KV Store

09 September 2026, 18:28 UTC
Compute Fanout Fastly Compute AI Accelerator Edge Cloud Services Websockets Config Store KV Store Secret Store
 
09 September 2026, 18:28 UTC

We are investigating an issue causing elevated 5xx errors for some customers using our Compute services.

Our engineers are actively working to diagnose the contributing factor.  We will provide another update as more information becomes available or within the next hour.


All other products and services are unaffected by this incident.

 
09 September 2026, 19:20 UTC

Our engineers believe they have identified the contributing factor causing the issue impacting our Compute services.

Our engineers are now developing a fix, and we will post a new update once it has been fully implemented and we see signs of recovery.

All other products and services remain unaffected by this incident.

 
09 September 2026, 20:33 UTC

Engineering has deployed a fix and have confirmed a gradual recovery to Compute services. We will continue to monitor until we’ve confirmed that customer experience has been fully restored.

All other products and services remain unaffected by this incident.



 
09 September 2026, 22:05 UTC

Engineering has confirmed that Compute services has been fully restored. Customers may have experienced elevated 5xx errors from 18:28 to 21:52 UTC.

This incident is resolved.



Note:  Our Customer Escalation Management team will update the start date and time of the initial "investigating" status post upon the resolution of this incident. This update is meant to provide our customers and their end users with a potential impact window. The date and time mentioned in the message above indicates when the status post was requested by our Acute Incident Response team.

Status Post, Created Date/Time:   2026-09-09 19:15:48 UTC  

07 September 2026, 18:50 UTC
Compute Security Fanout Fastly Compute AI Accelerator Edge Cloud Services Next-Gen WAF (NGWAF) Websockets Config Store KV Store Secret Store
 
07 September 2026, 18:50 UTC

We are investigating an issue causing elevated 431 errors on requests for our customers.

We will provide another update as more information becomes available or within the next hour.

 
11 September 2026, 15:34 UTC

Our engineers have identified the contributing factor causing the issue impacting our CDN service.

Our engineers are now deploying a fix, and we will post a new update once it has been fully implemented and we see signs of recovery.

All other products and services remain unaffected by this incident.

 
11 September 2026, 15:35 UTC

A fix is being deployed for the issue impacting our CDN service.

We are observing a gradual restoration of services, though some customers may continue to experience intermittent issues as the system stabilizes.

Our team is actively monitoring the recovery and will post another update once services are fully restored.



 
11 September 2026, 16:19 UTC

A fix has been deployed for the issue impacting our Next-Gen WAF services running on Compute.

We are observing a gradual restoration of services, though some customers may continue to experience intermittent issues as the system stabilizes.

To clarify an earlier update: this issue affected Next-Gen WAF on Compute, not our CDN service, which was not impacted.

Our team is actively monitoring the recovery and will post another update once services are fully restored.

 
11 September 2026, 22:06 UTC

Engineering has confirmed that our Compute services and NGWAF services that run on Compute have been fully restored. Customers may have experienced elevated 431 errors from September 7, at 18:50 UTC to September 11, at 20:00 UTC.

This incident is resolved.



Note:   Our Customer Escalation Management team will update the start date and time of the initial "investigating" status post upon the resolution of this incident. This update is meant to provide our customers and their end users with a potential impact window. The date and time mentioned in the message above indicates when the status post was requested by our Acute Incident Response team.

Status Post, Created Date/Time:    2026-09-11 15:22:36 UTC    

Network Services Compute Fastly Compute Object Storage KV Store
 
24 April 2026, 21:42 UTC

This incident post has been superseded, please refer to the updated post here: https://www.fastlystatus.com/incident/378503

Network Services Compute Fastly Compute Object Storage KV Store
 
24 April 2026, 21:42 UTC

We are investigating elevated errors to our KV Store, Object Storage service  for Asia Pacific (APAC) and South Asia regions.

All other products and services are unaffected by this incident.

 
25 April 2026, 14:05 UTC

Our engineers believe they have identified contributing factor causing the issue impacting the  KV Store, Object Storage for Asia Pacific (APAC) and South Asia regions.

We are now developing a fix, and will post a new update once it has been fully implemented and we see signs of recovery.

All other products and services are unaffected by this incident.

 
25 April 2026, 14:35 UTC

Engineering has confirmed the impact to KV Store, Object Storage service for Asia Pacific (APAC) and South Asia regions has been mitigated.

