Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 2.16.183.18:443 · gapi.admin.kalundborg.dk
2026-01-23 10:41
HTTP/1.1 400 Bad Request
Content-Type: application/json; charset=utf-8
Content-Length: 151
Expires: Fri, 23 Jan 2026 10:41:02 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 23 Jan 2026 10:41:02 GMT
Connection: close
Set-Cookie: GoPublicAffinity=1769164863.288.653054.3870|4782eab11d711089353f64b6dd66f484; Path=/; Secure; HttpOnly
Strict-Transport-Security: max-age=31536000
{"succeeded":false,"errors":{"general":[{"message":"Origin-headeren må ikke være tom","code":"ORIGIN_HEADER_EMPTY"}],"validation":[]},"successes":[]}
Open service 2a02:26f0:480:23::1726:629d:443 · admin.kalundborg.dk
2026-01-09 21:57
HTTP/1.1 307 Temporary Redirect Location: /login?ref=/ Content-Length: 0 Cache-Control: max-age=60 Expires: Fri, 09 Jan 2026 21:58:39 GMT Date: Fri, 09 Jan 2026 21:57:39 GMT Connection: close Set-Cookie: GoPublicAffinity=1767995860.885.565854.746962|0541ce3ecda863307fd2c8b258b18333; Path=/; Secure; HttpOnly Strict-Transport-Security: max-age=31536000
Open service 2.16.204.28:443 · admin.kalundborg.dk
2026-01-09 21:57
HTTP/1.1 307 Temporary Redirect Location: /login?ref=/ Content-Length: 0 Cache-Control: max-age=60 Expires: Fri, 09 Jan 2026 21:58:40 GMT Date: Fri, 09 Jan 2026 21:57:40 GMT Connection: close Set-Cookie: GoPublicAffinity=1767995861.131.566616.941419|0541ce3ecda863307fd2c8b258b18333; Path=/; Secure; HttpOnly Strict-Transport-Security: max-age=31536000
Open service 2a02:26f0:480:23::1726:62a9:80 · admin.kalundborg.dk
2026-01-09 21:57
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://admin.kalundborg.dk/ Cache-Control: max-age=0 Expires: Fri, 09 Jan 2026 21:58:21 GMT Date: Fri, 09 Jan 2026 21:58:21 GMT Connection: close
Open service 2a02:26f0:480:23::1726:629d:80 · admin.kalundborg.dk
2026-01-09 21:57
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://admin.kalundborg.dk/ Cache-Control: max-age=0 Expires: Fri, 09 Jan 2026 21:58:22 GMT Date: Fri, 09 Jan 2026 21:58:22 GMT Connection: close
Open service 2.16.204.28:80 · admin.kalundborg.dk
2026-01-09 21:57
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://admin.kalundborg.dk/ Cache-Control: max-age=0 Expires: Fri, 09 Jan 2026 21:58:21 GMT Date: Fri, 09 Jan 2026 21:58:21 GMT Connection: close
Open service 2.16.204.11:443 · admin.kalundborg.dk
2026-01-09 21:57
HTTP/1.1 307 Temporary Redirect Location: /login?ref=/ Content-Length: 0 Cache-Control: max-age=60 Expires: Fri, 09 Jan 2026 21:58:40 GMT Date: Fri, 09 Jan 2026 21:57:40 GMT Connection: close Set-Cookie: GoPublicAffinity=1767995861.709.566616.112544|0541ce3ecda863307fd2c8b258b18333; Path=/; Secure; HttpOnly Strict-Transport-Security: max-age=31536000
Open service 2.16.204.11:80 · admin.kalundborg.dk
2026-01-09 21:57
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://admin.kalundborg.dk/ Cache-Control: max-age=0 Expires: Fri, 09 Jan 2026 21:58:22 GMT Date: Fri, 09 Jan 2026 21:58:22 GMT Connection: close
Open service 2a02:26f0:480:23::1726:62a9:443 · admin.kalundborg.dk
2026-01-09 21:57
HTTP/1.1 307 Temporary Redirect Location: /login?ref=/ Content-Length: 0 Cache-Control: max-age=60 Expires: Fri, 09 Jan 2026 21:58:40 GMT Date: Fri, 09 Jan 2026 21:57:40 GMT Connection: close Set-Cookie: GoPublicAffinity=1767995861.653.565854.45110|0541ce3ecda863307fd2c8b258b18333; Path=/; Secure; HttpOnly Strict-Transport-Security: max-age=31536000
