PatchSiren

FirebirdSQL CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH FirebirdSQL CVE published 2026-04-17

CVE-2025-65104

Firebird client library versions FB3 incorrectly report data length values to FB4 or higher servers, causing an information leak. This issue affects database administrators and developers using Firebird, who should assess exposure and prioritize upgrading to FB4 or higher client libraries to prevent potential data disclosure. Upgrading to FB4 client or higher fixes this issue. The vulnerability has a high [truncated]