5.9
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Description
Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive information via interception of requests intended to be sent over HTTPS.
To remediate this issue, users should upgrade to Graph Explorer v3.0.1 or later.
To remediate this issue, users should upgrade to Graph Explorer v3.0.1 or later.
Basic Information
ID
CVE-2026-10584
Source
AMZN
Published
Jun 2, 2026 at 19:08
Affected Product
Vendor
AWS
Product
Graph Explorer
Version
1.1.0
Affected Versions
AWS Graph Explorer 1.1.0