CircleCI-Public / CircleCI-Public/cimg-ruby
Bug Report: Critical Vulnerability CVE-2026-59873
- Dominant language
- Dockerfile
- Stars
- 37
- Forks
- 42
- PR merge metrics
- No merged PRs in 30d
Description
*Note: We also welcome PRs to fix bugs! This helps us take action faster where a bug has been identified!*
For our official CircleCI Docker Convenience Image support policy, please see [CircleCI docs](https://circleci.com/docs/convenience-images-support-policy).
This policy outlines the release, update, and deprecation policy for CircleCI Docker Convenience Images.
---
**Describe the bug**
The 3.4-browsers image has a critical vulnerability.
**To Reproduce**
Scan the image.
**Expected behavior**
The image should not have a critical vulnerability.
**Workarounds**
Build our own image.
**Screenshots and Build Links**
If possible, add screenshots and links to jobs to help explain your problem.
**Additional context**
Add any other context about the problem here.
Contributor guide
Research direction
Start by scanning the 3.4-browsers image and reviewing the details of CVE-2026-59873; the issue does not name a file or test to inspect. Done means the image no longer reports a critical vulnerability in a confirming scan and the affected image support remains intact.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker
- Domain
- infrastructure, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 45/100