


Perceptive Security
SOC/SIEM Consultancy

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum…
Published:
16 april 2026 om 22:00:00
Alert date:
17 april 2026 om 20:03:43
Source:
nvd.nist.gov
Database & Storage
A buffer overflow vulnerability exists in Firebird open-source database management system versions prior to 5.0.4, 4.0.7, and 3.0.14. The vulnerability occurs in the xdr_datum() function when deserializing slice packets, where cstring length validation is not performed against slice descriptor bounds. This allows an unauthenticated attacker to send crafted packets causing buffer overflow, potentially leading to server crashes or other security impacts. The issue has been patched in the latest versions across all affected branches.
Technical details
Mitigation steps:
Affected products:
Firebird Database Management System
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-33337
https://github.com/FirebirdSQL/firebird/releases/tag/v3.0.14
https://github.com/FirebirdSQL/firebird/releases/tag/v4.0.7
https://github.com/FirebirdSQL/firebird/releases/tag/v5.0.4
https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-89mq-229g-x47p
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