 
25 April 2026, 16:21 UTC

Engineering has confirmed that KV Store, Object Storage service for Asia Pacific (APAC) and South Asia regions has been fully restored. Customers may have experienced  increased latency observed when accessing  KV Store and Object Storage  from 14:42 UTC on April 24, 2026  to  14:49 UTC on April 25, 2026 .

This incident is resolved.




Note:   Our Customer Escalation Management team will update the start date and time of the initial "investigating" status post upon the resolution of this incident. This update is meant to provide our customers and their end users with a potential impact window. The date and time mentioned in the message above indicates when the status post was requested by our Acute Incident Response team.

Status Post, Created Date/Time:    2026-04-25 16:19:58 UTC    

03 February 2026, 19:00 UTC
Compute Fastly Compute Config Store KV Store Secret Store
 
03 February 2026, 19:00 UTC

We are investigating elevated errors to our Fastly Compute service when creating new services using the default domain, edgecompute.app.  Existing Compute services remain unaffected by this incident. 


All other products and services are unaffected by this incident.

 
03 February 2026, 23:23 UTC

Our engineers believe they have identified contributing factor causing the issue impacting the Fastly Compute status page component.

We are now developing a fix, and will post a new update once it has been fully implemented and we see signs of recovery.

All other products and services are unaffected by this incident.

 
03 February 2026, 23:24 UTC

Engineering has confirmed the impact to our Fastly Compute service has been mitigated.

 
04 February 2026, 00:01 UTC

Engineering has confirmed that our Fastly Compute service has been fully restored. Customers may have experienced elevated errors when new Compute service deployments were attempted with the default domain, 'edgecompute.app' from 19:00 to 23:20 UTC.

This incident is resolved.


Note:  Our Customer Escalation Management team will update the start date and time of the initial "investigating" status post upon the resolution of this incident. This update is meant to provide our customers and their end users with a potential impact window. The date and time mentioned in the message above indicates when the status post was requested by our Acute Incident Response team.

Status Post, Created Date/Time:   2026-02-03 23:17:05 UTC  

Fastly Compute Security Fastly Compute Customer Services Next-Gen WAF (NGWAF) Config Store KV Store General Updates Secret Store
 
03 December 2025, 16:21 UTC

The Fastly Security Team, in coordination with Vercel, AWS, Next.js, and Meta, are issuing this urgent security advisory regarding a newly discovered, critical vulnerability in the React framework. The Next.js CVE-2025-66478 and React CVE-2025-55182 were published today, the 3rd of December 2025 at 15:54 UTC.

What Happened

On the 1st of December 2025, Vercel notified Fastly of a critical-severity unauthenticated Remote Code Execution (RCE) vulnerability that was responsibly disclosed to Meta, affecting React’s “Server Function" protocol. 

The vulnerability impacts applications utilizing React Server Components (RSC) functionality via the following common frameworks/plugins:

  • Next.js versions 15 and 16 (when using App Router)
  • React Router RSC preview
  • Parcel RSC plugin
  • Vite RSC plugin

As of this notification, Fastly does not have knowledge or evidence of this vulnerability being exploited in the wild.

However, some customers running workloads using Fastly Compute, specifically those using the affected React versions and RSC implementations listed above, may be at risk. We encourage all Compute customers to refer to the identification and mitigation steps described in the next section.

What You Can Do 

Next-Gen WAF (NGWAF)

To mitigate risk for your applications protected by NGWAF, we recommend that you immediately apply the Virtual Patch for CVE-2025-66478 (which also addresses CVE-2025-55182) to all Edge and On-prem services that may be vulnerable. The detection content within this CVE-specific Templated Rule looks for specific patterns within request headers and POST bodies that may indicate potential exploitation attempts of this CVE. Fastly’s Security Research team developed and tested this content in close collaboration with Vercel and AWS. 

Compute

To mitigate risk for Compute Services, we recommend that you take the following steps: 

Inventory and Identification: Identify all applications within your environment that are using the affected React versions (19.0, 19.1, and 19.2) in conjunction with any of the listed RSC implementations: 

  • Next.js 15, 15.1, 15.2, 15.3, 15.4, 15.5, 16 
  • App Router
  • React Router RSC preview
  • Parcel RSC plugin
  • Vite RSC plugin. 

One method for identification is to perform a targeted search across your codebase for the relevant package dependencies in the package.json file.  Efficient methods include: 

  • GitHub/Code Search: Use tools like GitHub's code search functionality.
  • Command-Line Tools: Use grep or similar tools for local/private repositories.

