Generated remediation guidance and an executive summary. No account required.
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when processing CNCT_specific_data segments during authentication, the server assumes segments arrive in strictly ascending order. If segments arrive out of order, the Array class's grow() method computes a negative size value, causing a SIGSEGV crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.
Cite this page
CVE-2026-27890. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-27890
Use CWE-119, Firebirdsql vendor hub and Firebird product page to widen CVE-2026-27890 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-40342, CVE-2026-28224 and CVE-2025-65104 for nearby disclosures in the same product family.