TencentEdgeOne
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd110a331ec9da4adef8bac5c2831ffcb32cb6ee15dcb6ee15d
Public Swagger UI/API detected at path: /v2/api-docs - sample paths:
GET /dev-api/test/user/list
GET /dev-api/test/user/{userId}
POST /dev-api/test/user/save
PUT /dev-api/test/user/update
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd110a331ec9da4adef8bac5c2831ffcb32cb6ee15dcb6ee15d
Public Swagger UI/API detected at path: /v2/api-docs - sample paths:
GET /dev-api/test/user/list
GET /dev-api/test/user/{userId}
POST /dev-api/test/user/save
PUT /dev-api/test/user/update
Open service 43.152.43.121:443 ยท api.a9527.cn
2026-01-22 22:14
HTTP/1.1 418 Unknown Status Content-Length: 0 Connection: close Date: Thu, 22 Jan 2026 22:14:59 GMT Server: TencentEdgeOne EO-LOG-UUID: 9305446915810244980