Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 142.250.201.83:80 · cpa-api.causeway.com
2026-02-08 08:25
HTTP/1.1 302 Found location: https://cpa-api.causeway.com/ x-cloud-trace-context: 9a3a87ef282ecf37ea1b53ebecd1c986 date: Sun, 08 Feb 2026 08:25:45 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 2a00:1450:4001:806::2013:80 · cpa-api.causeway.com
2026-02-08 08:25
HTTP/1.1 302 Found location: https://cpa-api.causeway.com/ x-cloud-trace-context: 7d50f0fa2f68d263c2d8fba1f077f127;o=1 date: Sun, 08 Feb 2026 08:25:45 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 142.250.185.147:443 · cpa-api.causeway.com
2026-01-23 14:18
HTTP/1.1 200 OK x-correlation-id: 9e2e5451-dfec-43ce-a06e-092193195260 x-api-metrics: Total:4.403ms; nonspecific_httprequest:4.403ms; x-cloud-trace-context: 17b718cb18918e8e97ae8bf27db622ec date: Fri, 23 Jan 2026 14:18:07 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 142.250.185.147:443 · cpa-api.causeway.com
2026-01-09 18:29
HTTP/1.1 200 OK x-correlation-id: c5b1ee19-fe52-4db7-a6a0-3067808d6b48 x-api-metrics: Total:0.609ms; nonspecific_httprequest:0.609ms; x-cloud-trace-context: f6a4eb13964dc6d71377d479350256f5 date: Fri, 09 Jan 2026 18:29:03 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 142.250.185.147:443 · cpa-api.causeway.com
2026-01-02 21:57
HTTP/1.1 200 OK x-correlation-id: dcc7babc-ddd4-4d67-9533-585c3602f049 x-api-metrics: Total:0.336ms; nonspecific_httprequest:0.336ms; x-cloud-trace-context: 48cb54e146ba635a624547b987c629ef date: Fri, 02 Jan 2026 21:57:43 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 142.250.185.147:443 · cpa-api.causeway.com
2025-12-23 04:17
HTTP/1.1 200 OK x-correlation-id: 6aaeeb33-0352-45b9-ad2f-cb729284587a x-api-metrics: Total:0.387ms; nonspecific_httprequest:0.387ms; x-cloud-trace-context: eaa196a514746b9eb49d00e5a759a514 date: Tue, 23 Dec 2025 04:17:12 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close