Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 172.217.208.121:443 · api.iqbi.nl
2026-01-09 15:21
HTTP/1.1 404 Not Found x-powered-by: Express vary: Origin access-control-allow-credentials: true content-security-policy: default-src 'none' x-content-type-options: nosniff content-type: text/html; charset=utf-8 x-cloud-trace-context: a4321f33b7a50495516703eb5b227170 date: Fri, 09 Jan 2026 15:22:01 GMT server: Google Frontend Content-Length: 139 Connection: close Page title: Error <!DOCTYPE html> <html lang="en"> <head> <meta charset="utf-8"> <title>Error</title> </head> <body> <pre>Cannot GET /</pre> </body> </html>
Open service 172.217.208.121:443 · api.iqbi.nl
2026-01-02 12:21
HTTP/1.1 404 Not Found x-powered-by: Express vary: Origin access-control-allow-credentials: true content-security-policy: default-src 'none' x-content-type-options: nosniff content-type: text/html; charset=utf-8 x-cloud-trace-context: 43af6f71adba4a0176df0e56f06fe534 date: Fri, 02 Jan 2026 12:21:38 GMT server: Google Frontend Content-Length: 139 Connection: close Page title: Error <!DOCTYPE html> <html lang="en"> <head> <meta charset="utf-8"> <title>Error</title> </head> <body> <pre>Cannot GET /</pre> </body> </html>
Open service 172.217.208.121:443 · api.iqbi.nl
2025-12-22 18:27
HTTP/1.1 404 Not Found x-powered-by: Express vary: Origin access-control-allow-credentials: true content-security-policy: default-src 'none' x-content-type-options: nosniff content-type: text/html; charset=utf-8 x-cloud-trace-context: 0488adda2aa9a62c1f272b3bd071d176 date: Mon, 22 Dec 2025 18:27:13 GMT server: Google Frontend Content-Length: 139 Connection: close Page title: Error <!DOCTYPE html> <html lang="en"> <head> <meta charset="utf-8"> <title>Error</title> </head> <body> <pre>Cannot GET /</pre> </body> </html>
Open service 172.217.208.121:443 · api.iqbi.nl
2025-12-20 18:35
HTTP/1.1 404 Not Found x-powered-by: Express vary: Origin access-control-allow-credentials: true content-security-policy: default-src 'none' x-content-type-options: nosniff content-type: text/html; charset=utf-8 x-cloud-trace-context: 1ea61ac3fbc8dd09d66c0893e8639b4c date: Sat, 20 Dec 2025 18:35:22 GMT server: Google Frontend Content-Length: 139 Connection: close Page title: Error <!DOCTYPE html> <html lang="en"> <head> <meta charset="utf-8"> <title>Error</title> </head> <body> <pre>Cannot GET /</pre> </body> </html>