Open service 2.16.183.18:443 · gapi.admin.kalundborg.dk
2026-01-09 13:49
HTTP/1.1 400 Bad Request
Content-Type: application/json; charset=utf-8
Content-Length: 151
Expires: Fri, 09 Jan 2026 13:49:32 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 09 Jan 2026 13:49:32 GMT
Connection: close
Set-Cookie: GoPublicAffinity=1767966573.276.564620.27558|4782eab11d711089353f64b6dd66f484; Path=/; Secure; HttpOnly
Strict-Transport-Security: max-age=31536000
{"succeeded":false,"errors":{"general":[{"message":"Origin-headeren må ikke være tom","code":"ORIGIN_HEADER_EMPTY"}],"validation":[]},"successes":[]}
Open service 2a02:26f0:7100::210:178:80 · admin.kalundborg.dk
2026-01-01 22:07
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://admin.kalundborg.dk/ Cache-Control: max-age=0 Expires: Thu, 01 Jan 2026 22:07:24 GMT Date: Thu, 01 Jan 2026 22:07:24 GMT Connection: close
Open service 2a02:26f0:7100::210:179:80 · admin.kalundborg.dk
2026-01-01 22:07
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://admin.kalundborg.dk/ Cache-Control: max-age=0 Expires: Thu, 01 Jan 2026 22:07:23 GMT Date: Thu, 01 Jan 2026 22:07:23 GMT Connection: close
Open service 2a02:26f0:7100::210:178:443 · admin.kalundborg.dk
2026-01-01 22:07
HTTP/1.1 307 Temporary Redirect Location: /login?ref=/ Content-Length: 0 Cache-Control: max-age=60 Expires: Thu, 01 Jan 2026 22:08:21 GMT Date: Thu, 01 Jan 2026 22:07:21 GMT Connection: close Set-Cookie: GoPublicAffinity=1767305242.378.540904.571695|0541ce3ecda863307fd2c8b258b18333; Path=/; Secure; HttpOnly Strict-Transport-Security: max-age=31536000
Open service 2a02:26f0:7100::210:179:443 · admin.kalundborg.dk
2026-01-01 22:07
HTTP/1.1 307 Temporary Redirect Location: /login?ref=/ Content-Length: 0 Cache-Control: max-age=60 Expires: Thu, 01 Jan 2026 22:08:21 GMT Date: Thu, 01 Jan 2026 22:07:21 GMT Connection: close Set-Cookie: GoPublicAffinity=1767305242.366.540767.822215|0541ce3ecda863307fd2c8b258b18333; Path=/; Secure; HttpOnly Strict-Transport-Security: max-age=31536000
Open service 2.16.183.18:443 · admin.kalundborg.dk
2026-01-01 22:07
HTTP/1.1 307 Temporary Redirect Location: /login?ref=/ Content-Length: 0 Cache-Control: max-age=60 Expires: Thu, 01 Jan 2026 22:08:20 GMT Date: Thu, 01 Jan 2026 22:07:20 GMT Connection: close Set-Cookie: GoPublicAffinity=1767305241.904.539197.220859|0541ce3ecda863307fd2c8b258b18333; Path=/; Secure; HttpOnly Strict-Transport-Security: max-age=31536000
Open service 2.16.183.7:443 · admin.kalundborg.dk
2026-01-01 22:07
HTTP/1.1 307 Temporary Redirect Location: /login?ref=/ Content-Length: 0 Cache-Control: max-age=60 Expires: Thu, 01 Jan 2026 22:08:21 GMT Date: Thu, 01 Jan 2026 22:07:21 GMT Connection: close Set-Cookie: GoPublicAffinity=1767305242.304.539197.704580|0541ce3ecda863307fd2c8b258b18333; Path=/; Secure; HttpOnly Strict-Transport-Security: max-age=31536000
Open service 2.16.183.7:80 · admin.kalundborg.dk
2026-01-01 22:07
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://admin.kalundborg.dk/ Cache-Control: max-age=0 Expires: Thu, 01 Jan 2026 22:07:23 GMT Date: Thu, 01 Jan 2026 22:07:23 GMT Connection: close
Open service 2.16.183.18:80 · admin.kalundborg.dk
2026-01-01 22:07
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://admin.kalundborg.dk/ Cache-Control: max-age=0 Expires: Thu, 01 Jan 2026 22:07:23 GMT Date: Thu, 01 Jan 2026 22:07:23 GMT Connection: close
Open service 2.16.183.7:80 · gapi.admin.kalundborg.dk
2026-01-01 22:04
