Heroku
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 76.223.57.73:443 · api.onework.com.br
2026-01-09 08:45
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 13
Content-Security-Policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
Content-Type: application/json; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-origin
Date: Fri, 09 Jan 2026 08:45:22 GMT
Etag: W/"d-wgfZrxyMRZjwsCw+MwO+/hppD2A"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Origin-Agent-Cluster: ?1
Referrer-Policy: no-referrer
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=x0%2Fl0d5lqqc6beW4z7%2BmtT29LiwrDkMqZKog5w3eBXg%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767948322"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=x0%2Fl0d5lqqc6beW4z7%2BmtT29LiwrDkMqZKog5w3eBXg%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767948322"
Server: Heroku
Set-Cookie: connect.sid=s%3AkucpvWXO8dcUADwc4g70p0XFeC2N83NA.RwUvtz13SUVMFiB2sp%2FKUZ68zrh33lJtiBbTDhSKBkM; Path=/; HttpOnly
Strict-Transport-Security: max-age=15552000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Xss-Protection: 0
Connection: close
"API ONEWORK"
Open service 76.223.57.73:80 · api.onework.com.br
2026-01-09 01:51
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 13
Content-Security-Policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
Content-Type: application/json; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-origin
Date: Fri, 09 Jan 2026 01:52:55 GMT
Etag: W/"d-wgfZrxyMRZjwsCw+MwO+/hppD2A"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Origin-Agent-Cluster: ?1
Referrer-Policy: no-referrer
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=YoGJJkRiZJ37yw58Aej0frv5A36MRRZb6aHctXJp9VE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767923575"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=YoGJJkRiZJ37yw58Aej0frv5A36MRRZb6aHctXJp9VE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767923575"
Server: Heroku
Set-Cookie: connect.sid=s%3AOHgg_awew5FjWcYh7DNTVKZpU5ZOaIY6.8xoH4CVe78M1ajjYRQ3fmPoiQaivfXofFwpg7PAEc%2BQ; Path=/; HttpOnly
Strict-Transport-Security: max-age=15552000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Xss-Protection: 0
Connection: close
"API ONEWORK"
Open service 76.223.57.73:443 · api.onework.com.br
2026-01-02 08:40
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 13
Content-Security-Policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
Content-Type: application/json; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-origin
Date: Fri, 02 Jan 2026 08:40:02 GMT
Etag: W/"d-wgfZrxyMRZjwsCw+MwO+/hppD2A"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Origin-Agent-Cluster: ?1
Referrer-Policy: no-referrer
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=PdJPe%2FbjuyM9a6zaRuHXaq0UTRwHZwN180CaLU1t%2F1U%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767343202"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=PdJPe%2FbjuyM9a6zaRuHXaq0UTRwHZwN180CaLU1t%2F1U%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767343202"
Server: Heroku
Set-Cookie: connect.sid=s%3AGr4Ucr5betSWInFwqW_oCP7dpq0KFEss.EKImyCw6cdVpOch62gYNceutjZVfcXwZCp5dx1wyTUQ; Path=/; HttpOnly
Strict-Transport-Security: max-age=15552000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Xss-Protection: 0
Connection: close
"API ONEWORK"
Open service 76.223.57.73:80 · api.onework.com.br
2026-01-01 19:46
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 13
Content-Security-Policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
Content-Type: application/json; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-origin
Date: Thu, 01 Jan 2026 19:46:30 GMT
Etag: W/"d-wgfZrxyMRZjwsCw+MwO+/hppD2A"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Origin-Agent-Cluster: ?1
Referrer-Policy: no-referrer
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=UiDghSI3UeIsrgkORHbQsMsycAUZ9Ol39eEmUd%2BZsbE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767296790"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=UiDghSI3UeIsrgkORHbQsMsycAUZ9Ol39eEmUd%2BZsbE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767296790"
Server: Heroku
Set-Cookie: connect.sid=s%3ABj6_oymxp8EgvC61DPq5kHQUgV1iOx8n.5zuUtm48toWLnoSabWyRS2BAl%2BSmnRklkU0KM83RV6Y; Path=/; HttpOnly
Strict-Transport-Security: max-age=15552000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Xss-Protection: 0
Connection: close
"API ONEWORK"
Open service 76.223.57.73:80 · api.onework.com.br
