Skip to content
AWSAWS-2026-038

HTTPS Fallback to HTTP in Graph Explorer

Medium5.9CVE-2026-10584 · Published Sep 22, 2026

Bulletin ID:  2026-038-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/02/2026 12:15 PM PDT Description: Graph Explorer is an open source application that provides visualization and exploration of data in graph databases such as Amazon Neptune. We identified CVE-2026-10584 where, under certain circumstances, the server silently falls back to HTTP when HTTPS is enabled but certificates are unavailable, resulting in cleartext transmission of sensitive information. Impacted versions:  >= 1.1.0 AND Resolution: This issue has been addressed in Graph Explorer version 3.0.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If you cannot upgrade immediately, please take the following actions: Verify your deployment is actually serving over HTTPS by checking the protocol in the browser or via curl Ensure HOST is set in your docker run command so certificates are generated correctly Avoid using non-default configuration directory paths when relying on automatic self-signed certificate generation References: CVE-2026-10584 GHSA-r6vr-4r...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.

Changes since it was listed

DateChange
Sep 26Severity: Unrated to Medium
Details and references

Bulletin ID:  2026-038-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/02/2026 12:15 PM PDT Description: Graph Explorer is an open source application that provides visualization and exploration of data in graph databases such as Amazon Neptune. We identified CVE-2026-10584 where, under certain circumstances, the server silently falls back to HTTP when HTTPS is enabled but certificates are unavailable, resulting in cleartext transmission of sensitive information. Impacted versions:  >= 1.1.0 AND Resolution: This issue has been addressed in Graph Explorer version 3.0.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If you cannot upgrade immediately, please take the following actions: Verify your deployment is actually serving over HTTPS by checking the protocol in the browser or via curl Ensure HOST is set in your docker run command so certificates are generated correctly Avoid using non-default configuration directory paths when relying on automatic self-signed certificate generation References: CVE-2026-10584 GHSA-r6vr-4rxc-x6q4 Acknowledgement: We would like to thank Eduardo Caro for collaborating on this issue through the coordinated vulnerability disclosure process. Please email  aws-security@amazon.com  with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-038-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-10584 - HTTPS Fallback to HTTP in Graph Explorer Bulletin ID:  2026-038-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/02/2026 12:15 PM PDT Description: Graph Explorer is an open source application that provides visualization and exploration of data in graph databases such as Amazon Neptune. We identified CVE-2026-10584 where, under certain circumstances, the server silently falls back to HTTP when HTTPS is enabled but certificates are unavailable, resulting in cleartext transmission of sensitive information. Impacted versions:  >= 1.1.0 AND Resolution: This issue has been addressed in Graph Explorer version 3.0.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If you cannot upgrade immediately, please take the following actions: Verify your deployment is actually serving over HTTPS by checking the protocol in the browser or via curl Ensure HOST is set in your docker run command so certificates are generated correctly Avoid using non-default configuration directory paths when relying on automatic self-signed certificate generation References: CVE-2026-10584 GHSA-r6vr-4rxc-x6q4 Acknowledgement: We would like to thank Eduardo Caro for collaborating on this issue through the coordinated vulnerability disclosure process. Please email  aws-security@amazon.com  with any security questions or concerns.   {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.ama

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
NVD

More AWS advisories

All AWS

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.