CLEANSTART-2026-AJ39907
Dashboard / Vulnerabilities / CLEANSTART-2026-AJ39907
CLEANSTART-2026-AJ39907
Summary: gRPC-Go is the Go language implementation of gRPC
Details: Multiple security vulnerabilities affect the step package. gRPC-Go is the Go language implementation of gRPC. See references for individual vulnerability details.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-AJ39907.json, https://osv.dev/vulnerability/CVE-2025-47912, https://osv.dev/vulnerability/CVE-2025-58183, https://osv.dev/vulnerability/CVE-2025-58185, https://osv.dev/vulnerability/CVE-2025-58186, https://osv.dev/vulnerability/CVE-2025-58187, https://osv.dev/vulnerability/CVE-2025-58188, https://osv.dev/vulnerability/CVE-2025-58189, https://osv.dev/vulnerability/CVE-2025-61723, https://osv.dev/vulnerability/CVE-2025-61724, https://osv.dev/vulnerability/CVE-2025-61725, https://osv.dev/vulnerability/CVE-2025-61729, https://osv.dev/vulnerability/CVE-2025-62820, https://osv.dev/vulnerability/CVE-2025-69725, https://osv.dev/vulnerability/CVE-2026-25793, https://osv.dev/vulnerability/CVE-2026-26958, https://osv.dev/vulnerability/CVE-2026-29181, https://osv.dev/vulnerability/CVE-2026-30836, https://osv.dev/vulnerability/CVE-2026-33815, https://osv.dev/vulnerability/CVE-2026-33816, https://osv.dev/vulnerability/CVE-2026-33818, https://osv.dev/vulnerability/CVE-2026-34986, https://osv.dev/vulnerability/CVE-2026-39821, https://osv.dev/vulnerability/CVE-2026-39822, https://osv.dev/vulnerability/CVE-2026-40097, https://osv.dev/vulnerability/CVE-2026-41178, https://osv.dev/vulnerability/CVE-2026-41889, https://osv.dev/vulnerability/CVE-2026-42505, https://osv.dev/vulnerability/CVE-2026-46600, https://osv.dev/vulnerability/CVE-2026-56853, https://osv.dev/vulnerability/CVE-2026-56855, https://osv.dev/vulnerability/CVE-2026-56858, https://osv.dev/vulnerability/CVE-2026-56859, https://osv.dev/vulnerability/CVE-2026-56860, https://osv.dev/vulnerability/CVE-2026-56862, https://osv.dev/vulnerability/CVE-2026-78662, https://osv.dev/vulnerability/CVE-2026-84304, https://osv.dev/vulnerability/ghsa-259r-337f-4rfw, https://osv.dev/vulnerability/ghsa-3fxj-6jh8-hvhx, https://osv.dev/vulnerability/ghsa-9g5q-2w5x-hmxf, https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf, https://osv.dev/vulnerability/ghsa-mpwr-8vm7-h73f, https://osv.dev/vulnerability/ghsa-rjr7-jggh-pgcp, https://nvd.nist.gov/vuln/detail/CVE-2025-47912, https://nvd.nist.gov/vuln/detail/CVE-2025-58183, https://nvd.nist.gov/vuln/detail/CVE-2025-58185, https://nvd.nist.gov/vuln/detail/CVE-2025-58186, https://nvd.nist.gov/vuln/detail/CVE-2025-58187, https://nvd.nist.gov/vuln/detail/CVE-2025-58188, https://nvd.nist.gov/vuln/detail/CVE-2025-58189, https://nvd.nist.gov/vuln/detail/CVE-2025-61723, https://nvd.nist.gov/vuln/detail/CVE-2025-61724, https://nvd.nist.gov/vuln/detail/CVE-2025-61725, https://nvd.nist.gov/vuln/detail/CVE-2025-61729, https://nvd.nist.gov/vuln/detail/CVE-2025-62820, https://nvd.nist.gov/vuln/detail/CVE-2025-69725, https://nvd.nist.gov/vuln/detail/CVE-2026-25793, https://nvd.nist.gov/vuln/detail/CVE-2026-26958, https://nvd.nist.gov/vuln/detail/CVE-2026-29181, https://nvd.nist.gov/vuln/detail/CVE-2026-30836, https://nvd.nist.gov/vuln/detail/CVE-2026-33815, https://nvd.nist.gov/vuln/detail/CVE-2026-33816, https://nvd.nist.gov/vuln/detail/CVE-2026-33818, https://nvd.nist.gov/vuln/detail/CVE-2026-34986, https://nvd.nist.gov/vuln/detail/CVE-2026-39821, https://nvd.nist.gov/vuln/detail/CVE-2026-39822, https://nvd.nist.gov/vuln/detail/CVE-2026-40097, https://nvd.nist.gov/vuln/detail/CVE-2026-41178, https://nvd.nist.gov/vuln/detail/CVE-2026-41889, https://nvd.nist.gov/vuln/detail/CVE-2026-42505, https://nvd.nist.gov/vuln/detail/CVE-2026-46600, https://nvd.nist.gov/vuln/detail/CVE-2026-56853, https://nvd.nist.gov/vuln/detail/CVE-2026-56855, https://nvd.nist.gov/vuln/detail/CVE-2026-56858, https://nvd.nist.gov/vuln/detail/CVE-2026-56859, https://nvd.nist.gov/vuln/detail/CVE-2026-56860, https://nvd.nist.gov/vuln/detail/CVE-2026-56862, https://nvd.nist.gov/vuln/detail/CVE-2026-78662, https://nvd.nist.gov/vuln/detail/CVE-2026-84304
Affected packages
Package
Name: step
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
