Input validation error in Firebird - CVE-2026-34232
Published: April 20, 2026
Firebird
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in xdr_status_vector() when parsing an op_response packet containing isc_arg_cstring in the status vector. A remote attacker can send a specially crafted packet to cause a denial of service.
The issue can crash the server while decoding a client-supplied op_response packet, even though such a request is later dropped in loopThread().