Caddy
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff43714a58ce1e10bc88da3aa79aedf3b7272baecef9
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /
GET /.well-known/live
GET /.well-known/openid-configuration
GET /.well-known/ready
GET /backups/{backend}/{id}
GET /backups/{backend}/{id}/restore
GET /classifications/{id}
GET /meta
GET /nodes
GET /nodes/{className}
GET /objects
GET /objects/{className}/{id}
GET /objects/{id}
GET /schema
GET /schema/cluster-status
GET /schema/{className}
GET /schema/{className}/shards
GET /schema/{className}/tenants
HEAD /schema/{className}/tenants/{tenantName}
POST /backups/{backend}
POST /batch/objects
POST /batch/references
POST /classifications/
POST /graphql
POST /graphql/batch
POST /objects/validate
POST /objects/{className}/{id}/references/{propertyName}
POST /objects/{id}/references/{propertyName}
POST /schema/{className}/properties
PUT /schema/{className}/shards/{shardName}
Open service 35.246.197.197:443 · ars-ai-api-db.functn.com
2026-01-08 20:37
HTTP/1.1 301 Moved Permanently
Alt-Svc: h3=":443"; ma=2592000
Content-Length: 111
Content-Type: text/plain; charset=utf-8
Date: Thu, 08 Jan 2026 20:37:57 GMT
Location: /v1
Server: Caddy
Connection: close
{"links":{"href":"/v1","name":"api v1","documentationHref":"https://weaviate.io/developers/weaviate/current/"}}
Open service 35.246.197.197:443 · ars-ai-api-db.functn.com
2026-01-03 06:09
HTTP/1.1 301 Moved Permanently
Alt-Svc: h3=":443"; ma=2592000
Content-Length: 111
Content-Type: text/plain; charset=utf-8
Date: Sat, 03 Jan 2026 06:09:53 GMT
Location: /v1
Server: Caddy
Connection: close
{"links":{"href":"/v1","name":"api v1","documentationHref":"https://weaviate.io/developers/weaviate/current/"}}
Open service 35.246.197.197:80 · ars-ai-api-db.functn.com
2026-01-03 06:09
HTTP/1.1 308 Permanent Redirect Connection: close Location: https://ars-ai-api-db.functn.com/ Server: Caddy Date: Sat, 03 Jan 2026 06:09:53 GMT Content-Length: 0
Open service 35.246.197.197:443 · ars-ai-api-db.functn.com
2026-01-02 02:51
HTTP/1.1 301 Moved Permanently
Alt-Svc: h3=":443"; ma=2592000
Content-Length: 111
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 02:51:07 GMT
Location: /v1
Server: Caddy
Connection: close
{"links":{"href":"/v1","name":"api v1","documentationHref":"https://weaviate.io/developers/weaviate/current/"}}
Open service 35.246.197.197:443 · ars-ai-api-db.functn.com
2025-12-22 09:57
HTTP/1.1 301 Moved Permanently
Alt-Svc: h3=":443"; ma=2592000
Content-Length: 111
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 09:57:46 GMT
Location: /v1
Server: Caddy
Connection: close
{"links":{"href":"/v1","name":"api v1","documentationHref":"https://weaviate.io/developers/weaviate/current/"}}