CVE-2026-28224

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, the port_server_crypt_callback handler is not initialized, resulting in a null pointer dereference and server crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*
cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*
cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*

History

24 Apr 2026, 19:45

Type Values Removed Values Added
References () https://github.com/FirebirdSQL/firebird/releases/tag/v3.0.14 - () https://github.com/FirebirdSQL/firebird/releases/tag/v3.0.14 - Release Notes
References () https://github.com/FirebirdSQL/firebird/releases/tag/v4.0.7 - () https://github.com/FirebirdSQL/firebird/releases/tag/v4.0.7 - Release Notes
References () https://github.com/FirebirdSQL/firebird/releases/tag/v5.0.4 - () https://github.com/FirebirdSQL/firebird/releases/tag/v5.0.4 - Release Notes
References () https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-xrcw-wpjx-pr95 - () https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-xrcw-wpjx-pr95 - Exploit, Vendor Advisory
CPE cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:*
First Time Firebirdsql firebird
Firebirdsql

17 Apr 2026, 20:16

Type Values Removed Values Added
References () https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-xrcw-wpjx-pr95 - () https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-xrcw-wpjx-pr95 -

17 Apr 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-17 19:16

Updated : 2026-04-24 19:45


NVD link : CVE-2026-28224

Mitre link : CVE-2026-28224

CVE.ORG link : CVE-2026-28224


JSON object : View

Products Affected

firebirdsql

  • firebird
CWE
CWE-476

NULL Pointer Dereference