Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa348e0bdcd233c376f371818e61d312537f683468f
GraphQL introspection enabled at /graphql Types: 318 (by kind: ENUM: 38, INPUT_OBJECT: 38, INTERFACE: 3, OBJECT: 223, SCALAR: 15, UNION: 1) Operations: - Query: Query | fields: admin, countries, creator, creatorByReferralCode, featureFlags - Mutation: Mutation | fields: addFeatureToLeapProduct, confirmSubscription, connectIdentity, createAssistantMessage, createAssistantThread Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa348e0bdcd233c376f371818e61d312537f683468f
GraphQL introspection enabled at /graphql Types: 318 (by kind: ENUM: 38, INPUT_OBJECT: 38, INTERFACE: 3, OBJECT: 223, SCALAR: 15, UNION: 1) Operations: - Query: Query | fields: admin, countries, creator, creatorByReferralCode, featureFlags - Mutation: Mutation | fields: addFeatureToLeapProduct, confirmSubscription, connectIdentity, createAssistantMessage, createAssistantThread Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Open service 13.248.213.92:80 · api.theleap-staging.com
2026-01-09 21:52
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=xin8WosLfZqdY%2B%2BrgdCAt12s%2FlTgGCFkMB4bKwbZBRk%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767995585"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=xin8WosLfZqdY%2B%2BrgdCAt12s%2FlTgGCFkMB4bKwbZBRk%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767995585"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: 669ed28e-505a-9f92-f708-19df0d5db615
X-Runtime: 0.001365
Date: Fri, 09 Jan 2026 21:53:05 GMT
Connection: close
Open service 3.33.241.96:443 · api.theleap-staging.com
2026-01-09 21:52
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=6WU%2Fey4cuyrVrIZr5u2TS9xIWqrM8AH%2FyF4%2BHBYNGmM%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767995524"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=6WU%2Fey4cuyrVrIZr5u2TS9xIWqrM8AH%2FyF4%2BHBYNGmM%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767995524"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: 0260c318-8f1e-7dd7-6a09-ab39ce9f9827
X-Runtime: 0.001358
Date: Fri, 09 Jan 2026 21:52:04 GMT
Connection: close
Open service 76.223.57.73:80 · api.theleap-staging.com
2026-01-04 00:08
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=g22umCyCVp9s1kfN2v9a1ddh3c%2B2ZpM5aSdFZJOpXrE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767485311"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=g22umCyCVp9s1kfN2v9a1ddh3c%2B2ZpM5aSdFZJOpXrE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767485311"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: 150a1a00-3011-ffdc-7b10-89e9a4ac15cc
X-Runtime: 0.001312
Date: Sun, 04 Jan 2026 00:08:31 GMT
Connection: close
Open service 3.33.241.96:80 · api.theleap-staging.com
2026-01-04 00:08
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=g22umCyCVp9s1kfN2v9a1ddh3c%2B2ZpM5aSdFZJOpXrE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767485311"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=g22umCyCVp9s1kfN2v9a1ddh3c%2B2ZpM5aSdFZJOpXrE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767485311"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: 2fa3f386-21f3-9da8-a2c6-2bf11370c45f
X-Runtime: 0.001107
Date: Sun, 04 Jan 2026 00:08:31 GMT
Connection: close
Open service 13.248.213.92:443 · api.theleap-staging.com
2026-01-04 00:08
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=wiJQQLI9ejYSpRzXTw%2BmV3bLsn3VQqe3d9QqYgWpPCw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767485308"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=wiJQQLI9ejYSpRzXTw%2BmV3bLsn3VQqe3d9QqYgWpPCw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767485308"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: 479f65a2-888e-6832-fc4d-0363738f7484
X-Runtime: 0.001321
Date: Sun, 04 Jan 2026 00:08:28 GMT
Connection: close
Open service 15.197.149.68:80 · api.theleap-staging.com
2026-01-04 00:08
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=HGxV4F6N530pTS%2FQpZoCXzcV%2BzA5wyN6P5jKAi2abnI%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767485312"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=HGxV4F6N530pTS%2FQpZoCXzcV%2BzA5wyN6P5jKAi2abnI%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767485312"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: f2b66b9f-a224-b8c0-d246-2c190d838d28
X-Runtime: 0.001345
Date: Sun, 04 Jan 2026 00:08:32 GMT
Connection: close
Open service 3.33.241.96:443 · api.theleap-staging.com
2026-01-04 00:08
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=OTgE6vjjaFuhE3nfX6pnPEoTDkFV0br5OiccNHT28Mc%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767485309"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=OTgE6vjjaFuhE3nfX6pnPEoTDkFV0br5OiccNHT28Mc%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767485309"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: fd3a9729-fcde-7ad6-eefd-86d264075fa8
X-Runtime: 0.026082
Date: Sun, 04 Jan 2026 00:08:29 GMT
Connection: close
Open service 13.248.213.92:80 · api.theleap-staging.com
2026-01-04 00:08
