Executive brief
ByteDance InfiniStore is a high-performance key-value storage system. A vulnerability in how it handles data storage keys allows an attacker to intentionally cause performance slowdowns. By submitting specifically crafted keys, an attacker can force the system into an inefficient state, leading to a denial-of-service condition that impacts all users of the storage instance.
Technical details
The vulnerability exists in the `purge_kv_map` function within `src/infinistore.h` of the KV Map Handler component. InfiniStore utilizes `std::unordered_map<std::string, ...>` with the default `std::hash<std::string>` implementation, which is deterministic and non-cryptographic. Because the application does not use a keyed secret or per-process randomization for hashing, a local attacker can precompute and submit a large set of distinct cache keys that collide into the same hash bucket. This forces the map operations to degrade from O(1) to O(n) complexity, blocking the single-threaded libuv server path and causing a denial of service. As of the advisory date, no patch is available.
Affected products
- ByteDance InfiniStore <= 0.2.33
Timeline
- 2026-06-05: disclosed: Vulnerability disclosed via GitHub Advisory and NVD.
- 2026-06-05: advisory
- 2026-07-15: other: Advisory updated with reviewed status.