cloudflare
tcp/443 tcp/80 tcp/8443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 172.66.0.125:443 · dev-contentapi.pwtcxstest.com
2026-01-23 13:53
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 13:53:26 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Server: cloudflare CF-Ray: 9c27c6fdbfa255fc-SIN CF-Cache-Status: HIT Age: 1 Last-Modified: Fri, 23 Jan 2026 13:53:25 GMT Strict-Transport-Security: max-age=2592000 Vary: Accept-Encoding uc-cache-status: HIT, min-ttl=60, ttl=1800 x-powered-by: ASP.NET Set-Cookie: __cf_bm=IOq7nuKV7idsVUJUlNqTFc3g2VZEdyo0oi59vTEVg7Y-1769176406-1.0.1.1-fh8q_w2jIbtTfdCcNBkyEt7B6Zw7aX2nbeWH8yiatX_ca90xTMuF8JZXmIKaLtlwiklmEqQB88iHkNYFEydjZWzU37xpk_jwa9q9tG3ScRc; path=/; expires=Fri, 23-Jan-26 14:23:26 GMT; domain=.dev-contentapi.pwtcxstest.com; HttpOnly; Secure; SameSite=None alt-svc: h3=":443"; ma=86400 <h1>Nothing to see here</h1>
Open service 2a06:98c1:58::7d:80 · dev-contentapi.pwtcxstest.com
2026-01-23 11:15
HTTP/1.1 301 Moved Permanently Date: Fri, 23 Jan 2026 11:15:37 GMT Content-Type: text/html Content-Length: 167 Connection: close Cache-Control: max-age=3600 Expires: Fri, 23 Jan 2026 12:15:37 GMT Location: https://dev-contentapi.pwtcxstest.com/ Set-Cookie: __cf_bm=p4q7fE2.Mp7iRF6RpGR30dJ.45ubrDlSaDMsj_Az2Zg-1769166937-1.0.1.1-L0.bSNV3UuGv7W1g.R_H1cW_T6hbcdp1Eet7terxHDO2bu4CByB1YLs1oN52bIomqbosKjS6Q1JbxVXqYcEAo1YIN7N7sPLdNVticlOYpHg; path=/; expires=Fri, 23-Jan-26 11:45:37 GMT; domain=.dev-contentapi.pwtcxstest.com; HttpOnly Server: cloudflare CF-RAY: 9c26dfcf6e78932c-EWR alt-svc: h3=":443"; ma=86400 Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>cloudflare</center> </body> </html>
Open service 2606:4700:7::7d:8443 · dev-contentapi.pwtcxstest.com
2026-01-23 11:15
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 11:15:37 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Server: cloudflare CF-Ray: 9c26dfcf7af4b669-FRA CF-Cache-Status: HIT Age: 1 Last-Modified: Fri, 23 Jan 2026 11:15:36 GMT Strict-Transport-Security: max-age=2592000 Vary: Accept-Encoding uc-cache-status: HIT, min-ttl=60, ttl=1800 x-powered-by: ASP.NET Set-Cookie: __cf_bm=RvgW0kDfioTadsuc3sX8Jhi96rt48l2SHK1Kv8xN_Vc-1769166937-1.0.1.1-gsXcGFiM_FFnkbwC4p0u8d_G6p_XgApYzCWY50bRbYWICGkMPAD1LxtKlEtCrRZ4O5tAENoHiOVabL1V5orxvNXRYwxOJL3ba0Gaxxykqq0; path=/; expires=Fri, 23-Jan-26 11:45:37 GMT; domain=.dev-contentapi.pwtcxstest.com; HttpOnly; Secure; SameSite=None alt-svc: h3=":8443"; ma=86400 <h1>Nothing to see here</h1>
Open service 2606:4700:7::7d:443 · dev-contentapi.pwtcxstest.com
2026-01-23 11:15
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 11:15:37 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Server: cloudflare CF-Ray: 9c26dfcf49105ada-FRA CF-Cache-Status: HIT Age: 1 Last-Modified: Fri, 23 Jan 2026 11:15:36 GMT Strict-Transport-Security: max-age=2592000 Vary: Accept-Encoding uc-cache-status: HIT, min-ttl=60, ttl=1800 x-powered-by: ASP.NET Set-Cookie: __cf_bm=VTjRu6qzl_7GBvtpJFMAOVRitHldrm2p1cpYRdFKWc4-1769166937-1.0.1.1-L5eh2I4ejZci.lmXEKMsjFZLaTjCR4tRE5OTS.Gxcu13uOr2LevEh7usxIZL5Gve.vZGd6hK64g7liEve6PDGH_FwLTQVgzyROP8GgMPIiM; path=/; expires=Fri, 23-Jan-26 11:45:37 GMT; domain=.dev-contentapi.pwtcxstest.com; HttpOnly; Secure; SameSite=None alt-svc: h3=":443"; ma=86400 <h1>Nothing to see here</h1>
