<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Graph-Explorer on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/graph-explorer/</link><description>Recent content in Graph-Explorer on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Tue, 02 Jun 2026 19:17:39 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/graph-explorer/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-10584: AWS Graph Explorer HTTPS Fallback Flaw</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-10584-aws-graph-explorer-https-fallback-cleartext/</link><pubDate>Tue, 02 Jun 2026 19:17:39 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-10584-aws-graph-explorer-https-fallback-cleartext/</guid><description>CVE-2026-10584 causes Graph Explorer (v1.1.0–3.0.1) to silently fall back to HTTP, exposing Amazon Neptune data in cleartext. Upgrade to v3.0.1 now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/security/security-bulletins/rss/2026-038-aws/">AWS Security Bulletins</a></p>
<hr>
<p>A vulnerability in Graph Explorer (versions 1.1.0 to 3.0.1), an open-source tool used with Amazon Neptune, can cause the application to silently fall back from HTTPS to unencrypted HTTP when TLS certificates are unavailable. This means sensitive data, potentially including graph database queries and results, may be transmitted in cleartext without any visible warning. The issue is tracked as CVE-2026-10584 and requires an explicit upgrade to version 3.0.1 or later.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Audit any Graph Explorer deployments running versions 1.1.0 through 3.0.1 and upgrade to 3.0.1 immediately; additionally, enforce network-level controls (e.g. VPC security groups or WAF rules) to block plain HTTP traffic to Neptune endpoints as a defence-in-depth measure while patching is underway.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/security/security-bulletins/rss/2026-038-aws/">CVE-2026-10584 - HTTPS Fallback to HTTP in Graph Explorer</a></p>
]]></content:encoded></item></channel></rss>