{"api_version":"1","generated_at":"2026-04-18T04:16:48+00:00","cve":"CVE-2026-27890","urls":{"html":"https://cve.report/CVE-2026-27890","api":"https://cve.report/api/cve/CVE-2026-27890.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-27890","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-27890"},"summary":{"title":"Firebird has Pre-Auth DOS when Processing Out of Order CNCT_specific_data Segments","description":"Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segments arrive out of order, the Array class's grow() method computes a negative size value, causing a SIGSEGV crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-04-17 19:16:34","updated_at":"2026-04-17 19:16:34"},"problem_types":["CWE-119","CWE-787","CWE-119 CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer","CWE-787 CWE-787: Out-of-bounds Write"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"8.2","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.2","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","version":"3.1"}}],"references":[{"url":"https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-6crx-4g37-7j49","name":"https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-6crx-4g37-7j49","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/FirebirdSQL/firebird/releases/tag/v5.0.4","name":"https://github.com/FirebirdSQL/firebird/releases/tag/v5.0.4","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/FirebirdSQL/firebird/releases/tag/v4.0.7","name":"https://github.com/FirebirdSQL/firebird/releases/tag/v4.0.7","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/FirebirdSQL/firebird/releases/tag/v3.0.14","name":"https://github.com/FirebirdSQL/firebird/releases/tag/v3.0.14","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-27890","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27890","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"FirebirdSQL","product":"firebird","version":"affected >= 3.0.0, < 3.0.14","platforms":[]},{"source":"CNA","vendor":"FirebirdSQL","product":"firebird","version":"affected >= 4.0.0, < 4.0.7","platforms":[]},{"source":"CNA","vendor":"FirebirdSQL","product":"firebird","version":"affected >= 5.0.0, < 5.0.4","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-27890","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-04-17T18:50:13.916401Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-04-17T18:50:22.134Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"firebird","vendor":"FirebirdSQL","versions":[{"status":"affected","version":">= 3.0.0, < 3.0.14"},{"status":"affected","version":">= 4.0.0, < 4.0.7"},{"status":"affected","version":">= 5.0.0, < 5.0.4"}]}],"descriptions":[{"lang":"en","value":"Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segments arrive out of order, the Array class's grow() method computes a negative size value, causing a SIGSEGV crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-119","description":"CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-787","description":"CWE-787: Out-of-bounds Write","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-04-17T18:36:11.924Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-6crx-4g37-7j49","tags":["x_refsource_CONFIRM"],"url":"https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-6crx-4g37-7j49"},{"name":"https://github.com/FirebirdSQL/firebird/releases/tag/v3.0.14","tags":["x_refsource_MISC"],"url":"https://github.com/FirebirdSQL/firebird/releases/tag/v3.0.14"},{"name":"https://github.com/FirebirdSQL/firebird/releases/tag/v4.0.7","tags":["x_refsource_MISC"],"url":"https://github.com/FirebirdSQL/firebird/releases/tag/v4.0.7"},{"name":"https://github.com/FirebirdSQL/firebird/releases/tag/v5.0.4","tags":["x_refsource_MISC"],"url":"https://github.com/FirebirdSQL/firebird/releases/tag/v5.0.4"}],"source":{"advisory":"GHSA-6crx-4g37-7j49","discovery":"UNKNOWN"},"title":"Firebird has Pre-Auth DOS when Processing Out of Order CNCT_specific_data Segments"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-27890","datePublished":"2026-04-17T18:14:29.433Z","dateReserved":"2026-02-24T15:19:29.716Z","dateUpdated":"2026-04-17T18:50:22.134Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-04-17 19:16:34","lastModifiedDate":"2026-04-17 19:16:34","problem_types":["CWE-119","CWE-787","CWE-119 CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer","CWE-787 CWE-787: Out-of-bounds Write"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":4.2}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"27890","Ordinal":"1","Title":"Firebird has Pre-Auth DOS when Processing Out of Order CNCT_spec","CVE":"CVE-2026-27890","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"27890","Ordinal":"1","NoteData":"Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segments arrive out of order, the Array class's grow() method computes a negative size value, causing a SIGSEGV crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.","Type":"Description","Title":"Firebird has Pre-Auth DOS when Processing Out of Order CNCT_spec"}]}}}