CVE-2026-28214: Firebird server hangs when using specific clumplet on batch creation
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the ClumpletReader::getClumpletSize() function can overflow the totalLength value when parsing a Wide type clumplet, causing an infinite loop. An authenticated user with INSERT privileges on any table can exploit this via a crafted Batch Parameter Block to cause a denial of service against the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28214?
CVE-2026-28214 has been classified with a severity level that indicates a vulnerability in Firebird servers prior to versions 5.0.4, 4.0.7, and 3.0.14.
How do I fix CVE-2026-28214?
To mitigate CVE-2026-28214, upgrade your Firebird server to version 5.0.4 or later, 4.0.7 or later, or 3.0.14 or later.
What systems are affected by CVE-2026-28214?
CVE-2026-28214 affects Firebird server versions prior to 5.0.4, 4.0.7, and 3.0.14.
What is the impact of CVE-2026-28214?
The impact of CVE-2026-28214 is that the Firebird server may hang when processing specific clumplets during batch creation.
When was CVE-2026-28214 disclosed?
CVE-2026-28214 was disclosed in a security advisory related to Firebird's vulnerability.