istio-envoy
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 35.193.113.78:443 · api.tocketicket.cl
2026-01-23 00:35
HTTP/1.1 404 Not Found content-type: text/plain x-trace-id: 10ef866cacc6121bea6c6917ee32e9ed date: Fri, 23 Jan 2026 00:35:48 GMT content-length: 18 x-envoy-upstream-service-time: 0 strict-transport-security: max-age=31536000; includeSubDomains server: istio-envoy connection: close 404 page not found
Open service 35.193.113.78:443 · api.tocketicket.cl
2026-01-10 02:14
HTTP/1.1 404 Not Found content-type: text/plain x-trace-id: 118c8fa3d9d5c5ba7e86741873a6fe6a date: Sat, 10 Jan 2026 02:14:34 GMT content-length: 18 x-envoy-upstream-service-time: 2 strict-transport-security: max-age=31536000; includeSubDomains server: istio-envoy connection: close 404 page not found
Open service 35.193.113.78:443 · api.tocketicket.cl
2026-01-02 23:39
HTTP/1.1 404 Not Found content-type: text/plain x-trace-id: 76593c5e1d851e2794c86bdce8d22b7d date: Fri, 02 Jan 2026 23:39:52 GMT content-length: 18 x-envoy-upstream-service-time: 2 strict-transport-security: max-age=31536000; includeSubDomains server: istio-envoy connection: close 404 page not found
Open service 35.193.113.78:443 · api.tocketicket.cl
2025-12-23 09:51
HTTP/1.1 404 Not Found content-type: text/plain x-trace-id: 3ba8c43de32593a180e2b2607f38b4ae date: Tue, 23 Dec 2025 09:51:00 GMT content-length: 18 x-envoy-upstream-service-time: 1 strict-transport-security: max-age=31536000; includeSubDomains server: istio-envoy connection: close 404 page not found