{"id":"CVE-2026-67199","published":"2026-08-04T15:16:40.570","lastModified":"2026-08-04T17:16:58.900","description":"Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop indefinitely by submitting a crafted expression containing unbounded for or while loop constructs in a TableMakeViewReq message. Attackers can embed an arbitrarily large iteration count in an expression column evaluated once per table row, causing the Tornado IOLoop to block without any iteration cap, deadline, or cancellation check, rendering the server unresponsive to all connected clients.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-770"],"vendors":[],"products":[],"references":[{"url":"https://christbowel.com/blog/perspective-5-0-0-five-cves/","tags":[]},{"url":"https://www.vulncheck.com/advisories/perspective-dos-via-loop-expression-evaluation","tags":[]},{"url":"https://christbowel.com/blog/perspective-5-0-0-five-cves/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows remote attackers to create a denial of service by submitting a crafted expression with an unbounded loop in a TableMakeViewReq message, blocking the server event loop indefinitely.","exploitability":"Exploitation requires sending a specific crafted request; preconditions include the target running Perspective 5.0.0.","blast_radius":"If exploited, it could render the server unresponsive to all connected clients, impacting service availability and user experience.","remediation":"Update to a patched version of Perspective or apply vendor-provided patches immediately.","tags":["dos","server","loop","tornado"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:05:37.429Z"}}