cloudflare
tcp/443 tcp/80 tcp/8443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d8df885661df198657651e455efedf9b4df4503b
GraphQL introspection enabled at /graphql Types: 112 (by kind: ENUM: 6, INPUT_OBJECT: 42, OBJECT: 52, SCALAR: 12) Operations: - Query: Query | fields: getAccount, getAccountProjects, getCellImage, getCellImages, getChatGroups - Mutation: Mutation | fields: createChatGroup, createChatMessage, createChatSummary, createDirectChatGroup, createEmployee Directives: deprecated, include, skip (total: 3)
Open service 162.159.140.98:443 · api.dev.cpcdx.com
2026-01-09 14:54
HTTP/1.1 200 OK Date: Fri, 09 Jan 2026 14:54:42 GMT Content-Type: text/html Transfer-Encoding: chunked Connection: close CF-RAY: 9bb4c577dbae94d2-LHR x-frame-options: SAMEORIGIN x-xss-protection: 1; mode=block x-content-type-options: nosniff x-download-options: noopen x-permitted-cross-domain-policies: none referrer-policy: strict-origin-when-cross-origin Cache-Control: no-cache x-request-id: 8ca10f0b-52a2-4544-9ed2-e546aa00750c x-runtime: 0.008801 vary: Origin x-do-app-origin: 9b1b18e2-28e1-42b7-ba25-bdac6c086f2b x-do-orig-status: 200 cf-cache-status: MISS Set-Cookie: __cf_bm=0q7B3gFB9x4M_mQmdCWyTkPGhJxLCW_JhJ6.bcdtlAM-1767970482-1.0.1.1-dI2jpCa9qUq5AeYSyjX3ET_JHrMq6HsNj0JaisPF1LlCGg08A8LoANgaf52EcO3Ds97eriyWv4_ZpGMddRpTU2rbWefEZMArERw5YwBNY6U; path=/; expires=Fri, 09-Jan-26 15:24:42 GMT; domain=.api.dev.cpcdx.com; HttpOnly; Secure; SameSite=None Server: cloudflare alt-svc: h3=":443"; ma=86400
Open service 162.159.140.98:443 · api.dev.cpcdx.com
2026-01-02 23:37
HTTP/1.1 200 OK Date: Fri, 02 Jan 2026 23:37:23 GMT Content-Type: text/html Transfer-Encoding: chunked Connection: close CF-RAY: 9b7e1582cf829bf7-FRA x-frame-options: SAMEORIGIN x-xss-protection: 1; mode=block x-content-type-options: nosniff x-download-options: noopen x-permitted-cross-domain-policies: none referrer-policy: strict-origin-when-cross-origin Cache-Control: no-cache x-request-id: 9c497a8d-7dec-4c94-8fa8-25184d545a6d x-runtime: 0.005884 vary: Origin x-do-app-origin: 9b1b18e2-28e1-42b7-ba25-bdac6c086f2b x-do-orig-status: 200 cf-cache-status: MISS Set-Cookie: __cf_bm=KWNsvYggrNcUFvbCzy5NxWLUjYTe06HdpQ9IKrixoJk-1767397043-1.0.1.1-DRi4uPJgdYypKixS2CI0x22kG9HP8pBgg4Kx7T7_TNpmfqg_9mpDmelpXbBNH69a20uYwFhLEreXt9ptvDcoIPEqYRHbFZ734uij0RVn5wA; path=/; expires=Sat, 03-Jan-26 00:07:23 GMT; domain=.api.dev.cpcdx.com; HttpOnly; Secure; SameSite=None Server: cloudflare alt-svc: h3=":443"; ma=86400
Open service 162.159.140.98:8443 · api.dev.cpcdx.com
2026-01-01 00:50
HTTP/1.1 522 Date: Thu, 01 Jan 2026 00:51:09 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close X-Frame-Options: SAMEORIGIN Referrer-Policy: same-origin Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Server: cloudflare CF-RAY: 9b6e06540f104c9b-YYZ alt-svc: h3=":8443"; ma=86400 error code: 522
