CVE 5.9 MEDIUM

HTTPS Fallback to HTTP in Graph Explorer_CVE-2026-10584

5.9 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive information via interception of requests intended to be sent over HTTPS.



To remediate this issue, users should upgrade to Graph Explorer v3.0.1 or later.

Basic Information

ID CVE-2026-10584
Source AMZN
Published Jun 2, 2026 at 19:08

Affected Product

Vendor AWS
Product Graph Explorer
Version 1.1.0
Affected Versions AWS Graph Explorer 1.1.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.