This was pointed out to be missing from the BIP by @petertodd.
CTV is, as implemented in the PR, safe. This is not by accident, CTV was designed to not have these problems. But it's important to make these DoS issues and CTV's design w.r.t. clear, especially since the adding of the example checker logic did make the BIP's spec dos-able (though not any reference implementation).