Open service 162.159.140.98:443 · api.dev.cpcdx.com
2026-01-01 00:50
HTTP/1.1 200 OK Date: Thu, 01 Jan 2026 00:50:53 GMT Content-Type: text/html Transfer-Encoding: chunked Connection: close CF-RAY: 9b6e06538bba0d16-SJC x-frame-options: SAMEORIGIN x-xss-protection: 1; mode=block x-content-type-options: nosniff x-download-options: noopen x-permitted-cross-domain-policies: none referrer-policy: strict-origin-when-cross-origin Cache-Control: no-cache x-request-id: 59a9a4c2-dffc-46b2-aa2b-fb049524dc72 x-runtime: 0.004688 vary: Origin x-do-app-origin: 9b1b18e2-28e1-42b7-ba25-bdac6c086f2b x-do-orig-status: 200 cf-cache-status: MISS Set-Cookie: __cf_bm=t6Vo.Ji4zlqqlQHZ89.w3BmU0ZClPRIzdmCF2xYXj9Q-1767228653-1.0.1.1-_sT4g2JRTgUw02UfQtN.xAtsKCR9k65Rx26ONh6x0C57uNRMIZDR9vJo1wK8pNao4z2FEzxw8QNFFm26k89YFCE_KDKXaDc0N5vF8L37oLY; path=/; expires=Thu, 01-Jan-26 01:20:53 GMT; domain=.api.dev.cpcdx.com; HttpOnly; Secure; SameSite=None Server: cloudflare alt-svc: h3=":443"; ma=86400
Open service 2606:4700:7::60:443 · api.dev.cpcdx.com
2026-01-01 00:50
HTTP/1.1 200 OK Date: Thu, 01 Jan 2026 00:50:50 GMT Content-Type: text/html Transfer-Encoding: chunked Connection: close CF-RAY: 9b6e06539951583f-EWR x-frame-options: SAMEORIGIN x-xss-protection: 1; mode=block x-content-type-options: nosniff x-download-options: noopen x-permitted-cross-domain-policies: none referrer-policy: strict-origin-when-cross-origin Cache-Control: no-cache x-request-id: 983d2eaa-2ee6-4814-8325-1b97cbbd353f x-runtime: 0.004117 vary: Origin x-do-app-origin: 9b1b18e2-28e1-42b7-ba25-bdac6c086f2b x-do-orig-status: 200 cf-cache-status: MISS Set-Cookie: __cf_bm=tYnzvR811evgVEFbwylzSrpDwqJ.Hso1u7hH90ncDhQ-1767228650-1.0.1.1-ZgHRv2orTcoOomcnYzTkCwy0eqzmyPYcfLUzftN_MHMVNjxlkbOwRDstRqPzEGqhqUYsMycOC1sW1Nvb5650tUCxWmjGM7y4I6jhCdJIvb4; path=/; expires=Thu, 01-Jan-26 01:20:50 GMT; domain=.api.dev.cpcdx.com; HttpOnly; Secure; SameSite=None Server: cloudflare alt-svc: h3=":443"; ma=86400
Open service 172.66.0.96:80 · api.dev.cpcdx.com
2026-01-01 00:50
HTTP/1.1 301 Moved Permanently Date: Thu, 01 Jan 2026 00:50:48 GMT Content-Type: text/html Content-Length: 167 Connection: close Cache-Control: max-age=3600 Expires: Thu, 01 Jan 2026 01:50:48 GMT Location: https://api.dev.cpcdx.com/ Set-Cookie: __cf_bm=pkY.YHZXQOmrm5vJ.U1_0nzdMp0Otx7J6dVtG5VMg5s-1767228648-1.0.1.1-jo_FDEVYx9fYDrIDFsk7G_ERMlPJQWU3JFolfGLIDKIXdJm917.fpe_NOL4DnMYBR2CkpY2Bc.XjyPh3KR72B1RLj9qmid0joJx9f6t0vVU; path=/; expires=Thu, 01-Jan-26 01:20:48 GMT; domain=.api.dev.cpcdx.com; HttpOnly Server: cloudflare CF-RAY: 9b6e064d19dedbfb-FRA alt-svc: h3=":443"; ma=86400 Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>cloudflare</center> </body> </html>
