Heroku
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522d40da2d0
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@github.com:somosbob/front-bob.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main
Open service 75.2.97.79:80 · api.somosbob.com
2026-01-10 00:39
HTTP/1.1 500 Internal Server Error
Content-Length: 10
Date: Sat, 10 Jan 2026 00:40:37 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=weZGXpxV4xr%2FQPHm9DD5zW8LPTpBIy7nWoJwte0tDy8%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1768005637"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=weZGXpxV4xr%2FQPHm9DD5zW8LPTpBIy7nWoJwte0tDy8%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1768005637"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Content-Type: text/plain; charset=utf-8
Connection: close
undefined
Open service 13.248.132.87:443 · api.somosbob.com
2026-01-09 16:16
HTTP/1.1 500 Internal Server Error
Content-Length: 10
Date: Fri, 09 Jan 2026 16:16:34 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=PK9gUMamGYpVBPQgANF876sjG8yb8PEQfZVj%2FfhAJ9w%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767975394"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=PK9gUMamGYpVBPQgANF876sjG8yb8PEQfZVj%2FfhAJ9w%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767975394"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Content-Type: text/plain; charset=utf-8
Connection: close
undefined
Open service 75.2.97.79:80 · api.somosbob.com
2026-01-02 19:28
HTTP/1.1 500 Internal Server Error
Content-Length: 10
Date: Fri, 02 Jan 2026 19:28:43 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=H0J11XC9ds%2F5OmHJcCl3bXIBG9AcdXT983lVBCZN7Sk%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767382123"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=H0J11XC9ds%2F5OmHJcCl3bXIBG9AcdXT983lVBCZN7Sk%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767382123"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Content-Type: text/plain; charset=utf-8
Connection: close
undefined
Open service 75.2.97.79:80 · api.somosbob.com
2025-12-23 09:22
HTTP/1.1 500 Internal Server Error
Content-Length: 10
Date: Tue, 23 Dec 2025 09:22:56 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=YjmFAblSsSQhmCNFTSkDBL69XhnRRDEgnkqghyKeCPw%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766481776"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=YjmFAblSsSQhmCNFTSkDBL69XhnRRDEgnkqghyKeCPw%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766481776"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Content-Type: text/plain; charset=utf-8
Connection: close
undefined
Open service 13.248.132.87:443 · api.somosbob.com
2025-12-23 04:34
HTTP/1.1 500 Internal Server Error
Content-Length: 10
Date: Tue, 23 Dec 2025 04:34:23 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=iN3kGld0kf7n1%2BTQ1M1ttvMSDmTgcOSJLDsX14Bhq6M%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766464463"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=iN3kGld0kf7n1%2BTQ1M1ttvMSDmTgcOSJLDsX14Bhq6M%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766464463"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Content-Type: text/plain; charset=utf-8
Connection: close
undefined
Open service 75.2.97.79:80 · api.somosbob.com
2025-12-21 05:33
HTTP/1.1 500 Internal Server Error
Content-Length: 10
Date: Sun, 21 Dec 2025 05:33:28 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=RTn23Um%2B9CgATyMQiSxGNacMMQpTfie5mhkEyn24dkw%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766295208"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=RTn23Um%2B9CgATyMQiSxGNacMMQpTfie5mhkEyn24dkw%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766295208"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Content-Type: text/plain; charset=utf-8
Connection: close
undefined
Open service 13.248.132.87:443 · api.somosbob.com
2025-12-21 02:22
HTTP/1.1 500 Internal Server Error
Content-Length: 10
Date: Sun, 21 Dec 2025 02:22:05 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=YEPFtje4orHsLGmxI99so0WdKvRDGgccz8rrID%2FAvPg%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766283725"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=YEPFtje4orHsLGmxI99so0WdKvRDGgccz8rrID%2FAvPg%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766283725"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Content-Type: text/plain; charset=utf-8
Connection: close
undefined
Open service 75.2.97.79:80 · api.somosbob.com
2025-12-19 07:51
HTTP/1.1 500 Internal Server Error
Content-Length: 10
Date: Fri, 19 Dec 2025 07:51:04 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=B2e%2BrkzBkNmxPftom5zPovS1T81c%2Flm5CB1MQdcJVm0%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766130664"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=B2e%2BrkzBkNmxPftom5zPovS1T81c%2Flm5CB1MQdcJVm0%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766130664"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Content-Type: text/plain; charset=utf-8
Connection: close
undefined
Open service 13.248.132.87:443 · api.somosbob.com
2025-12-19 01:37
HTTP/1.1 500 Internal Server Error
Content-Length: 10
Date: Fri, 19 Dec 2025 01:37:08 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=34WXN7jHknZ70XVwCQZx58FilAqGHKxabsQowm6D7Jo%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766108228"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=34WXN7jHknZ70XVwCQZx58FilAqGHKxabsQowm6D7Jo%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766108228"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Content-Type: text/plain; charset=utf-8
Connection: close
undefined