CVE-2026-67198
Published: August 4th, 2026
Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or MakeTableReq with no data field to trigger unwrap() calls on None values at nine distinct sites, causing the process to abort with SIGABRT.
HIGH
CVSS v3: 7.5
CVSS v3: 7.5
Status
| DocFilters Release | Package | State | Justification | Comment |
|---|---|---|---|---|
| 26.3 | protobuf (3.0.0) | Not Affected | Code Not Present | CVE-2026-67198 is a denial-of-service vulnerability (availability-only, CVSS 3.1 base 7.5) in Perspective (github.com/perspective-dev/perspective, formerly finos/perspective), a Rust data-visualization and analytics component. The flaw is in Perspective’s own VirtualServer protocol dispatcher, where nine Rust unwrap() calls on None values abort the process with SIGABRT when a request such as ViewToArrowReq or MakeTableReq omits a required field. The CVE was flagged against Document Filters because the scanner matched the word ‘protobuf’ in the description to our external/protobuf-3.0.0 dependency, but the vulnerability is not in the protobuf library itself. Perspective is not present in Document Filters in any form: the codebase contains no Rust source files and no Cargo.toml, and the VirtualServer dispatcher, ViewToArrowReq, and MakeTableReq message types do not exist anywhere in this tree. Document Filters uses the C++ protobuf library v3.0.0 compiled from source for runtime deserialization only, and ships no network server that could be remotely reached. |
| 26.2 | protobuf (3.0.0) | Needs Triage | ||
| 26.1 | protobuf (3.0.0) | Needs Triage | ||
| 25.4 | protobuf (3.0.0) | Needs Triage | ||
| 25.3 | protobuf (3.0.0) | Needs Triage | ||
| 25.2 | protobuf (3.0.0) | Needs Triage | ||
| 25.1 | protobuf (3.0.0) | Needs Triage | ||
| 24.4 | protobuf (3.0.0) | Needs Triage | ||
| 24.4.0 | protobuf (3.0.0) | Needs Triage | ||
| 24.3 | protobuf (3.0.0) | Needs Triage | ||
| 24.2 | protobuf (3.0.0) | Needs Triage | ||
| 24.1 | protobuf (3.0.0) | Needs Triage | ||
| 23.3 | protobuf (3.0.0) | Needs Triage | ||
| 23.2 | protobuf (3.0.0) | Needs Triage | ||
| 23.1 | protobuf (3.0.0) | Needs Triage | ||
| 22.4 | protobuf (3.0.0) | Needs Triage | ||
| 22.3 | protobuf (3.0.0) | Needs Triage | ||
| 22.2 | protobuf (3.0.0) | Needs Triage | ||
| 22.1 | protobuf (3.0.0) | Needs Triage | ||
| 21.11 | protobuf (3.0.0) | Needs Triage | ||
| 21.8 | protobuf (3.0.0) | Needs Triage | ||
| 21.5.0 | protobuf (3.0.0) | Needs Triage | ||
| 21.2.0 | protobuf (3.0.0) | Needs Triage | ||
| 11.4.19.3667 | protobuf (3.0.0) | Needs Triage | ||
| 11.4.18.3599 | protobuf (3.0.0) | Needs Triage | ||
| 11.4.16.3445 | protobuf (3.0.0) | Needs Triage | ||
| 11.4.15.3368 | protobuf (3.0.0) | Needs Triage | ||
| 11.4.14.3263 | protobuf (3.0.0) | Needs Triage | ||
| 11.4.13.3179 | protobuf (3.0.0) | Needs Triage | ||
| 11.4.12.3054 | protobuf (3.0.0) | Needs Triage | ||
| 11.4.11.3040 | protobuf (3.0.0) | Needs Triage | ||
| 11.4.11.2990 | protobuf (3.0.0) | Needs Triage | ||
| 11.4.10.2934 | protobuf (3.0.0) | Needs Triage | ||
| 11.4.9.2878 | protobuf (3.0.0) | Needs Triage | ||
| 11.4.8.2822 | protobuf (3.0.0) | Needs Triage |
Severity score breakdown
Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
HIGH
Base Score
7.5
Base Severity
HIGH
Confidentiality Impact
NONE
Integrity Impact
NONE
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
NONE
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Version
3.1