---
id: CVE-2025-65104
title: Firebird is an open-source relational database management system
summary: >-
  Firebird is an open-source relational database management system. In versions
  FB3 of the client library placed incorrect data length values into XSQLDA
  fields when communicating with FB4 or higher servers, resulting in an
  information lea…
severity: high
cvss: 7.9
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L'
cwe:
  - CWE-200
vendor: firebirdsql
product: firebird
affected:
  - firebird < 3.0.14
patched:
  - firebird 3.0.14
published: '2026-04-17'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-65104'
references:
  - url: 'https://github.com/FirebirdSQL/firebird/releases/tag/v4.0.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/FirebirdSQL/firebird/security/advisories/GHSA-mfpr-9886-xjhg
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00185
epssPercentile: 0.07284
ingestedAt: '2026-09-30T22:27:27.762Z'
---

## Overview

Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue is fixed by upgrading to the FB4 client or higher.

## Affected

- `firebird < 3.0.14`

## Remediation

Upgrade past the affected range:

- `firebird 3.0.14`
