Description
@fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of several functions were determined to include a use-after-free bug. This bug could allow for unintended data loss if the result of the preceding functions were sent anywhere else, and often results in a guest trap causing services to return a 500. This bug has been fixed in version 3.16.0 of the `@fastly/js-compute` package.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2111 | @fastly/js-compute is a JavaScript SDK and runtime for building Fastly Compute applications. The implementation of several functions were determined to include a use-after-free bug. This bug could allow for unintended data loss if the result of the preceding functions were sent anywhere else, and often results in a guest trap causing services to return a 500. This bug has been fixed in version 3.16.0 of the `@fastly/js-compute` package. |
Github GHSA |
GHSA-mp3g-vpm9-9vqv | @fastly/js-compute has a use-after-free in some host call implementations |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:04:25.287Z
Reserved: 2024-06-14T14:16:16.467Z
Link: CVE-2024-38375
Updated: 2024-07-30T19:52:47.894Z
Status : Deferred
Published: 2024-06-26T19:15:13.677
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-38375
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:31:05Z
Weaknesses
EUVD
Github GHSA