CVE-2026-10584
Awaiting Analysis
Awaiting Analysis - Queue
Information Disclosure in Graph Explorer via HTTP Fallback
Publication date: 2026-06-02
Last updated on: 2026-06-04
Assigner: AMZN
Description
Description
Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive information via interception of requests intended to be sent over HTTPS.
To remediate this issue, users should upgrade to Graph Explorer v3.0.1 or later.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| aws | graph_explorer | From 1.1.0 (inc) to 3.0.1 (exc) |
| aws | graph_explorer | 3.0.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-319 | The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. |