{"id":"CGA-hhq6-grpf-4gq9","modified":"2026-01-28T03:28:21.334599Z","published":"2025-03-31T16:05:00.556675Z","withdrawn":"2026-01-28T03:28:21.334599Z","related":["CGA-hhq6-grpf-4gq9","CVE-2025-22870","GHSA-qxp5-gwg8-xv66"],"affected":[{"package":{"name":"step-kms-plugin","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/step-kms-plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.12.1-r4"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-hhq6-grpf-4gq9.json"}},{"package":{"name":"step-kms-plugin","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/step-kms-plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.12.1-r4"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-hhq6-grpf-4gq9.json"}}],"schema_version":"1.7.3"}