Open service 2606:4700:7::60:80 · api.dev.cpcdx.com
2026-01-01 00:50
HTTP/1.1 301 Moved Permanently Date: Thu, 01 Jan 2026 00:50:48 GMT Content-Type: text/html Content-Length: 167 Connection: close Cache-Control: max-age=3600 Expires: Thu, 01 Jan 2026 01:50:48 GMT Location: https://api.dev.cpcdx.com/ Set-Cookie: __cf_bm=1qmklfQIx_FccJ.JkcjoVlCeEyCF5vGKp5g2LcSjCQA-1767228648-1.0.1.1-OQKwD_fHKaNfaPYBckg9nyMeIxyMQgJau3t.23RzQsZk.qLIgDbvnZsqYM3wPvSI3Cuy2NxbQJ8u7ZBQmeH8pTshfUaFMJHCCp_EaCujwNI; path=/; expires=Thu, 01-Jan-26 01:20:48 GMT; domain=.api.dev.cpcdx.com; HttpOnly Server: cloudflare CF-RAY: 9b6e064d0954d390-FRA alt-svc: h3=":443"; ma=86400 Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>cloudflare</center> </body> </html>
Open service 172.66.0.96:443 · api.dev.cpcdx.com
2026-01-01 00:50
HTTP/1.1 200 OK Date: Thu, 01 Jan 2026 00:50:49 GMT Content-Type: text/html Transfer-Encoding: chunked Connection: close CF-RAY: 9b6e0652fc3fe640-EWR x-frame-options: SAMEORIGIN x-xss-protection: 1; mode=block x-content-type-options: nosniff x-download-options: noopen x-permitted-cross-domain-policies: none referrer-policy: strict-origin-when-cross-origin Cache-Control: no-cache x-request-id: 4435fc80-6994-4d1b-bb24-1361e02ada4b x-runtime: 0.004103 vary: Origin x-do-app-origin: 9b1b18e2-28e1-42b7-ba25-bdac6c086f2b x-do-orig-status: 200 cf-cache-status: MISS Set-Cookie: __cf_bm=PVsAk6Zuzl.NSfnn3LUl5bxms2q.CZd7vUJzmd.zNYI-1767228649-1.0.1.1-Tgvzad547I3qyrWxHneRM8EJCCQfs8d3BIn6r6xISzdv2vRYC6gZJormQhNaFiC27hsc6lMAeYDJqzHwrSYhnDOa.C6so2xqjNirV9Emyy8; path=/; expires=Thu, 01-Jan-26 01:20:49 GMT; domain=.api.dev.cpcdx.com; HttpOnly; Secure; SameSite=None Server: cloudflare alt-svc: h3=":443"; ma=86400
Open service 2a06:98c1:58::60:443 · api.dev.cpcdx.com
2026-01-01 00:50
HTTP/1.1 200 OK Date: Thu, 01 Jan 2026 00:50:49 GMT Content-Type: text/html Transfer-Encoding: chunked Connection: close CF-RAY: 9b6e065178e8c3f3-EWR x-frame-options: SAMEORIGIN x-xss-protection: 1; mode=block x-content-type-options: nosniff x-download-options: noopen x-permitted-cross-domain-policies: none referrer-policy: strict-origin-when-cross-origin Cache-Control: no-cache x-request-id: 57c0c484-3030-46ea-b952-fa55cbe40ae3 x-runtime: 0.004260 vary: Origin x-do-app-origin: 9b1b18e2-28e1-42b7-ba25-bdac6c086f2b x-do-orig-status: 200 cf-cache-status: MISS Set-Cookie: __cf_bm=s7hvmz4ZnsDKkl.9_EX_LTlPdYW0pZ.F9ErNGHASgD4-1767228649-1.0.1.1-q_pBYjYn9kGBrJAN1HKIil1CSvWGBN9yc4YEOx8l_f6mXXSK0QRme5nPOCgT7uge5K5ufK2VN6PHgk2rxX8hGbK5zStkaxso6mk5zwSxU.8; path=/; expires=Thu, 01-Jan-26 01:20:49 GMT; domain=.api.dev.cpcdx.com; HttpOnly; Secure; SameSite=None Server: cloudflare alt-svc: h3=":443"; ma=86400
Open service 2606:4700:7::60:8443 · api.dev.cpcdx.com
