CVE-2026-34232: high-severity vulnerability in FirebirdSQL firebird
Firebird: DoS via `op_response` packet from client
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.7%
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_status_vector() function does not handle the isc_arg_cstring type when decoding an op_response packet, causing a server crash when one is encountered in the status vector. An unauthenticated attacker can exploit this by sending a crafted op_response packet to the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
FirebirdSQL · firebirdRelated CVEs — FirebirdSQL firebird
In the same product, most dangerous first.
CVE-2026-40342CRITICALFirebird: Path Traversal + Arbitrary File Write Leads to Remote Code ExecutionEPSS 0.8%CVE-2026-33337HIGHFirebird has a buffer overflow when parsing corrupted slice packetsEPSS 0.8%CVE-2026-28212HIGHFirebird has potential server crash via null pointer dereference when processing op_slice packetEPSS 0.8%CVE-2026-28224HIGHFirebird Null Pointer Dereference via CryptCallback causes DOSEPSS 0.7%CVE-2026-27890HIGHFirebird has Pre-Auth DOS when Processing Out of Order CNCT_specific_data SegmentsEPSS 0.7%CVE-2026-35215HIGHFirebird: DoS via malicious slice descriptor in slice packetEPSS 0.7%