Patching and Deployment: The affected React versions are 19.0, 19.1, and 19.2. Immediately deploy the official, stable patched versions released today, the 3rd of December 2025. The React 19 patch will be published for 19.2. The affected Next.js versions are 15 through 16, and patches will be published for versions 15, 15.1, 15.2, 15.3, 15.4, 15.5, and 16.

What We Did Immediately

Fastly initiated an internal investigation for our core platform infrastructure and has found no indication that we are directly vulnerable as of the date of this advisory. This includes our Compute platform itself; as described earlier, due to Compute’s sandboxed architecture, any apps that are not vulnerable to this bug will be protected even if neighboring apps are malicious or compromised. 

In close partnership with Vercel, AWS, and Meta, our security research team began developing NGWAF content ahead of disclosure to provide protection for our customers as soon as the patch is applied. Fastly is currently investigating additional ways we can detect and block attack traffic as a result of this announced vulnerability. We will continue to develop and refine relevant NGWAF content as we observe exploitation attempts. 

Customers with any questions or concerns may engage with our Support team through https://support.fastly.com or by contacting your designated account management team members.

 
05 December 2025, 22:56 UTC

Following further investigation and evaluation of the React2Shell vulnerability, and in response to widespread exploitation attempts, Fastly is implementing a default block for requests matching the attack signatures within NGWAF.

This action provides our NGWAF customers with enhanced defence against this emerging and urgent threat. No action is required on your part to benefit from this added protection.

We continue to encourage all customers to update any affected applications as soon as possible.

Customers with any questions or concerns may engage with our Support team through https://support.fastly.com or by contacting your designated account management team members.

 
12 December 2025, 00:06 UTC

On the 11th of December 2025 CVE-2025-55184 and CVE-2025-55183 were published; unlike React2Shell, these vulnerabilities do not allow for Remote Code Execution.

CVE-2025-55184 facilitates a Denial of Service in which an attacker can force a vulnerable application server into an infinite loop by crafting a specific request.

CVE-2025-55183 facilitates a leak of React Server Function source code. This CVE is likely not a high impact for you unless you are using React Server Components and have sensitive or proprietary information contained in React Server Function source code.

What We Did Immediately

After receiving initial information from Vercel and Meta about CVE-2025-55184 and CVE-2025-55183, Fastly developed and deployed a Virtual Patch for each CVE in blocking mode by default for all Fastly NGWAF customers out of an abundance of caution. If you wish to disable this virtual patch, please refer to our documentation.

We continue to encourage all customers to update any affected applications as soon as possible.

Customers with any questions or concerns may engage with our Support team through https://support.fastly.com or by contacting your designated account management team members.


 
12 December 2025, 19:50 UTC

CVE-2025-67779: Complete DoS Fix

The fix addressing CVE-2025-55184 in React Server Components was incomplete and did not fully prevent DoS attacks in all payload types. CVE-2025-67779 addresses those additional payload types.

The Fastly NGWAF already covers this addendum CVE with our existing detection of CVE-2025-55184. We recommend upgrading any React and Next.js apps to patch this issue as well. 

We continue to encourage all customers to update any affected applications as soon as possible.

Customers with any questions or concerns may engage with our Support team through https://support.fastly.com or by contacting your designated account management team members.


Platform Compute North America Fastly Compute Config Store Ashburn (IAD) KV Store Secret Store Chicago (CHI)
 
13 November 2025, 23:49 UTC

Fastly Engineers detected a performance impacting event affecting the Fastly Compute Services within our Ashburn (IAD) and Chicago (CHI) Points of Presence (POPs).

All other POPs and services were unaffected. The issue has been resolved and we are monitoring performance closely.

 
14 November 2025, 01:12 UTC

Engineering has confirmed that this incident has been fully restored. Customers may have experienced increased latency and errors affecting Fastly Compute Services from Thursday at 23:49 UTC to Friday at 01:12 UTC.

This incident is resolved.

Affected customers may have experienced impact to varying degrees and to a shorter duration than as set forth above.

To offer feedback on our status page, click "Give Feedback" 

Status Post, Created Date/Time: 2025-11-14 01:51:47 UTC 



Note: Our Customer Escalation Management team will update the start date and time of the initial "investigating" status post upon the resolution of this incident. This update is meant to provide our customers and their end users with a potential impact window. The date and time mentioned in the message above indicates when the status post was requested by our Acute Incident Response team.


