@fastly/js-compute has a use-after-free in some host call implementations
- Severity:
- Medium
Description
The implementation of the following functions were determined to include a use-after-free bug:
FetchEvent.client.tlsCipherOpensslNameFetchEvent.client.tlsProtocolFetchEvent.client.tlsClientCertificateFetchEvent.client.tlsJA3MD5FetchEvent.client.tlsClientHelloCacheEntry.prototype.userMetadataof thefastly:cachesubsystem- `Device.
Recommendation
Update the @fastly/js-compute package to the latest compatible version. Followings are version details:
- Affected version(s): >= 3.0.0, < 3.16.0
- Patched version(s): 3.16.0
References
Related Issues
- Fastly Compute@Edge JS Runtime has fixed random number seed during compilation - CVE-2022-39218
- Use-After-Free in puppeteer - CVE-2019-5786
- Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges - CVE-2026-50131
- Plate media plugins has a XSS in media embed element when using custom URL parsers - CVE-2024-40631
You might also like:
- Tags:
- npm
- @fastly/js-compute
Anything's wrong? Let us know Last updated on June 26, 2024


