Vercel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 216.198.79.1:443 · api.kitrex.in
2026-01-09 20:26
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Age: 0
Cache-Control: public, max-age=0, must-revalidate
Content-Length: 56
Content-Type: application/json; charset=utf-8
Date: Fri, 09 Jan 2026 20:26:12 GMT
Etag: W/"38-Bj7qiG9jpplvECFESTJix7ikhHk"
Server: Vercel
Strict-Transport-Security: max-age=63072000
Vary: Origin
X-Powered-By: Express
X-Vercel-Cache: MISS
X-Vercel-Id: fra1::sin1::b5gz9-1767990372752-f7015361c4e2
Connection: close
{"success":false,"message":"Route not found","path":"/"}
Open service 216.198.79.1:443 · api.kitrex.in
2026-01-02 17:23
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Age: 0
Cache-Control: public, max-age=0, must-revalidate
Content-Length: 56
Content-Type: application/json; charset=utf-8
Date: Fri, 02 Jan 2026 17:24:02 GMT
Etag: W/"38-Bj7qiG9jpplvECFESTJix7ikhHk"
Server: Vercel
Strict-Transport-Security: max-age=63072000
Vary: Origin
X-Powered-By: Express
X-Vercel-Cache: MISS
X-Vercel-Id: lhr1::sin1::7g9d5-1767374640590-080b802f347b
Connection: close
{"success":false,"message":"Route not found","path":"/"}
Open service 216.198.79.1:443 · api.kitrex.in
2025-12-23 01:19
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Age: 0
Cache-Control: public, max-age=0, must-revalidate
Content-Length: 56
Content-Type: application/json; charset=utf-8
Date: Tue, 23 Dec 2025 01:19:56 GMT
Etag: W/"38-Bj7qiG9jpplvECFESTJix7ikhHk"
Server: Vercel
Strict-Transport-Security: max-age=63072000
Vary: Origin
X-Powered-By: Express
X-Vercel-Cache: MISS
X-Vercel-Id: fra1::sin1::xdr8r-1766452794463-439a60b69a8b
Connection: close
{"success":false,"message":"Route not found","path":"/"}
Open service 216.198.79.1:443 · api.kitrex.in
2025-12-20 15:30
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Age: 0
Cache-Control: public, max-age=0, must-revalidate
Content-Length: 56
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 15:30:27 GMT
Etag: W/"38-Bj7qiG9jpplvECFESTJix7ikhHk"
Server: Vercel
Strict-Transport-Security: max-age=63072000
Vary: Origin
X-Powered-By: Express
X-Vercel-Cache: MISS
X-Vercel-Id: sin1::sin1::phg75-1766244625251-2993c5963b73
Connection: close
{"success":false,"message":"Route not found","path":"/"}