03 November 2025, 16:13 UTC
Compute Fanout Fastly Compute AI Accelerator Edge Cloud Services Websockets Config Store KV Store Secret Store
 
03 November 2025, 16:13 UTC

We are investigating elevated errors to our Compute services impacting new Compute activation deployments. Currently active Compute deployments remain unaffected by this incident.


All other products and services are unaffected by this incident.

 
03 November 2025, 18:59 UTC

Our engineers are continuing to investigate activations on our Compute services. We have not yet identified the root cause but are actively working on diagnostics. We will provide another update as soon as we have more information.

 
03 November 2025, 19:53 UTC

Our engineers believe they have identified a contributing factor causing the issue impacting the Compute status page component.

We are now developing a fix, and will post a new update once it has been fully implemented and we see signs of recovery.

All other products and services are unaffected by this incident.

 
03 November 2025, 20:00 UTC

The fix has been successfully deployed, and we have observed a recovery of Compute activations. Error rates and latency have returned to nominal levels.

Our team will continue to monitor the platform to ensure stability before we resolve this incident.

We will provide a final update once the incident is fully resolved.

 
03 November 2025, 20:04 UTC

Our engineers have identified an additional contributing factor and are developing an adjusted mitigation strategy to our Compute services. 

All other locations and services are unaffected.

 
03 November 2025, 22:32 UTC

A new fix has been successfully deployed, and we have observed a recovery of Compute activations. 

Our team will continue to monitor the platform to ensure stability before we resolve this incident.

We will provide a final update once the incident is fully resolved.

 
03 November 2025, 22:44 UTC

Engineering has confirmed that activations for our Compute services has been fully restored. Customers may have experienced elevated errors when deploying new activations from 16:13 to 22:06 UTC.

Existing services already deployed were unaffected by this incident.

This incident is resolved. All services are now operating normally.

To offer feedback on our status page, click "Give Feedback" 

Status Post, Created Date/Time: 2025-11-03 17:57:17 UTC 



Note: Our Customer Escalation Management team will update the start date and time of the initial "investigating" status post upon the resolution of this incident. This update is meant to provide our customers and their end users with a potential impact window. The date and time mentioned in the message above indicates when the status post was requested by our Acute Incident Response team.


Fastly Compute Fanout Fastly Compute Customer Services AI Accelerator Edge Cloud Services Websockets Config Store KV Store General Updates Secret Store
 
31 October 2025, 00:29 UTC

We are issuing an urgent advisory regarding an incompatibility between Compute services and the newly released Rust version 1.91.

Action Required 

We strongly recommend that you DO NOT upgrade to Rust version 1.91 at this time.

What Happened

We first identified this incompatibility in our testing environment on the 30th of October 2025, and have since confirmed the same Compute crash behavior in our production environment.

  • Incompatible Version: Rust 1.91

  • Compatible Version: Rust 1.90 and below (Previous Stable Versions)

  • Impact: Using Rust 1.91 with Compute may lead to crash behavior, which will impact your traffic on Fastly.

What’s next? What do I have to do?

If you have already upgraded your services to Rust version 1.91, you must immediately downgrade to the previous stable and compatible version, Rust version 1.90, to prevent or resolve any impact to your traffic.

We are actively working on a fix to ensure compatibility with Rust version 1.91 and will provide an update as soon as a fix is available. Thank you for your patience and understanding.

Customers with any questions or concerns may engage with our Support team through https://support.fastly.com or by contacting your designated account management team members.

17 September 2025, 07:20 UTC
Network Services Compute Fastly Compute Object Storage KV Store
 
17 September 2025, 07:20 UTC

We're investigating possible performance impact affecting the KV Store service.

 
17 September 2025, 08:41 UTC

Engineering has confirmed that KV Store and Object Storage services has recovered. Customers may have experienced elevated errors for these Edge storage services from 07:20 to 08:12 UTC on the 17th September 2025.

This incident is resolved.

Affected customers may have experienced impact to varying degrees and to a shorter duration than as set forth above.

To offer feedback on our status page, click "Give Feedback" 

Status Post, Created Date/Time: 2025-09-17 08:13:28 UTC 



Note: Our Customer Escalation Management team will update the start date and time of the initial "investigating" status post upon the resolution of this incident. This update is meant to provide our customers and their end users with a potential impact window. The date and time mentioned in the message above indicates when the status post was requested by our Acute Incident Response team.