{"id":"CGA-4h5v-fq73-rrmq","modified":"2026-01-12T00:20:43.857324Z","published":"2025-04-10T14:20:37.839021Z","withdrawn":"2026-01-12T00:20:43.857324Z","related":["CGA-4h5v-fq73-rrmq","CVE-2025-22871","GHSA-g9pc-8g42-g6vq"],"affected":[{"package":{"name":"step","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/step"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.28.6-r2"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-4h5v-fq73-rrmq.json"}},{"package":{"name":"step","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/step"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.28.6-r2"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-4h5v-fq73-rrmq.json"}}],"schema_version":"1.7.3"}