Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd110b5863c01ec2a9c0b427edccebbe0e6416cbc783f875ced
Public Swagger UI/API detected at path: /api-docs/swagger.json - sample paths: GET /v1/auth/permissions GET /v1/auth/renew-token-session GET /v1/auth/user-data GET /v1/auth/validate POST /v1/auth/login POST /v1/auth/logout POST /v1/auth/permissions/validate POST /v1/auth/recover-password POST /v1/auth/reset-password
Open service 172.217.208.121:443 · admin-geral-api-auth-trace-development.ecotrace.technology
2026-01-09 02:22
HTTP/1.1 404 Not Found
x-powered-by: Express
vary: Origin
access-control-allow-credentials: true
content-type: application/json; charset=utf-8
etag: W/"56-E6UG3s6GTizRA2Jb4HT9rvFc8Fg"
x-cloud-trace-context: 21fdbbf5351f24b5ce49944960df611a
date: Fri, 09 Jan 2026 02:22:23 GMT
server: Google Frontend
Content-Length: 86
Connection: close
{"error":{"timestamp":"2026-01-09T02:22:23.267Z","code":404,"message":"Cannot GET /"}}
Open service 172.217.208.121:443 · admin-geral-api-auth-trace-development.ecotrace.technology
2026-01-02 01:59
HTTP/1.1 404 Not Found
x-powered-by: Express
vary: Origin
access-control-allow-credentials: true
content-type: application/json; charset=utf-8
etag: W/"56-UYkAJZrLlDLvmMupBECz3lB1Ej0"
x-cloud-trace-context: 561e51e7dcabb4cea27d6da73a17bb72
date: Fri, 02 Jan 2026 01:59:56 GMT
server: Google Frontend
Content-Length: 86
Connection: close
{"error":{"timestamp":"2026-01-02T01:59:56.720Z","code":404,"message":"Cannot GET /"}}
Open service 172.217.208.121:443 · admin-geral-api-auth-trace-development.ecotrace.technology
2025-12-30 12:13
HTTP/1.1 404 Not Found
x-powered-by: Express
vary: Origin
access-control-allow-credentials: true
content-type: application/json; charset=utf-8
etag: W/"56-LrVceOrFfk4OAaykHoQQ5EQF6Yg"
x-cloud-trace-context: bb7bf98b17f1993851b1a613c9cb090e
date: Tue, 30 Dec 2025 12:14:00 GMT
server: Google Frontend
Content-Length: 86
Connection: close
{"error":{"timestamp":"2025-12-30T12:14:00.117Z","code":404,"message":"Cannot GET /"}}
Open service 172.217.208.121:443 · admin-geral-api-auth-trace-development.ecotrace.technology
2025-12-22 06:32
HTTP/1.1 404 Not Found
x-powered-by: Express
vary: Origin
access-control-allow-credentials: true
content-type: application/json; charset=utf-8
etag: W/"56-gnibVdbwUYd7UXmBsh/Qn20qPT8"
x-cloud-trace-context: 73748755df241c09d989166c71e904d6
date: Mon, 22 Dec 2025 06:32:11 GMT
server: Google Frontend
Content-Length: 86
Connection: close
{"error":{"timestamp":"2025-12-22T06:32:11.420Z","code":404,"message":"Cannot GET /"}}
Open service 172.217.208.121:443 · admin-geral-api-auth-trace-development.ecotrace.technology
2025-12-20 18:28
HTTP/1.1 404 Not Found
x-powered-by: Express
vary: Origin
access-control-allow-credentials: true
content-type: application/json; charset=utf-8
etag: W/"56-x9LDKCleNelQ0fkb3NCnVS2cg9k"
x-cloud-trace-context: d7c1a59ff553475fa6d791900d1ee576
date: Sat, 20 Dec 2025 18:28:33 GMT
server: Google Frontend
Content-Length: 86
Connection: close
{"error":{"timestamp":"2025-12-20T18:28:33.894Z","code":404,"message":"Cannot GET /"}}
Open service 172.217.208.121:443 · admin-geral-api-auth-trace-development.ecotrace.technology
2025-12-19 02:26
HTTP/1.1 404 Not Found
x-powered-by: Express
vary: Origin
access-control-allow-credentials: true
content-type: application/json; charset=utf-8
etag: W/"56-velVaIHy9+CED+fzSIl154aunmQ"
x-cloud-trace-context: 1facd61979d04e7c2bbb5a2fbc948e12
date: Fri, 19 Dec 2025 02:26:23 GMT
server: Google Frontend
Content-Length: 86
Connection: close
{"error":{"timestamp":"2025-12-19T02:26:23.433Z","code":404,"message":"Cannot GET /"}}