CircleCI-Public / CircleCI-Public/cimg-ruby

Bug Report: Critical Vulnerability CVE-2026-59873

Open
#238 1 comment 0 reactions 0 assignees View on GitHub
bug
Dominant language
Dockerfile
Stars
37
Forks
42
PR merge metrics
No merged PRs in 30d

Description

*Note: We also welcome PRs to fix bugs! This helps us take action faster where a bug has been identified!*

For our official CircleCI Docker Convenience Image support policy, please see [CircleCI docs](https://circleci.com/docs/convenience-images-support-policy).

This policy outlines the release, update, and deprecation policy for CircleCI Docker Convenience Images.

---

**Describe the bug**
The 3.4-browsers image has a critical vulnerability.

**To Reproduce**
Scan the image.

**Expected behavior**
The image should not have a critical vulnerability.

**Workarounds**
Build our own image.

**Screenshots and Build Links**
If possible, add screenshots and links to jobs to help explain your problem.

**Additional context**
Add any other context about the problem here.

Contributor guide

Open the contributing guide

Research direction

Start by scanning the 3.4-browsers image and reviewing the details of CVE-2026-59873; the issue does not name a file or test to inspect. Done means the image no longer reports a critical vulnerability in a confirming scan and the affected image support remains intact.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker
Domain
infrastructure, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.