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://gapi.admin.kalundborg.dk/ Cache-Control: max-age=0 Expires: Thu, 01 Jan 2026 22:04:30 GMT Date: Thu, 01 Jan 2026 22:04:30 GMT Connection: close
Open service 2.16.183.18:80 · gapi.admin.kalundborg.dk
2026-01-01 22:04
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://gapi.admin.kalundborg.dk/ Cache-Control: max-age=0 Expires: Thu, 01 Jan 2026 22:04:30 GMT Date: Thu, 01 Jan 2026 22:04:30 GMT Connection: close
Open service 2a02:26f0:7100::210:178:443 · gapi.admin.kalundborg.dk
2026-01-01 22:04
HTTP/1.1 400 Bad Request
Content-Type: application/json; charset=utf-8
Content-Length: 151
Expires: Thu, 01 Jan 2026 22:04:27 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 01 Jan 2026 22:04:27 GMT
Connection: close
Set-Cookie: GoPublicAffinity=1767305068.174.541027.399268|4782eab11d711089353f64b6dd66f484; Path=/; Secure; HttpOnly
Strict-Transport-Security: max-age=31536000
{"succeeded":false,"errors":{"general":[{"message":"Origin-headeren må ikke være tom","code":"ORIGIN_HEADER_EMPTY"}],"validation":[]},"successes":[]}
Open service 2a02:26f0:7100::210:179:443 · gapi.admin.kalundborg.dk
2026-01-01 22:04
HTTP/1.1 400 Bad Request
Content-Type: application/json; charset=utf-8
Content-Length: 151
Expires: Thu, 01 Jan 2026 22:04:27 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 01 Jan 2026 22:04:27 GMT
Connection: close
Set-Cookie: GoPublicAffinity=1767305068.045.541027.159241|4782eab11d711089353f64b6dd66f484; Path=/; Secure; HttpOnly
Strict-Transport-Security: max-age=31536000
{"succeeded":false,"errors":{"general":[{"message":"Origin-headeren må ikke være tom","code":"ORIGIN_HEADER_EMPTY"}],"validation":[]},"successes":[]}
Open service 2a02:26f0:7100::210:179:80 · gapi.admin.kalundborg.dk
2026-01-01 22:04
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://gapi.admin.kalundborg.dk/ Cache-Control: max-age=0 Expires: Thu, 01 Jan 2026 22:04:30 GMT Date: Thu, 01 Jan 2026 22:04:30 GMT Connection: close
Open service 2a02:26f0:7100::210:178:80 · gapi.admin.kalundborg.dk
2026-01-01 22:04
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://gapi.admin.kalundborg.dk/ Cache-Control: max-age=0 Expires: Thu, 01 Jan 2026 22:04:29 GMT Date: Thu, 01 Jan 2026 22:04:29 GMT Connection: close
Open service 2.16.183.18:443 · gapi.admin.kalundborg.dk
2026-01-01 22:04
HTTP/1.1 400 Bad Request
Content-Type: application/json; charset=utf-8
Content-Length: 151
Expires: Thu, 01 Jan 2026 22:04:27 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 01 Jan 2026 22:04:27 GMT
Connection: close
Set-Cookie: GoPublicAffinity=1767305068.05.540081.20023|4782eab11d711089353f64b6dd66f484; Path=/; Secure; HttpOnly
Strict-Transport-Security: max-age=31536000
{"succeeded":false,"errors":{"general":[{"message":"Origin-headeren må ikke være tom","code":"ORIGIN_HEADER_EMPTY"}],"validation":[]},"successes":[]}
Open service 2.16.183.7:443 · gapi.admin.kalundborg.dk
2026-01-01 22:04
HTTP/1.1 400 Bad Request
Content-Type: application/json; charset=utf-8
Content-Length: 151
Expires: Thu, 01 Jan 2026 22:04:27 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 01 Jan 2026 22:04:27 GMT
Connection: close
Set-Cookie: GoPublicAffinity=1767305068.016.541305.37913|4782eab11d711089353f64b6dd66f484; Path=/; Secure; HttpOnly
Strict-Transport-Security: max-age=31536000
{"succeeded":false,"errors":{"general":[{"message":"Origin-headeren må ikke være tom","code":"ORIGIN_HEADER_EMPTY"}],"validation":[]},"successes":[]}