2026-01-01 00:50
HTTP/1.1 522 Date: Thu, 01 Jan 2026 00:51:09 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close X-Frame-Options: SAMEORIGIN Referrer-Policy: same-origin Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Server: cloudflare CF-RAY: 9b6e0652ebd4d278-FRA alt-svc: h3=":8443"; ma=86400 error code: 522
Open service 162.159.140.98:80 · api.dev.cpcdx.com
2026-01-01 00:50
HTTP/1.1 301 Moved Permanently Date: Thu, 01 Jan 2026 00:50:48 GMT Content-Type: text/html Content-Length: 167 Connection: close Cache-Control: max-age=3600 Expires: Thu, 01 Jan 2026 01:50:48 GMT Location: https://api.dev.cpcdx.com/ Set-Cookie: __cf_bm=QHa4mGUlr0Uitt_llSJ3hnWvF2jlOOoh2bYsS8NklCI-1767228648-1.0.1.1-hc8b6OXBZdvsqBD7M5ZCaPGmEn8D2K3DA88hFXvCj4rlhe_6V26IoZDf7BNReyZmDTUAbH1NdUzrRfXqlvn6JzhJZPJjvvvr5mZXf8Fvtmo; path=/; expires=Thu, 01-Jan-26 01:20:48 GMT; domain=.api.dev.cpcdx.com; HttpOnly Server: cloudflare CF-RAY: 9b6e064cab94433d-EWR alt-svc: h3=":443"; ma=86400 Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>cloudflare</center> </body> </html>
Open service 2a06:98c1:58::60:80 · api.dev.cpcdx.com
2026-01-01 00:50
HTTP/1.1 301 Moved Permanently Date: Thu, 01 Jan 2026 00:50:48 GMT Content-Type: text/html Content-Length: 167 Connection: close Cache-Control: max-age=3600 Expires: Thu, 01 Jan 2026 01:50:48 GMT Location: https://api.dev.cpcdx.com/ Set-Cookie: __cf_bm=VK1AJoZsDF3uy_gY2v_2udKgpILHKZBNY8kFgdkgzV4-1767228648-1.0.1.1-B8BmG3NL8sbSOGIeTHFk9doiOTDAP8dC9UvnE0FyF0tRYGRwaxqmqCk1Ec36kgcZ86T3VyFEzprGU2cA.lYQbIevxi_ZBmQyRjbSV34QfmE; path=/; expires=Thu, 01-Jan-26 01:20:48 GMT; domain=.api.dev.cpcdx.com; HttpOnly Server: cloudflare CF-RAY: 9b6e064c6e65fff3-AMS alt-svc: h3=":443"; ma=86400 Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>cloudflare</center> </body> </html>
Open service 172.66.0.96:8443 · api.dev.cpcdx.com
2026-01-01 00:50
HTTP/1.1 522 Date: Thu, 01 Jan 2026 00:51:09 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close X-Frame-Options: SAMEORIGIN Referrer-Policy: same-origin Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Server: cloudflare CF-RAY: 9b6e06529a0ed34d-FRA alt-svc: h3=":8443"; ma=86400 error code: 522
Open service 2a06:98c1:58::60:8443 · api.dev.cpcdx.com
2026-01-01 00:50
HTTP/1.1 522 Date: Thu, 01 Jan 2026 00:51:08 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close X-Frame-Options: SAMEORIGIN Referrer-Policy: same-origin Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Server: cloudflare CF-RAY: 9b6e06529fa79f93-AMS alt-svc: h3=":8443"; ma=86400 error code: 522
Open service 162.159.140.98:443 · api.dev.cpcdx.com
2025-12-23 05:07
