9same product

Firebird is an open-source relational database management system. In versions FB3 of the client library placed...

CVE-2026-33337HIGH7.5same product

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14...