NULL pointer dereference in Firebird - CVE-2026-28224
Published: April 20, 2026
Firebird
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to null pointer dereference in port_server_crypt_callback handling when processing an unauthenticated op_crypt_key_callback request. A remote attacker can send a specially crafted request to cause a denial of service.
The request can be sent without authorization.