2025-12-22 20:15
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 13
Content-Security-Policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
Content-Type: application/json; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-origin
Date: Mon, 22 Dec 2025 20:15:49 GMT
Etag: W/"d-wgfZrxyMRZjwsCw+MwO+/hppD2A"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Origin-Agent-Cluster: ?1
Referrer-Policy: no-referrer
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=GQUyA32aQWUTEeNWxzqHhFkdG%2F9v1DT3d0I8rVzfwEw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766434549"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=GQUyA32aQWUTEeNWxzqHhFkdG%2F9v1DT3d0I8rVzfwEw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766434549"
Server: Heroku
Set-Cookie: connect.sid=s%3ALvub6rSBESZxyscBytJfjLdmojIBRfUk.Tv6naaqZox%2BnUTotnjnjNW0%2FLm6p8Z4GkHwALHq%2B8DI; Path=/; HttpOnly
Strict-Transport-Security: max-age=15552000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Xss-Protection: 0
Connection: close
"API ONEWORK"
Open service 76.223.57.73:80 · api.onework.com.br
2025-12-21 04:01
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 13
Content-Security-Policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
Content-Type: application/json; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-origin
Date: Sun, 21 Dec 2025 04:01:06 GMT
Etag: W/"d-wgfZrxyMRZjwsCw+MwO+/hppD2A"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Origin-Agent-Cluster: ?1
Referrer-Policy: no-referrer
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=gA4EyepHxDiOdSHpz5gGyiiWuuCGvi5zyHKUVL%2FTW3A%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766289666"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=gA4EyepHxDiOdSHpz5gGyiiWuuCGvi5zyHKUVL%2FTW3A%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766289666"
Server: Heroku
Set-Cookie: connect.sid=s%3AP3fDE2-NSnIrrxSNu4TkBp63-7lEsbYj.ffOA7Yr4ROwoJYobXC9MsrzzdT1gaPcWHPZIbUY5akQ; Path=/; HttpOnly
Strict-Transport-Security: max-age=15552000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Xss-Protection: 0
Connection: close
"API ONEWORK"
Open service 76.223.57.73:443 · api.onework.com.br
2025-12-21 00:19
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 13
Content-Security-Policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
Content-Type: application/json; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-origin
Date: Sun, 21 Dec 2025 00:19:33 GMT
Etag: W/"d-wgfZrxyMRZjwsCw+MwO+/hppD2A"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Origin-Agent-Cluster: ?1
Referrer-Policy: no-referrer
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=teqhX3BNxZPfYF9BU1D5RgNCS9M8akFEVvcoMTMcsuM%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766276373"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=teqhX3BNxZPfYF9BU1D5RgNCS9M8akFEVvcoMTMcsuM%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766276373"
Server: Heroku
Set-Cookie: connect.sid=s%3AGlw3qNpPLjfnC-M2vCepWNE2fXsJXGT9.eG5RKTMUKYiLrCI6cvmDMPvdx8OzWen5NnEztjKrfSU; Path=/; HttpOnly
Strict-Transport-Security: max-age=15552000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Xss-Protection: 0
Connection: close
"API ONEWORK"
Open service 76.223.57.73:80 · api.onework.com.br
2025-12-19 04:48
HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Content-Length: 13
Content-Security-Policy: default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';img-src 'self' data:;object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
Content-Type: application/json; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Cross-Origin-Resource-Policy: same-origin
Date: Fri, 19 Dec 2025 04:48:53 GMT
Etag: W/"d-wgfZrxyMRZjwsCw+MwO+/hppD2A"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Origin-Agent-Cluster: ?1
Referrer-Policy: no-referrer
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=iQm0RCh%2B6gfAaq%2FlxGZ9YQb5BkOk7%2F1xtoTd5dRXDVk%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766119733"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=iQm0RCh%2B6gfAaq%2FlxGZ9YQb5BkOk7%2F1xtoTd5dRXDVk%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766119733"
Server: Heroku
Set-Cookie: connect.sid=s%3AOE_yO4wTCBGYP8FNJQQ7KRsXhO-k_XbZ.MVjLaaILhoXlJAGS6VCBR2qGf0T0B5zaHQTJQVZYFiM; Path=/; HttpOnly
Strict-Transport-Security: max-age=15552000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Xss-Protection: 0
Connection: close
"API ONEWORK"