HTTPS Fallback to HTTP in Graph Explorer
Medium5.9CVE-2026-10584 · Published Sep 22, 2026
Bulletin ID: 2026-038-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/02/2026 12:15 PM PDT Description: Graph Explorer is an open source application that provides visualization and exploration of data in graph databases such as Amazon Neptune. We identified CVE-2026-10584 where, under certain circumstances, the server silently falls back to HTTP when HTTPS is enabled but certificates are unavailable, resulting in cleartext transmission of sensitive information. Impacted versions: >= 1.1.0 AND Resolution: This issue has been addressed in Graph Explorer version 3.0.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If you cannot upgrade immediately, please take the following actions: Verify your deployment is actually serving over HTTPS by checking the protocol in the browser or via curl Ensure HOST is set in your docker run command so certificates are generated correctly Avoid using non-default configuration directory paths when relying on automatic self-signed certificate generation References: CVE-2026-10584 GHSA-r6vr-4r...
Affected versions
Changes since it was listed
| Date | Change |
|---|---|
| Sep 26 | Severity: Unrated to Medium |
Details and references
Bulletin ID: 2026-038-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/02/2026 12:15 PM PDT Description: Graph Explorer is an open source application that provides visualization and exploration of data in graph databases such as Amazon Neptune. We identified CVE-2026-10584 where, under certain circumstances, the server silently falls back to HTTP when HTTPS is enabled but certificates are unavailable, resulting in cleartext transmission of sensitive information. Impacted versions: >= 1.1.0 AND Resolution: This issue has been addressed in Graph Explorer version 3.0.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If you cannot upgrade immediately, please take the following actions: Verify your deployment is actually serving over HTTPS by checking the protocol in the browser or via curl Ensure HOST is set in your docker run command so certificates are generated correctly Avoid using non-default configuration directory paths when relying on automatic self-signed certificate generation References: CVE-2026-10584 GHSA-r6vr-4rxc-x6q4 Acknowledgement: We would like to thank Eduardo Caro for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-038-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-10584 - HTTPS Fallback to HTTP in Graph Explorer Bulletin ID: 2026-038-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/02/2026 12:15 PM PDT Description: Graph Explorer is an open source application that provides visualization and exploration of data in graph databases such as Amazon Neptune. We identified CVE-2026-10584 where, under certain circumstances, the server silently falls back to HTTP when HTTPS is enabled but certificates are unavailable, resulting in cleartext transmission of sensitive information. Impacted versions: >= 1.1.0 AND Resolution: This issue has been addressed in Graph Explorer version 3.0.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If you cannot upgrade immediately, please take the following actions: Verify your deployment is actually serving over HTTPS by checking the protocol in the browser or via curl Ensure HOST is set in your docker run command so certificates are generated correctly Avoid using non-default configuration directory paths when relying on automatic self-signed certificate generation References: CVE-2026-10584 GHSA-r6vr-4rxc-x6q4 Acknowledgement: We would like to thank Eduardo Caro for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.ama
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- NVD
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 22 | Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths | High8.8 | No fix yet |
| Sep 22 | Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible... | High8.0 | No fix yet |
| Sep 22 | Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import | Critical9.0 | No fix yet |
| Sep 22 | Issue with HTTP/2 multi-frame request body inspection in AWS WAF | Critical9.8 | No fix yet |
| Sep 22 | Authenticated SQL injection in the metrics-service retention policy subsystem of... | High8.1 | No fix yet |
| Sep 22 | Excessive memory allocation in s2n-quic | Medium5.3 | No fix yet |