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=g22umCyCVp9s1kfN2v9a1ddh3c%2B2ZpM5aSdFZJOpXrE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767485311"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=g22umCyCVp9s1kfN2v9a1ddh3c%2B2ZpM5aSdFZJOpXrE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767485311"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: bcdcfb8e-61f5-a90b-cc9d-e64cbf2d6ab8
X-Runtime: 0.001158
Date: Sun, 04 Jan 2026 00:08:31 GMT
Connection: close
Open service 15.197.149.68:443 · api.theleap-staging.com
2026-01-04 00:08
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=wiJQQLI9ejYSpRzXTw%2BmV3bLsn3VQqe3d9QqYgWpPCw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767485308"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=wiJQQLI9ejYSpRzXTw%2BmV3bLsn3VQqe3d9QqYgWpPCw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767485308"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: 6d5c37dd-d600-77f3-e289-5527ac514e52
X-Runtime: 0.001408
Date: Sun, 04 Jan 2026 00:08:28 GMT
Connection: close
Open service 13.248.213.92:80 · api.theleap-staging.com
2026-01-02 16:57
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=e4dks8xS83WwuwOO0Ajgpx67ekrosG8JYNHFkW0QMBU%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767373053"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=e4dks8xS83WwuwOO0Ajgpx67ekrosG8JYNHFkW0QMBU%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767373053"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: ec755eb1-67ea-e36d-6221-b81b6f729bcb
X-Runtime: 0.001171
Date: Fri, 02 Jan 2026 16:57:33 GMT
Connection: close
Open service 3.33.241.96:443 · api.theleap-staging.com
2026-01-02 12:34
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=yquz%2BxsyW3oGRXGKS%2F8cxtJ1OiPJk%2FviSlZv2o7oIrE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767357298"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=yquz%2BxsyW3oGRXGKS%2F8cxtJ1OiPJk%2FviSlZv2o7oIrE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767357298"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: 9fbc0a0b-08be-f41f-b1d5-a1df28bfb8f8
X-Runtime: 0.001657
Date: Fri, 02 Jan 2026 12:34:58 GMT
Connection: close
Open service 3.33.241.96:443 · api.theleap-staging.com
2025-12-30 11:36
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=P31n%2BhuYfq9nXuK3iJta5xHhDjJi3wZDt8V4tShZWVA%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767094583"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=P31n%2BhuYfq9nXuK3iJta5xHhDjJi3wZDt8V4tShZWVA%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767094583"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: 58255ae2-2d5c-dc4b-376b-4416bfe5fbfc
X-Runtime: 0.001777
Date: Tue, 30 Dec 2025 11:36:23 GMT
Connection: close
Open service 13.248.213.92:80 · api.theleap-staging.com
2025-12-23 02:11
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=YuIw%2FRGZNZuEJgOTBMGVxlr2PTVueo19jzCaIEnxMFQ%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766455881"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=YuIw%2FRGZNZuEJgOTBMGVxlr2PTVueo19jzCaIEnxMFQ%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766455881"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: 2662e5d5-6969-6842-823e-a66056c5d3d3
X-Runtime: 0.001515
Date: Tue, 23 Dec 2025 02:11:21 GMT
Connection: close
Open service 3.33.241.96:443 · api.theleap-staging.com
2025-12-22 10:53
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2FJv%2Fb64OWmyL%2FwNwGUUI0g8olWMEM7tvVxyHygtb9V0%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766400815"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2FJv%2Fb64OWmyL%2FwNwGUUI0g8olWMEM7tvVxyHygtb9V0%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766400815"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: 294bfa48-5540-1a7d-fc1c-171a0d767254
X-Runtime: 0.001307
Date: Mon, 22 Dec 2025 10:53:35 GMT
Connection: close
Open service 3.33.241.96:443 · api.theleap-staging.com
2025-12-21 05:11
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=7J5zgwJs4%2FtqcyFICKpguE8fgyB0tcS9HpHtPvknXV0%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766293864"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=7J5zgwJs4%2FtqcyFICKpguE8fgyB0tcS9HpHtPvknXV0%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766293864"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: f3683bae-a4ca-fad2-69fe-65eefeedf3d0
X-Runtime: 0.001393
Date: Sun, 21 Dec 2025 05:11:04 GMT
Connection: close
Open service 13.248.213.92:80 · api.theleap-staging.com
2025-12-20 14:33
HTTP/1.1 404 Not Found
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=uqXuohC9HrWaUQ1nvmqL1WGX3vUz4dWI1yCtkWeCmvc%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766241222"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=uqXuohC9HrWaUQ1nvmqL1WGX3vUz4dWI1yCtkWeCmvc%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766241222"
Server: Heroku
Via: 1.1 heroku-router
X-Request-Id: 3d71c18e-431d-5e54-1d8d-477b202e5ba0
X-Runtime: 0.001633
Date: Sat, 20 Dec 2025 14:33:42 GMT
Connection: close