Kestrel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035498bc9b856620a90a1ff7a0a25ddcf2790ebb018df
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: GET /api/v1/Participants/status POST /api/v1/OAuth/Token POST /api/v1/Participants POST /api/v1/Participants/Search POST /api/v1/Participants/upload-pdf
Open service 40.119.12.82:443 · api-qa.planrollouts.com
2026-01-23 03:37
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Fri, 23 Jan 2026 03:37:46 GMT Server: Kestrel Request-Context: appId=cid-v1:8311ef44-a446-4259-8b66-8f91bd5eda5d
Open service 40.119.12.82:443 · api-qa.planrollouts.com
2026-01-09 09:07
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Fri, 09 Jan 2026 09:08:02 GMT Server: Kestrel Request-Context: appId=cid-v1:8311ef44-a446-4259-8b66-8f91bd5eda5d
Open service 40.119.12.82:443 · api-qa.planrollouts.com
2026-01-01 19:36
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Thu, 01 Jan 2026 19:36:25 GMT Server: Kestrel Request-Context: appId=cid-v1:8311ef44-a446-4259-8b66-8f91bd5eda5d
Open service 40.119.12.82:443 · api-qa.planrollouts.com
2025-12-22 22:10
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Mon, 22 Dec 2025 22:10:56 GMT Server: Kestrel Request-Context: appId=cid-v1:8311ef44-a446-4259-8b66-8f91bd5eda5d