Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 95.100.110.18:443 · databand-internal-stg-develop.databand.ai
2026-01-23 07:43
HTTP/1.1 302 Moved Temporarily Content-Type: text/html; charset=utf-8 Content-Length: 195 Location: /app X-Robots-Tag: noindex, nofollow Permissions-Policy: geolocation=() X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Content-Security-Policy: default-src 'self'; frame-src https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self'; object-src 'none'; style-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; font-src https://1.www.s81c.com 'self' data:; worker-src 'self' blob:; img-src https://*.googletagmanager.com https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io https://www.gravatar.com 'self' data:; script-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; script-src-elem https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; connect-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin X-INSTANA-L: 1 traceparent: 00-000000000000000025f5ecfcd8bae4b3-25f5ecfcd8bae4b3-01 tracestate: in=25f5ecfcd8bae4b3;25f5ecfcd8bae4b3 X-INSTANA-T: 25f5ecfcd8bae4b3 X-INSTANA-S: 25f5ecfcd8bae4b3 Server-Timing: intid;desc=25f5ecfcd8bae4b3 Expires: Fri, 23 Jan 2026 07:43:02 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 23 Jan 2026 07:43:02 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Set-Cookie: X-CSRF-TOKEN=ImU1ODI1NjhiYzlmNTU1YjBkNTZiZmNmZDNkNWUyNzExMmNmNTlkYmYi.aXMmhg.P_5jR0SJ_uKWwhv0JuzLkpBTLvA; Expires=Fri, 23 Jan 2026 08:43:02 GMT; Max-Age=3600; Secure; Path=/; SameSite=Lax Set-Cookie: dbnd_session=86582e8a-5e0d-4c21-8381-f23c2e74c2be; Expires=Fri, 23 Jan 2026 08:43:02 GMT; Secure; HttpOnly; Path=/; SameSite=Lax Page title: Redirecting... <!doctype html> <html lang=en> <title>Redirecting...</title> <h1>Redirecting...</h1> <p>You should be redirected automatically to the target URL: <a href="/app">/app</a>. If not, click the link.
Open service 95.100.110.18:443 · databand-internal-stg-develop.databand.ai
2026-01-09 11:41
HTTP/1.1 302 Moved Temporarily Content-Type: text/html; charset=utf-8 Content-Length: 195 Location: /app X-Robots-Tag: noindex, nofollow Permissions-Policy: geolocation=() X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Content-Security-Policy: default-src 'self'; frame-src https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self'; object-src 'none'; style-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; font-src https://1.www.s81c.com 'self' data:; worker-src 'self' blob:; img-src https://*.googletagmanager.com https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io https://www.gravatar.com 'self' data:; script-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; script-src-elem https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; connect-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin X-INSTANA-L: 1 traceparent: 00-0000000000000000c5d3daef61fc5891-c5d3daef61fc5891-01 tracestate: in=c5d3daef61fc5891;c5d3daef61fc5891 X-INSTANA-T: c5d3daef61fc5891 X-INSTANA-S: c5d3daef61fc5891 Server-Timing: intid;desc=c5d3daef61fc5891 Expires: Fri, 09 Jan 2026 11:41:18 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 11:41:18 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Set-Cookie: X-CSRF-TOKEN=IjEwYWUyYWNiYWU4OWQ4YmZjZWFmZjJkOWJiMzgyYjUyMGFjYzEwYjIi.aWDpXg.R3nAOr2UgiVI8bJyy-3sBD7CRsc; Expires=Fri, 09 Jan 2026 12:41:18 GMT; Max-Age=3600; Secure; Path=/; SameSite=Lax Set-Cookie: dbnd_session=99b6540d-3ec8-42e7-80a0-b9b10dcea2c4; Expires=Fri, 09 Jan 2026 12:41:18 GMT; Secure; HttpOnly; Path=/; SameSite=Lax Page title: Redirecting... <!doctype html> <html lang=en> <title>Redirecting...</title> <h1>Redirecting...</h1> <p>You should be redirected automatically to the target URL: <a href="/app">/app</a>. If not, click the link.
