Vulnerability library
Security checkJune 26, 2024

@fastly/js-compute has a use-after-free in some host call implementations

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpm@fastly/js-compute

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The implementation of the following functions were determined to include a use-after-free bug:

  • FetchEvent.client.tlsCipherOpensslName
  • FetchEvent.client.tlsProtocol
  • FetchEvent.client.tlsClientCertificate
  • FetchEvent.client.tlsJA3MD5
  • FetchEvent.client.tlsClientHello
  • CacheEntry.prototype.userMetadata of the fastly:cache subsystem
  • `Device.

Recommendation

Update the @fastly/js-compute package to the latest compatible version. Followings are version details:

  • Affected version(s): >= 3.0.0, < 3.16.0
  • Patched version(s): 3.16.0

References

Could your website be exposed too?

SmartScanner can check your website for @fastly/js-compute has a use-after-free in some host call implementations and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated June 26, 2024