CVE-2026-33337 is a buffer overflow vulnerability in Firebird, an open-source relational database management system, affecting versions prior to 5.0.4, 4.0.7, and 3.0.14. The flaw exists in the xdr_datum() function during slice packet deserialization, where insufficient validation of cstring length allows a cstring to exceed allocated buffer bounds. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted packet to a Firebird server, potentially causing service disruption or other adverse security impacts. The vulnerability has a CVSS score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction, making it easily exploitable across network boundaries. The attack has low complexity and results in high availability impact through potential server crashes, though no confidentiality or integrity impact is expected. The EPSS score of 0.00054 indicates this is a relatively uncommon vulnerability compared to the broader CVE landscape. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. No public exploit code appears to be widely available, and community attention remains limited. Organizations running affected Firebird versions should prioritize patching to versions 5.0.4, 4.0.7, or 3.0.14 to remediate this denial-of-service risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.0.14CPE matchmatch criteria | cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.7CPE matchmatch criteria | cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.0.4CPE matchmatch criteria | cpe:2.3:a:firebirdsql:firebird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.