Junglewise Threat Intelligence

CVE-2026-11312: ByteDance InfiniStore Inefficient Algorithmic Complexity in KV Map Handler

CVE-2026-11312 · Severity: low · CVSS 3.3 · Published 2026-06-05

Vendors: PyPI.

Executive brief

ByteDance InfiniStore is a high-performance key-value storage system. A vulnerability in how it handles data storage keys allows an attacker to intentionally cause performance slowdowns. By submitting specifically crafted keys, an attacker can force the system into an inefficient state, leading to a denial-of-service condition that impacts all users of the storage instance.

Technical details

The vulnerability exists in the `purge_kv_map` function within `src/infinistore.h` of the KV Map Handler component. InfiniStore utilizes `std::unordered_map<std::string, ...>` with the default `std::hash<std::string>` implementation, which is deterministic and non-cryptographic. Because the application does not use a keyed secret or per-process randomization for hashing, a local attacker can precompute and submit a large set of distinct cache keys that collide into the same hash bucket. This forces the map operations to degrade from O(1) to O(n) complexity, blocking the single-threaded libuv server path and causing a denial of service. As of the advisory date, no patch is available.

Affected products

  • ByteDance InfiniStore <= 0.2.33

Timeline

  • 2026-06-05: disclosed: Vulnerability disclosed via GitHub Advisory and NVD.
  • 2026-06-05: advisory
  • 2026-07-15: other: Advisory updated with reviewed status.

References