cloudflare
tcp/443
nginx 1.24.0
tcp/443
nginx 1.28.0
tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 104.21.56.158:443 · chatter.york.pub
2026-01-09 03:20
HTTP/1.1 502 Bad Gateway Date: Fri, 09 Jan 2026 03:20:40 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Referrer-Policy: same-origin X-Frame-Options: SAMEORIGIN Server: cloudflare CF-RAY: 9bb0ccc30ae093d9-LHR alt-svc: h3=":443"; ma=86400 error code: 502
Open service 80.2.110.218:443 · chatter.york.pub
2026-01-07 16:15
HTTP/1.1 502 Bad Gateway Server: nginx/1.24.0 (Ubuntu) Date: Wed, 07 Jan 2026 16:15:23 GMT Content-Type: text/html Content-Length: 166 Connection: close Page title: 502 Bad Gateway <html> <head><title>502 Bad Gateway</title></head> <body> <center><h1>502 Bad Gateway</h1></center> <hr><center>nginx/1.24.0 (Ubuntu)</center> </body> </html>
Open service 80.2.110.218:80 · chatter.york.pub
2026-01-07 16:15
HTTP/1.1 301 Moved Permanently Server: nginx/1.28.0 Date: Wed, 07 Jan 2026 16:15:21 GMT Content-Type: text/html Content-Length: 178 Connection: close Location: https://chatter.york.pub/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.24.0 (Ubuntu)</center> </body> </html>
Open service 104.21.56.158:443 · chatter.york.pub
2026-01-02 02:52
HTTP/1.1 502 Bad Gateway Date: Fri, 02 Jan 2026 02:52:12 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Referrer-Policy: same-origin X-Frame-Options: SAMEORIGIN Server: cloudflare CF-RAY: 9b76f55f9c4ed2a1-FRA alt-svc: h3=":443"; ma=86400 error code: 502
Open service 104.21.56.158:443 · chatter.york.pub
2025-12-22 09:50
HTTP/1.1 200 OK
Date: Mon, 22 Dec 2025 09:50:59 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
x-xss-protection: 1
x-content-type-options: nosniff
x-frame-options: sameorigin
content-security-policy: default-src 'self' ; connect-src *; font-src 'self' data:; frame-src *; img-src * data: blob:; media-src * data:; script-src 'self' 'unsafe-eval' 'sha256-jqxtvDkBbRAl9Hpqv68WdNOieepg8tJSYu1xIy7zT34=' 'sha256-aui5xYk3Lu1dQcnsPlNZI+qDTdfzdUv3fzsw80VLJgw=' ; style-src 'self' 'unsafe-inline'
x-instance-id: 32a09ece-7d89-4428-bdf7-d93e8f035f2c
access-control-allow-origin: *
x-powered-by: Express
vary: Accept-Encoding
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=pAGZnFW1gT94qxoiG%2BAhUi7KEEC5J7na7yg%2FFO2gKJK854s73RiU4YpIRKNCcbklBDsfTwxKxBjZiHUln3OmQnMfSy4kQC5en6mAUyQ5ZW4%3D"}]}
Age: 0
Cache-Control: max-age=14400
cf-cache-status: HIT
last-modified: Mon, 22 Dec 2025 09:50:59 GMT
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="HIT"
Server-Timing: cfEdge;dur=81,cfOrigin;dur=0
CF-RAY: 9b1eb7d7bf347d12-SJC
alt-svc: h3=":443"; ma=86400
Open service 104.21.56.158:443 · chatter.york.pub
2025-12-20 08:19
HTTP/1.1 200 OK
Date: Sat, 20 Dec 2025 08:19:49 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
x-xss-protection: 1
x-content-type-options: nosniff
x-frame-options: sameorigin
content-security-policy: default-src 'self' ; connect-src *; font-src 'self' data:; frame-src *; img-src * data: blob:; media-src * data:; script-src 'self' 'unsafe-eval' 'sha256-jqxtvDkBbRAl9Hpqv68WdNOieepg8tJSYu1xIy7zT34=' 'sha256-aui5xYk3Lu1dQcnsPlNZI+qDTdfzdUv3fzsw80VLJgw=' ; style-src 'self' 'unsafe-inline'
x-instance-id: 32a09ece-7d89-4428-bdf7-d93e8f035f2c
access-control-allow-origin: *
x-powered-by: Express
vary: Accept-Encoding
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=jtLnLOUgRK%2FFUa8vojAaKefE4joV6MVlx3Y2BclCpLz88hfEbKFPhLSbPiUrehK44ZDR1q9p4019710GmnUKkgGcPRUIeRP8GM9GUVn%2FS9c%3D"}]}
Age: 0
Cache-Control: max-age=14400
cf-cache-status: HIT
last-modified: Sat, 20 Dec 2025 08:19:49 GMT
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
CF-RAY: 9b0db78a48a4a06d-FRA
alt-svc: h3=":443"; ma=86400