---
id: CVE-2026-11312
aliases:
  - GHSA-2vrg-7rqv-prf9
title: >-
  bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in
  InfiniStore KV Map
summary: >-
  bytedance InfiniStore: Denial of Service via Non-Cryptographic Hashing in
  InfiniStore KV Map
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'
vendor: infinistore
product: infinistore
ecosystem: pip
affected:
  - infinistore <= 0.2.33
published: '2026-06-05'
updated: '2026-07-15'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-2vrg-7rqv-prf9'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11312'
  - url: 'https://github.com/bytedance/InfiniStore/issues/200'
  - url: 'https://github.com/bytedance/InfiniStore'
  - url: 'https://vuldb.com/cve/CVE-2026-11312'
  - url: 'https://vuldb.com/submit/832348'
  - url: 'https://vuldb.com/vuln/368398'
  - url: 'https://vuldb.com/vuln/368398/cti'
tags:
  - osv
  - pip
epss: 0.00112
epssPercentile: 0.01263
ingestedAt: '2026-07-16T18:59:41.387Z'
---

## Overview

A vulnerability was found in bytedance InfiniStore up to 0.2.33. The impacted element is the function purge_kv_map in the library /src/infinistore.h of the component KV Map Handler. Performing a manipulation results in inefficient algorithmic complexity. The attack requires a local approach. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

## Affected packages

- `infinistore <= 0.2.33`

## Remediation

Refer to the advisory for the patched release.
