Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1926e27d0926e27d0926e27d0926e27d0926e27d0926e27d0
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html
Open service 217.169.130.138:443 · api.pb-santander.com
2026-01-23 01:21
HTTP/1.1 500
Date: Fri, 23 Jan 2026 01:21:15 GMT
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Cache-Control: no-cache;no-store;must-revalidate;private;max-age=0
Content-Security-Policy: default-src 'self';
vary: Origin,Access-Control-Request-Method,Access-Control-Request-Headers
content-type: application/json
set-cookie: 0fcd6cdd99c32f308c66b28b0789c09a=902eba56a7b351847ec7ff1b51d8c752; path=/; HttpOnly; Secure; SameSite=None;HttpOnly;Secure;SameSite=Strict
Connection: close
X-Frame-Options: SAMEORIGIN
Strict-Transport-Policy: timeout
Set-Cookie: TS01370017=0196082627bf5fbc8769fe6430fc8b30445694478b9428d8e90cb21406fbd5df007ddfecea92ba1a1882e5cbd392857cd44989c819e4c090367fea447d35076001a41f76dd; Path=/; Secure; HttpOnly
Transfer-Encoding: chunked
{"traceId":"bf5a3d13-e092-467a-b0d3-559b9c39493c","rewrittenPath":"","originalPath":"/","error":"Internal Server Error","message":"404 NOT_FOUND No static resource .","status":500}
Open service 217.169.130.138:443 · api.pb-santander.com
2026-01-09 07:32
HTTP/1.1 500
Date: Fri, 09 Jan 2026 07:32:08 GMT
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Cache-Control: no-cache;no-store;must-revalidate;private;max-age=0
Content-Security-Policy: default-src 'self';
vary: Origin,Access-Control-Request-Method,Access-Control-Request-Headers
content-type: application/json
set-cookie: 0fcd6cdd99c32f308c66b28b0789c09a=7a6c84b385100ebab29123a334373011; path=/; HttpOnly; Secure; SameSite=None
Connection: close
X-Frame-Options: SAMEORIGIN
Strict-Transport-Policy: timeout
Set-Cookie: TS01370017=019608262756eacade7594d9ffdd4d87a0853e03b63d7cc4c448dfc11083709e6f2c8cd832cbf1a18618d58b1188b042f36876d22445ecd2f0b0c4d21597587bebbf778cdf; Path=/; Secure; HttpOnly
Transfer-Encoding: chunked
{"traceId":"ebf45dfb-85a9-49f1-8aa2-37f2b2dff34b","rewrittenPath":"","originalPath":"/","error":"Internal Server Error","message":"404 NOT_FOUND No static resource .","status":500}
Open service 217.169.130.138:443 · api.pb-santander.com
2026-01-02 07:23
HTTP/1.1 500
Date: Fri, 02 Jan 2026 07:23:00 GMT
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Cache-Control: no-cache;no-store;must-revalidate;private;max-age=0
Content-Security-Policy: default-src 'self';
vary: Origin,Access-Control-Request-Method,Access-Control-Request-Headers
content-type: application/json
set-cookie: 0fcd6cdd99c32f308c66b28b0789c09a=7a6c84b385100ebab29123a334373011; path=/; HttpOnly; Secure; SameSite=None
Connection: close
X-Frame-Options: SAMEORIGIN
Strict-Transport-Policy: timeout
Set-Cookie: TS01370017=0196082627f33907e1bcb3e497e964622bf8a0ef4d3ac976279f9ce6e970d231b931565081980689b96fe6a26afba80b124c986368174089e8dd15271a4d46846dc732cbb9; Path=/; Secure; HttpOnly
Transfer-Encoding: chunked
{"traceId":"c8a1637f-b61f-42bc-945d-697c5a82490f","rewrittenPath":"","originalPath":"/","error":"Internal Server Error","message":"404 NOT_FOUND No static resource .","status":500}
Open service 217.169.130.138:443 · api.pb-santander.com
2025-12-23 03:37
HTTP/1.1 500
Date: Tue, 23 Dec 2025 03:37:33 GMT
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
Strict-Transport-Security: max-age=31536000; includeSubDomains
Cache-Control: no-cache;no-store;must-revalidate;private;max-age=0
Content-Security-Policy: default-src 'self';
vary: Origin,Access-Control-Request-Method,Access-Control-Request-Headers
content-type: application/json
set-cookie: 0fcd6cdd99c32f308c66b28b0789c09a=228f884869a689fa3de9bab232886432; path=/; HttpOnly; Secure; SameSite=None
Connection: close
X-Frame-Options: SAMEORIGIN
Strict-Transport-Policy: timeout
Set-Cookie: TS01370017=01960826271f85c522c9213c2d0fceb1263c6db7b5d1826ebf7f81ee829485dbfb27fea77855585819b5dff28008d2392f5f9a97d40b8f390f69505f462aa7ab5b2f7e1f73; Path=/; Secure; HttpOnly
Transfer-Encoding: chunked
{"traceId":"6c4d712a-172f-4444-b93a-94e1d9db383d","rewrittenPath":"","originalPath":"/","error":"Internal Server Error","message":"404 NOT_FOUND No static resource .","status":500}