CVE-2024-38375: Fastly Js-Compute-Runtime
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
@fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of several functions were determined to include a use-after-free bug. This bug could allow for unintended data loss if the result of the preceding functions were sent anywhere else, and often results in a guest trap causing services to return a 500. This bug has been fixed in version 3.16.0 of the `@fastly/js-compute` package.
Affected products
- Fastly Js-Compute-Runtime: from 3.0.0, before 3.16.0 (fixed in 3.16.0)
Published 2024-06-26. Last modified 2026-06-17.