HTTP/1.1 200 OK Date: Tue, 23 Dec 2025 05:07:20 GMT Content-Type: text/html Transfer-Encoding: chunked Connection: close CF-RAY: 9b2555b40bc71598-SJC x-frame-options: SAMEORIGIN x-xss-protection: 1; mode=block x-content-type-options: nosniff x-download-options: noopen x-permitted-cross-domain-policies: none referrer-policy: strict-origin-when-cross-origin Cache-Control: no-cache x-request-id: 4d015f71-ab05-4f74-ab95-613aa996d5ac x-runtime: 0.005581 vary: Origin x-do-app-origin: 9b1b18e2-28e1-42b7-ba25-bdac6c086f2b x-do-orig-status: 200 cf-cache-status: MISS Set-Cookie: __cf_bm=00AUPOXI7.Lnlh8Fp1HdAkcr1mkTRA1L1Kc5FDlQ3AU-1766466440-1.0.1.1-0bOlvavMYX.o80ySkuJGvThyys7BP0gl1gGpdW6dDcyIjk9md6NgxZK6gDSfQ4VyAry_4z8o0FVwsPHQ0_lFOo3cH1lVRaTbc_m6ZXuVEH0; path=/; expires=Tue, 23-Dec-25 05:37:20 GMT; domain=.api.dev.cpcdx.com; HttpOnly; Secure; SameSite=None Server: cloudflare alt-svc: h3=":443"; ma=86400
Open service 162.159.140.98:443 · api.dev.cpcdx.com
2025-12-21 01:50
HTTP/1.1 200 OK Date: Sun, 21 Dec 2025 01:50:45 GMT Content-Type: text/html Transfer-Encoding: chunked Connection: close CF-RAY: 9b13bafe7b82aaf2-YYZ x-frame-options: SAMEORIGIN x-xss-protection: 1; mode=block x-content-type-options: nosniff x-download-options: noopen x-permitted-cross-domain-policies: none referrer-policy: strict-origin-when-cross-origin Cache-Control: no-cache x-request-id: d4ddd163-a535-4d54-99d0-ae76ec73952c x-runtime: 0.002980 vary: Origin x-do-app-origin: 9b1b18e2-28e1-42b7-ba25-bdac6c086f2b x-do-orig-status: 200 cf-cache-status: MISS Set-Cookie: __cf_bm=npnwwg1zZdriAtnxcDN3K5RXHNqG2A5KfAx_3XHyHq0-1766281845-1.0.1.1-lQdykuqJWuhtlg6Pfd8PGkTelqB6Fl89qavo7xHBtZfViEmXoa17GFITPye6DTDcEaofl8bm33AXCeaDXeW.smlrQ2XtFTwA7k5fiQctoQQ; path=/; expires=Sun, 21-Dec-25 02:20:45 GMT; domain=.api.dev.cpcdx.com; HttpOnly; Secure; SameSite=None Server: cloudflare alt-svc: h3=":443"; ma=86400
Open service 162.159.140.98:443 · api.dev.cpcdx.com
2025-12-19 04:58
HTTP/1.1 200 OK Date: Fri, 19 Dec 2025 04:58:30 GMT Content-Type: text/html Transfer-Encoding: chunked Connection: close CF-RAY: 9b045345283160e4-LHR x-frame-options: SAMEORIGIN x-xss-protection: 1; mode=block x-content-type-options: nosniff x-download-options: noopen x-permitted-cross-domain-policies: none referrer-policy: strict-origin-when-cross-origin Cache-Control: no-cache x-request-id: f3d1efdc-d222-49c0-9bb0-b8016e88ebb5 x-runtime: 0.003127 vary: Origin x-do-app-origin: 9b1b18e2-28e1-42b7-ba25-bdac6c086f2b x-do-orig-status: 200 cf-cache-status: MISS Set-Cookie: __cf_bm=vhfn4_KjHs9cR_fsdH97wu91iUuJbhEFPGEkMkesE7s-1766120310-1.0.1.1-n9r4UEpK6NmAi9lIUdURJsZHZRfyGx3I.33RMD0d7u6lB6w8n0DVaYoy04UEnUthjUr.8EOIoflbBNuupFq_ZJ9ZMqe1e6iSU8UQJQLVKdA; path=/; expires=Fri, 19-Dec-25 05:28:30 GMT; domain=.api.dev.cpcdx.com; HttpOnly; Secure; SameSite=None Server: cloudflare alt-svc: h3=":443"; ma=86400