Vercel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 216.198.79.1:443 · api.fideprep.ch
2026-01-08 22:45
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Age: 0
Cache-Control: public, max-age=0, must-revalidate
Content-Length: 47
Content-Type: application/json; charset=utf-8
Date: Thu, 08 Jan 2026 22:45:14 GMT
Etag: W/"2f-DJnHc/3vJeiZipiuSI+WhqR66yk"
Server: Vercel
Strict-Transport-Security: max-age=63072000
Vary: Origin
X-Powered-By: Express
X-Vercel-Cache: MISS
X-Vercel-Id: sfo1::iad1::6mwcn-1767912314640-9b1a42bd9296
Connection: close
{"message":"API is working","docs":"/api-docs"}
Open service 216.198.79.1:443 · api.fideprep.ch
2026-01-01 19:22
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Age: 0
Cache-Control: public, max-age=0, must-revalidate
Content-Length: 47
Content-Type: application/json; charset=utf-8
Date: Thu, 01 Jan 2026 19:22:02 GMT
Etag: W/"2f-DJnHc/3vJeiZipiuSI+WhqR66yk"
Server: Vercel
Strict-Transport-Security: max-age=63072000
Vary: Origin
X-Powered-By: Express
X-Vercel-Cache: MISS
X-Vercel-Id: fra1::iad1::zmtxr-1767295321870-1b071f36e2dd
Connection: close
{"message":"API is working","docs":"/api-docs"}
Open service 216.198.79.1:443 · api.fideprep.ch
2025-12-30 03:53
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Age: 0
Cache-Control: public, max-age=0, must-revalidate
Content-Length: 47
Content-Type: application/json; charset=utf-8
Date: Tue, 30 Dec 2025 03:53:57 GMT
Etag: W/"2f-DJnHc/3vJeiZipiuSI+WhqR66yk"
Server: Vercel
Strict-Transport-Security: max-age=63072000
Vary: Origin
X-Powered-By: Express
X-Vercel-Cache: MISS
X-Vercel-Id: lhr1::iad1::8s7vn-1767066836618-8431ee1773ca
Connection: close
{"message":"API is working","docs":"/api-docs"}
Open service 216.198.79.1:443 · api.fideprep.ch
2025-12-22 04:36
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Age: 0
Cache-Control: public, max-age=0, must-revalidate
Content-Length: 47
Content-Type: application/json; charset=utf-8
Date: Mon, 22 Dec 2025 04:36:55 GMT
Etag: W/"2f-DJnHc/3vJeiZipiuSI+WhqR66yk"
Server: Vercel
Strict-Transport-Security: max-age=63072000
Vary: Origin
X-Powered-By: Express
X-Vercel-Cache: MISS
X-Vercel-Id: lhr1::iad1::2zhqg-1766378215150-1c9f207162d7
Connection: close
{"message":"API is working","docs":"/api-docs"}
Open service 216.198.79.1:443 · api.fideprep.ch
2025-12-20 04:33
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Age: 0
Cache-Control: public, max-age=0, must-revalidate
Content-Length: 47
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 04:33:38 GMT
Etag: W/"2f-DJnHc/3vJeiZipiuSI+WhqR66yk"
Server: Vercel
Strict-Transport-Security: max-age=63072000
Vary: Origin
X-Powered-By: Express
X-Vercel-Cache: MISS
X-Vercel-Id: iad1::iad1::wtt95-1766205217672-b6c99f00ba90
Connection: close
{"message":"API is working","docs":"/api-docs"}