bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Thursday, August 20, 2026

Graph Explorer HTTPS Fallback Vulnerability Requires Immediate Update

Graph Explorer versions 1.1.0 through 3.0.0 have a nasty security flaw (CVE-2026-10584) where the server silently downgrades from HTTPS to HTTP when certificates are missing, exposing sensitive data in cleartext. If you're running an affected version with Amazon Neptune, you need to upgrade to 3.0.1 or later right away. This is a critical issue that demands your attention.

source: [aws/security-bulletin]