Open service 95.100.110.18:443 · databand-internal-stg-develop.databand.ai
2026-01-02 16:35
HTTP/1.1 302 Moved Temporarily Content-Type: text/html; charset=utf-8 Content-Length: 195 Location: /app X-Robots-Tag: noindex, nofollow Permissions-Policy: geolocation=() X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Content-Security-Policy: default-src 'self'; frame-src https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self'; object-src 'none'; style-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; font-src https://1.www.s81c.com 'self' data:; worker-src 'self' blob:; img-src https://*.googletagmanager.com https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io https://www.gravatar.com 'self' data:; script-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; script-src-elem https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; connect-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin X-INSTANA-L: 1 traceparent: 00-00000000000000001cc00a1350bf96f4-1cc00a1350bf96f4-01 tracestate: in=1cc00a1350bf96f4;1cc00a1350bf96f4 X-INSTANA-T: 1cc00a1350bf96f4 X-INSTANA-S: 1cc00a1350bf96f4 Server-Timing: intid;desc=1cc00a1350bf96f4 Expires: Fri, 02 Jan 2026 16:35:29 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 16:35:29 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Set-Cookie: X-CSRF-TOKEN=IjU3ZmYxYWRhODM2NmI0NDI3YjhiOWY4OGE1NTQ1OTQzZjZkMWU0MDAi.aVfz0Q.EGslE8Wmjqx08lcjx95m06I_FGE; Expires=Fri, 02 Jan 2026 17:35:29 GMT; Max-Age=3600; Secure; Path=/; SameSite=Lax Set-Cookie: dbnd_session=35be300e-fcce-4acd-b7bc-59825d1de783; Expires=Fri, 02 Jan 2026 17:35:29 GMT; Secure; HttpOnly; Path=/; SameSite=Lax Page title: Redirecting... <!doctype html> <html lang=en> <title>Redirecting...</title> <h1>Redirecting...</h1> <p>You should be redirected automatically to the target URL: <a href="/app">/app</a>. If not, click the link.
Open service 95.100.110.18:443 · databand-internal-stg-develop.databand.ai
2025-12-23 02:03
HTTP/1.1 302 Moved Temporarily Content-Type: text/html; charset=utf-8 Content-Length: 195 Location: /app X-Robots-Tag: noindex, nofollow Permissions-Policy: geolocation=() X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Content-Security-Policy: default-src 'self'; frame-src https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self'; object-src 'none'; style-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; font-src https://1.www.s81c.com 'self' data:; worker-src 'self' blob:; img-src https://*.googletagmanager.com https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io https://www.gravatar.com 'self' data:; script-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; script-src-elem https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; connect-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin X-INSTANA-L: 1 traceparent: 00-0000000000000000344378ecef3f8689-344378ecef3f8689-01 tracestate: in=344378ecef3f8689;344378ecef3f8689 X-INSTANA-T: 344378ecef3f8689 X-INSTANA-S: 344378ecef3f8689 Server-Timing: intid;desc=344378ecef3f8689 Expires: Tue, 23 Dec 2025 02:03:56 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 02:03:56 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Set-Cookie: X-CSRF-TOKEN=IjU0ZDRjOGI0NzlmMWRjYjlkMWVmZDBhODE1OGY4NDQzOTI4ODU2YTci.aUn4jA.6rO7ptCsZtpAu1Ubq7pzv9Q71i8; Expires=Tue, 23 Dec 2025 03:03:56 GMT; Max-Age=3600; Secure; Path=/; SameSite=Lax Set-Cookie: dbnd_session=8ea3c1a2-3a1c-4ed7-85ff-b88d13b66558; Expires=Tue, 23 Dec 2025 03:03:56 GMT; Secure; HttpOnly; Path=/; SameSite=Lax Page title: Redirecting... <!doctype html> <html lang=en> <title>Redirecting...</title> <h1>Redirecting...</h1> <p>You should be redirected automatically to the target URL: <a href="/app">/app</a>. If not, click the link.