Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549e8d97bb70493dbcbed0d93ebed0d93ebed0d93eb
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /.well-known/keys
GET /.well-known/openid-configuration
POST /api/Signing/{clientId}
Open service 2a02:26f0:7100::210:1f9:443 · dev-cachingapiissuer.csp-digital.com
2026-01-09 14:09
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 09 Jan 2026 14:09:14 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 14:09:14 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=14 Server-Timing: origin; dur=5 Server-Timing: ak_p; desc="1767967753672_34603509_587324270_1819_15194_146_305_-";dur=1
Open service 2a02:26f0:7100::210:1f9:80 · dev-cachingapiissuer.csp-digital.com
2026-01-09 14:09
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://dev-cachingapiissuer.csp-digital.com Expires: Fri, 09 Jan 2026 14:09:53 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 14:09:53 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=17 Server-Timing: origin; dur=4 Server-Timing: ak_p; desc="1767967793736_34603509_587361148_2081_13101_1_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2.16.204.81:443 · dev-cachingapiissuer.csp-digital.com
2026-01-09 14:09
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 09 Jan 2026 14:09:14 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 14:09:14 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=12 Server-Timing: origin; dur=22 Server-Timing: ak_p; desc="1767967753777_34610513_397554637_3393_10339_148_310_-";dur=1
Open service 2a02:26f0:7100::210:1d2:443 · dev-cachingapiissuer.csp-digital.com
2026-01-09 14:09
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 09 Jan 2026 14:09:13 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 14:09:13 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=13 Server-Timing: origin; dur=37 Server-Timing: ak_p; desc="1767967753623_34603509_587324212_4985_13785_150_306_-";dur=1
Open service 2.16.204.78:80 · dev-cachingapiissuer.csp-digital.com
2026-01-09 14:09
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://dev-cachingapiissuer.csp-digital.com Expires: Fri, 09 Jan 2026 14:09:54 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 14:09:54 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=36 Server-Timing: origin; dur=1 Server-Timing: ak_p; desc="1767967794929_34610510_139186197_3763_12282_148_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a02:26f0:7100::210:1d2:80 · dev-cachingapiissuer.csp-digital.com
2026-01-09 14:09
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://dev-cachingapiissuer.csp-digital.com Expires: Fri, 09 Jan 2026 14:09:54 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 14:09:54 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=23 Server-Timing: origin; dur=19 Server-Timing: ak_p; desc="1767967794517_34603470_394191520_4216_17817_101_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2.16.204.81:80 · dev-cachingapiissuer.csp-digital.com
2026-01-09 14:09
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://dev-cachingapiissuer.csp-digital.com Expires: Fri, 09 Jan 2026 14:09:54 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 14:09:54 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=49 Server-Timing: origin; dur=24 Server-Timing: ak_p; desc="1767967794481_34610513_397611438_7248_9709_88_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2.16.204.78:443 · dev-cachingapiissuer.csp-digital.com
2026-01-09 14:09
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 09 Jan 2026 14:09:13 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 14:09:13 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=12 Server-Timing: origin; dur=4 Server-Timing: ak_p; desc="1767967753304_34610513_397553837_1662_9953_96_198_-";dur=1
Open service 23.213.161.223:443 · dev-cachingapiissuer.csp-digital.com
2026-01-09 06:16
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 09 Jan 2026 06:16:12 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 06:16:12 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=30 Server-Timing: origin; dur=3 Server-Timing: ak_p; desc="1767939372169_399876319_3775342157_3313_9526_160_331_-";dur=1
Open service 23.213.161.223:443 · dev-cachingapiissuer.csp-digital.com
2026-01-02 04:19
HTTP/1.1 504 Gateway Time-out Mime-Version: 1.0 Content-Type: text/html Content-Length: 280 Expires: Fri, 02 Jan 2026 04:19:29 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 04:19:29 GMT Connection: close Server-Timing: edge; dur=10022 Server-Timing: origin; dur=11 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767327559292_399876319_1280527365_1003210_8232_150_359_-";dur=1 Page title: Error <HTML><HEAD><TITLE>Error</TITLE></HEAD><BODY> An error occurred while processing your request.<p> Reference #97.dfa0d517.1767327559.4c534c05 <P>https://errors.edgesuite.net/97.dfa0d517.1767327559.4c534c05</P> </BODY></HTML>
Open service 23.213.161.223:443 · dev-cachingapiissuer.csp-digital.com
2025-12-22 19:21
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Mon, 22 Dec 2025 19:21:21 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 22 Dec 2025 19:21:21 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=11 Server-Timing: origin; dur=2 Server-Timing: ak_p; desc="1766431281294_399876319_1935565851_1276_11330_85_177_-";dur=1