Fastly is a content delivery and edge-computing platform whose vulnerability profile centers on its core CDN and serverless compute offerings, with exposure concentrating in information disclosure, cross-site scripting, and cryptographic seed-management issues. These weaknesses reflect the edge-facing and request-handling nature of the platform, where input validation and sensitive-data handling are critical to security posture. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fastly over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39218HIGH The JS Compute Runtime for Fastly's Compute@Edge platform provides the environment JavaScript is executed in when using the Compute@Edge JavaScript SDK. In versions prior to 0.5.3, | Sep 20, 2022 | 7.5 | 24 | NO | NO |
CVE-2015-10094MEDIUM A vulnerability was found in Fastly Plugin up to 0.97 on WordPress. It has been rated as problematic. Affected by this issue is the function post of the file lib/api.php. The manip | Mar 6, 2023 | 6.1 | 21 | NO | NO |
CVE-2017-13761MEDIUM The Fastly CDN module before 1.2.26 for Magento2, when used with a third-party authentication plugin, might allow remote authenticated users to obtain sensitive information from au | Sep 14, 2017 | 6.5 | 21 | NO | NO |
CVE-2025-58199MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Fastly Fastly fastly allows Cross Site Request Forgery.This issue affects Fastly: from n/a through <= 1.2.28. | Sep 22, 2025 | 4.3 | 17 | NO | NO |
CVE-2024-34768MEDIUM Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25. | Jun 11, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-34803MEDIUM Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25. | Jun 3, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fastly.
Media articles that mention a CVE ID that affects a product developed by Fastly — matched by CVE ID, not by vendor name.