{"id":"CVE-2026-67198","published":"2026-08-04T15:16:40.423","lastModified":"2026-08-04T17:16:58.467","description":"Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or MakeTableReq with no data field to trigger unwrap() calls on None values at nine distinct sites, causing the process to abort with SIGABRT.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-616"],"vendors":[],"products":[],"references":[{"url":"https://christbowel.com/blog/perspective-5-0-0-five-cves/","tags":[]},{"url":"https://www.vulncheck.com/advisories/perspective-dos-via-virtualserver-protocol-dispatcher","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw in Perspective 5.0.0 allows unauthenticated attackers to crash the server by sending malformed protobuf messages, leading to a denial-of-service condition.","exploitability":"Exploitation requires knowledge of the VirtualServer protocol and crafting specific malformed messages; no authentication is needed.","blast_radius":"If exploited, it could lead to service disruption affecting all users until the vulnerability is patched.","remediation":"Update Perspective to a version that addresses this vulnerability or apply vendor-provided patches immediately.","tags":["dos","protobuf","server-crash","unauthenticated"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:53:52.043Z"}}