High severity8.2NVD Advisory· Published Apr 17, 2026· Updated Apr 24, 2026
CVE-2026-28224
CVE-2026-28224
Description
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, the port_server_crypt_callback handler is not initialized, resulting in a null pointer dereference and server crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/FirebirdSQL/firebird/security/advisories/GHSA-xrcw-wpjx-pr95nvdExploitVendor Advisory
- github.com/FirebirdSQL/firebird/releases/tag/v3.0.14nvdRelease Notes
- github.com/FirebirdSQL/firebird/releases/tag/v4.0.7nvdRelease Notes
- github.com/FirebirdSQL/firebird/releases/tag/v5.0.4nvdRelease Notes
News mentions
0No linked articles in our index yet.