Vercel
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 216.198.79.1:443 · api.athlyze.app
2026-01-10 01:18
HTTP/1.1 200 OK Access-Control-Allow-Credentials: true Access-Control-Allow-Origin: * Age: 0 Cache-Control: public, max-age=0, must-revalidate Content-Length: 22 Content-Type: text/html; charset=utf-8 Date: Sat, 10 Jan 2026 01:18:53 GMT Etag: W/"16-s1fDO2CY+kkBSt8vuKffpxMB5qA" Server: Vercel Strict-Transport-Security: max-age=63072000 Vary: Origin X-Powered-By: Express X-Vercel-Cache: MISS X-Vercel-Id: fra1::iad1::5w247-1768007933104-d34f16d154cd Connection: close Athlyze API is running
Open service 216.198.79.1:443 · api.athlyze.app
2026-01-03 01:03
HTTP/1.1 200 OK Access-Control-Allow-Credentials: true Access-Control-Allow-Origin: * Age: 0 Cache-Control: public, max-age=0, must-revalidate Content-Length: 22 Content-Type: text/html; charset=utf-8 Date: Sat, 03 Jan 2026 01:03:08 GMT Etag: W/"16-s1fDO2CY+kkBSt8vuKffpxMB5qA" Server: Vercel Strict-Transport-Security: max-age=63072000 Vary: Origin X-Powered-By: Express X-Vercel-Cache: MISS X-Vercel-Id: bom1::iad1::sp7rd-1767402186093-08a11412c0e6 Connection: close Athlyze API is running
Open service 216.198.79.65:80 · api.athlyze.app
2025-12-31 18:07
HTTP/1.0 308 Permanent Redirect Content-Type: text/plain Location: https://api.athlyze.app/ Refresh: 0;url=https://api.athlyze.app/ server: Vercel Redirecting...
Open service 64.29.17.65:443 · api.athlyze.app
2025-12-31 18:07
HTTP/1.1 200 OK Access-Control-Allow-Credentials: true Access-Control-Allow-Origin: * Age: 0 Cache-Control: public, max-age=0, must-revalidate Content-Length: 22 Content-Type: text/html; charset=utf-8 Date: Wed, 31 Dec 2025 18:07:58 GMT Etag: W/"16-s1fDO2CY+kkBSt8vuKffpxMB5qA" Server: Vercel Strict-Transport-Security: max-age=63072000 Vary: Origin X-Powered-By: Express X-Vercel-Cache: MISS X-Vercel-Id: iad1::iad1::fd4v6-1767204476923-b1b94b6cc639 Connection: close Athlyze API is running
Open service 216.198.79.65:443 · api.athlyze.app
2025-12-31 18:07
HTTP/1.1 200 OK Access-Control-Allow-Credentials: true Access-Control-Allow-Origin: * Age: 0 Cache-Control: public, max-age=0, must-revalidate Content-Length: 22 Content-Type: text/html; charset=utf-8 Date: Wed, 31 Dec 2025 18:07:58 GMT Etag: W/"16-s1fDO2CY+kkBSt8vuKffpxMB5qA" Server: Vercel Strict-Transport-Security: max-age=63072000 Vary: Origin X-Powered-By: Express X-Vercel-Cache: MISS X-Vercel-Id: fra1::iad1::tfzcz-1767204476717-2ec544385609 Connection: close Athlyze API is running
Open service 64.29.17.65:80 · api.athlyze.app
2025-12-31 18:07
HTTP/1.0 308 Permanent Redirect Content-Type: text/plain Location: https://api.athlyze.app/ Refresh: 0;url=https://api.athlyze.app/ server: Vercel Redirecting...
Open service 216.198.79.1:443 · api.athlyze.app
2025-12-23 09:48
HTTP/1.1 200 OK Access-Control-Allow-Credentials: true Access-Control-Allow-Origin: * Age: 0 Cache-Control: public, max-age=0, must-revalidate Content-Length: 22 Content-Type: text/html; charset=utf-8 Date: Tue, 23 Dec 2025 09:48:06 GMT Etag: W/"16-s1fDO2CY+kkBSt8vuKffpxMB5qA" Server: Vercel Strict-Transport-Security: max-age=63072000 Vary: Origin X-Powered-By: Express X-Vercel-Cache: MISS X-Vercel-Id: fra1::iad1::nzwn5-1766483284546-a97c4674386a Connection: close Athlyze API is running
Open service 216.198.79.1:443 · api.athlyze.app
2025-12-21 09:31
HTTP/1.1 200 OK Access-Control-Allow-Credentials: true Access-Control-Allow-Origin: * Age: 0 Cache-Control: public, max-age=0, must-revalidate Content-Length: 22 Content-Type: text/html; charset=utf-8 Date: Sun, 21 Dec 2025 09:31:11 GMT Etag: W/"16-s1fDO2CY+kkBSt8vuKffpxMB5qA" Server: Vercel Strict-Transport-Security: max-age=63072000 Vary: Origin X-Powered-By: Express X-Vercel-Cache: MISS X-Vercel-Id: lhr1::iad1::n7pzz-1766309469907-dcd2d5b08559 Connection: close Athlyze API is running
Open service 216.198.79.1:443 · api.athlyze.app
2025-12-19 10:49
HTTP/1.1 200 OK Access-Control-Allow-Credentials: true Access-Control-Allow-Origin: * Age: 0 Cache-Control: public, max-age=0, must-revalidate Content-Length: 22 Content-Type: text/html; charset=utf-8 Date: Fri, 19 Dec 2025 10:49:24 GMT Etag: W/"16-s1fDO2CY+kkBSt8vuKffpxMB5qA" Server: Vercel Strict-Transport-Security: max-age=63072000 Vary: Origin X-Powered-By: Express X-Vercel-Cache: MISS X-Vercel-Id: fra1::iad1::vbnx6-1766141363171-ef1d3bf0a324 Connection: close Athlyze API is running