CVE-2026-67198CWE-616

CVE-2026-67198

High · published August 4, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
9.9
In the wild
Unconfirmed
What it is

Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or MakeTableReq with no data field to trigger unwrap() calls on None values at nine distinct sites, causing the process to abort with SIGABRT.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00200 · 9.9th percentile
Weakness
CWE-616 · Incomplete Identification of Uploaded File Variables (PHP)
Published
2026-08-04T19:16Z
References (2)
EPSS history
Timeline
  • 04 AUG 14:04Z
    Perspective 5.0.0 DoS via VirtualServer Protocol Dispatcher
    cvelistv5