Generated remediation guidance and an executive summary. No account required.
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, the port_server_crypt_callback handler is not initialized, resulting in a null pointer dereference and server crash. An unauthenticated attacker who knows only the server's IP and port can exploit this to crash the server. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.
Use CWE-476, Firebirdsql vendor hub and Firebird product page to widen CVE-2026-28224 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-40342, CVE-2026-27890 and CVE-2025-65104 for nearby disclosures in the same product family.