{"id":"CGA-hhq6-grpf-4gq9","modified":"2026-01-12T00:30:51.348692Z","published":"2025-03-31T16:08:02.411581Z","withdrawn":"2026-01-12T00:30:51.348692Z","related":["CGA-hhq6-grpf-4gq9","CVE-2025-22870","GHSA-qxp5-gwg8-xv66"],"affected":[{"package":{"name":"step-kms-plugin","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/step-kms-plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.12.1-r4"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-hhq6-grpf-4gq9.json"}},{"package":{"name":"step-kms-plugin","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/step-kms-plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.12.1-r4"}]}],"database_specific":{"source":"https://packages.cgr.dev/chainguard/osv/CGA-hhq6-grpf-4gq9.json"}}],"schema_version":"1.7.3"}