Improperly Controlled Modification of Dynamically-Determined Object Attributes The advisory has been revoked - it doesn't affect any version of package sgx-pckid-tool  (opens in a new tab)


Threat Intelligence

EPSS
0.3% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS9-SGXPCKIDTOOL-15598148
  • published15 Mar 2026
  • disclosed26 Feb 2026

Introduced: 26 Feb 2026

CVE-2026-27837  (opens in a new tab)
CWE-915  (opens in a new tab)

Amendment

The Centos security team deemed this advisory irrelevant for Centos:9.

NVD Description

Note: Versions mentioned in the description apply only to the upstream sgx-pckid-tool package and not the sgx-pckid-tool package as distributed by Centos.

Dottie provides nested object access and manipulation in JavaScript. Versions 2.0.4 through 2.0.6 contain an incomplete fix for CVE-2023-26132. The prototype pollution guard introduced in commit 7d3aee1 only validates the first segment of a dot-separated path, allowing an attacker to bypass the protection by placing __proto__ at any position other than the first. Both dottie.set() and dottie.transform() are affected. Version 2.0.7 contains an updated fix to address the residual vulnerability.