Heroku
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 99.83.151.71:443 · app-staging.parentbirth.com
2025-12-20 07:06
HTTP/1.1 503 Service Unavailable
Cache-Control: no-cache, no-store
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=ZE4nqsFVjIMvLJBvpVFA0GvxdySA4nV%2BtMEEhiReV8g%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766214391"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=ZE4nqsFVjIMvLJBvpVFA0GvxdySA4nV%2BtMEEhiReV8g%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766214391"
Server: Heroku
Via: 1.1 heroku-router
Date: Sat, 20 Dec 2025 07:06:31 GMT
Content-Length: 567
Connection: close
Page title: Application Error
<!DOCTYPE html>
<html>
<head>
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta charset="utf-8">
<title>Application Error</title>
<style media="screen">
html,body,iframe {
margin: 0;
padding: 0;
}
html,body {
height: 100%;
overflow: hidden;
}
iframe {
width: 100%;
height: 100%;
border: 0;
}
</style>
</head>
<body>
<iframe src="https://www.herokucdn.com/error-pages/application-error.html"></iframe>
</body>
</html>
Open service 75.2.97.79:80 · app-staging.parentbirth.com
2025-12-20 07:06
HTTP/1.1 503 Service Unavailable
Cache-Control: no-cache, no-store
Content-Type: text/html; charset=utf-8
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=zooMMXZp4UvOxNgNdDdi0eFKmgFy1H4nzseYWYgFiHk%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766214394"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=zooMMXZp4UvOxNgNdDdi0eFKmgFy1H4nzseYWYgFiHk%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766214394"
Server: Heroku
Via: 1.1 heroku-router
Date: Sat, 20 Dec 2025 07:06:34 GMT
Content-Length: 567
Connection: close
Page title: Application Error
<!DOCTYPE html>
<html>
<head>
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta charset="utf-8">
<title>Application Error</title>
<style media="screen">
html,body,iframe {
margin: 0;
padding: 0;
}
html,body {
height: 100%;
overflow: hidden;
}
iframe {
width: 100%;
height: 100%;
border: 0;
}
</style>
</head>
<body>
<iframe src="https://www.herokucdn.com/error-pages/application-error.html"></iframe>
</body>
</html>