Heroku
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 15.197.129.158:80 · api.pokerbunch.com
2026-01-08 22:49
HTTP/1.1 302 Found
Content-Length: 0
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; img-src 'self' data:; style-src 'self' 'unsafe-inline'
Date: Thu, 08 Jan 2026 22:50:30 GMT
Location: /swagger/index.html
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=eRHqyrJlMSco89vb7ISwPcqzL4uX1Egfu9jid2ETvtw%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767912631"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=eRHqyrJlMSco89vb7ISwPcqzL4uX1Egfu9jid2ETvtw%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767912631"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 1; mode=block
Connection: close
Open service 76.223.11.49:443 · api.pokerbunch.com
2026-01-08 22:25
HTTP/1.1 302 Found
Content-Length: 0
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; img-src 'self' data:; style-src 'self' 'unsafe-inline'
Date: Thu, 08 Jan 2026 22:25:30 GMT
Location: /swagger/index.html
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=3be2GRX2%2BgsUZS1RlYh3UR%2F66a%2Bp%2BVE6N4pDxjgJFaI%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767911130"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=3be2GRX2%2BgsUZS1RlYh3UR%2F66a%2Bp%2BVE6N4pDxjgJFaI%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767911130"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 1; mode=block
Connection: close
Open service 76.223.11.49:443 · api.pokerbunch.com
2026-01-02 11:25
HTTP/1.1 302 Found
Content-Length: 0
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; img-src 'self' data:; style-src 'self' 'unsafe-inline'
Date: Fri, 02 Jan 2026 11:25:00 GMT
Location: /swagger/index.html
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=4Z0pcRTroDH0PaIcLwH6JlA0bf71nofx4vFmHLkZnAI%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767353101"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=4Z0pcRTroDH0PaIcLwH6JlA0bf71nofx4vFmHLkZnAI%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767353101"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 1; mode=block
Connection: close
Open service 15.197.129.158:80 · api.pokerbunch.com
2025-12-30 06:30
HTTP/1.1 302 Found
Content-Length: 0
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; img-src 'self' data:; style-src 'self' 'unsafe-inline'
Date: Tue, 30 Dec 2025 06:30:22 GMT
Location: /swagger/index.html
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=kgSqyA%2FEVoIkJ2DXT5htHtGLOKEpDHkq%2FvhzlEIqmFg%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767076222"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=kgSqyA%2FEVoIkJ2DXT5htHtGLOKEpDHkq%2FvhzlEIqmFg%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767076222"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 1; mode=block
Connection: close
Open service 76.223.11.49:443 · api.pokerbunch.com
2025-12-22 15:11
HTTP/1.1 302 Found
Content-Length: 0
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; img-src 'self' data:; style-src 'self' 'unsafe-inline'
Date: Mon, 22 Dec 2025 15:11:20 GMT
Location: /swagger/index.html
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=FTrnwMQmv5m9kBooMcKRM%2BrIb%2F5N5J8ZqHY1l8NgPqs%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766416280"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=FTrnwMQmv5m9kBooMcKRM%2BrIb%2F5N5J8ZqHY1l8NgPqs%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766416280"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 1; mode=block
Connection: close
Open service 15.197.129.158:80 · api.pokerbunch.com
2025-12-22 15:11
HTTP/1.1 302 Found
Content-Length: 0
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; img-src 'self' data:; style-src 'self' 'unsafe-inline'
Date: Mon, 22 Dec 2025 15:11:23 GMT
Location: /swagger/index.html
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=cPkJDacYoJtW4uT0Fw4oYRvEj859X%2B31UVd5vzroqBI%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766416284"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=cPkJDacYoJtW4uT0Fw4oYRvEj859X%2B31UVd5vzroqBI%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766416284"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 1; mode=block
Connection: close
Open service 15.197.129.158:80 · api.pokerbunch.com
2025-12-20 11:24
HTTP/1.1 302 Found
Content-Length: 0
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; img-src 'self' data:; style-src 'self' 'unsafe-inline'
Date: Sat, 20 Dec 2025 11:24:17 GMT
Location: /swagger/index.html
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2FM90Pp8Lm3uXMyN9uyFukuci4rj0Izy5mmGEKWfy4gA%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766229857"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2FM90Pp8Lm3uXMyN9uyFukuci4rj0Izy5mmGEKWfy4gA%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766229857"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 1; mode=block
Connection: close
Open service 76.223.11.49:443 · api.pokerbunch.com
2025-12-20 11:24
HTTP/1.1 302 Found
Content-Length: 0
Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline'; img-src 'self' data:; style-src 'self' 'unsafe-inline'
Date: Sat, 20 Dec 2025 11:24:13 GMT
Location: /swagger/index.html
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=b66rZD%2FRyPI0xBCRLl05i6T0DzaDLT8EOckr0IA6JJY%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766229853"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=b66rZD%2FRyPI0xBCRLl05i6T0DzaDLT8EOckr0IA6JJY%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766229853"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 1; mode=block
Connection: close