Open service 2a06:98c1:58::7d:443 · dev-contentapi.pwtcxstest.com
2026-01-23 11:15
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 11:15:37 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Server: cloudflare CF-Ray: 9c26dfcede98d5a3-AMS CF-Cache-Status: HIT Age: 1 Last-Modified: Fri, 23 Jan 2026 11:15:36 GMT Strict-Transport-Security: max-age=2592000 Vary: Accept-Encoding uc-cache-status: HIT, min-ttl=60, ttl=1800 x-powered-by: ASP.NET Set-Cookie: __cf_bm=dxaXdTJY3UuAv6LLjH6SRJ6TiJYwBi42jQvChBbKFQM-1769166937-1.0.1.1-xG3iVZ_RmuMkeV2zqS1EIhDgaEldVbixMUXPSNdOztVTeqUxyZET9rkSpStBDOgxdHJXSP02NZPD3KQJNtcuXJUaOijvcEteMQL2OsqNE90; path=/; expires=Fri, 23-Jan-26 11:45:37 GMT; domain=.dev-contentapi.pwtcxstest.com; HttpOnly; Secure; SameSite=None alt-svc: h3=":443"; ma=86400 <h1>Nothing to see here</h1>
Open service 2a06:98c1:58::7d:8443 · dev-contentapi.pwtcxstest.com
2026-01-23 11:15
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 11:15:37 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Server: cloudflare CF-Ray: 9c26dfcfaffe426a-EWR CF-Cache-Status: HIT Age: 1 Last-Modified: Fri, 23 Jan 2026 11:15:36 GMT Strict-Transport-Security: max-age=2592000 Vary: Accept-Encoding uc-cache-status: HIT, min-ttl=60, ttl=1800 x-powered-by: ASP.NET Set-Cookie: __cf_bm=mAbmPMp_fWTCCc4kh3jSQWqWP8lHkKVK0go_ZPMDqrc-1769166937-1.0.1.1-BKq5FbRd0iVwd.qrn73b4S8seeL_ol0jF8Y9ik0eSlQNypm7g1S.Kckpm.r8ljMI2WBtNQ6Zz9qM4ipwVIwv9me.fUKDrNwD3sh0xPQ7dJQ; path=/; expires=Fri, 23-Jan-26 11:45:37 GMT; domain=.dev-contentapi.pwtcxstest.com; HttpOnly; Secure; SameSite=None alt-svc: h3=":8443"; ma=86400 <h1>Nothing to see here</h1>
Open service 172.66.0.125:443 · dev-contentapi.pwtcxstest.com
2026-01-23 11:15
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 11:15:37 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Server: cloudflare CF-Ray: 9c26dfcf9bd2375a-YYZ CF-Cache-Status: HIT Age: 1 Last-Modified: Fri, 23 Jan 2026 11:15:36 GMT Strict-Transport-Security: max-age=2592000 Vary: Accept-Encoding uc-cache-status: HIT, min-ttl=60, ttl=1800 x-powered-by: ASP.NET Set-Cookie: __cf_bm=VN7jB4ME0ESOax3PRRJ8ZpivcOHn_4YwaOkVqW7YVNU-1769166937-1.0.1.1-E3YyUk1T5S1d35KndSsN4vtWXh4j3X9ynbmYx_qgakTM28IXUC3CyiOVsPD.cnY.J2wmSroFXqDXa1JnJ_Mc8UQ.S_fmUdXY.UOuHPGPB_c; path=/; expires=Fri, 23-Jan-26 11:45:37 GMT; domain=.dev-contentapi.pwtcxstest.com; HttpOnly; Secure; SameSite=None alt-svc: h3=":443"; ma=86400 <h1>Nothing to see here</h1>
Open service 2606:4700:7::7d:80 · dev-contentapi.pwtcxstest.com
2026-01-23 11:15
HTTP/1.1 301 Moved Permanently Date: Fri, 23 Jan 2026 11:15:37 GMT Content-Type: text/html Content-Length: 167 Connection: close Cache-Control: max-age=3600 Expires: Fri, 23 Jan 2026 12:15:37 GMT Location: https://dev-contentapi.pwtcxstest.com/ Set-Cookie: __cf_bm=w9iqkVyfdjO71hECd6PDD2uPt3EF7.OviZgYAqFrO7s-1769166937-1.0.1.1-Vf49z8ldls9alQFKzzgXigN2FtThINyvhTSt7zIJcWit1mDJizAUNpHPTCtCybH4TxQz3PrRGFBgdwaK4cnJmPNIzN74nrPLGSd8LxxP3GY; path=/; expires=Fri, 23-Jan-26 11:45:37 GMT; domain=.dev-contentapi.pwtcxstest.com; HttpOnly Server: cloudflare CF-RAY: 9c26dfce5aa6dcf2-EWR alt-svc: h3=":443"; ma=86400 Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>cloudflare</center> </body> </html>
Open service 172.66.0.125:8443 · dev-contentapi.pwtcxstest.com
2026-01-23 11:15
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 11:15:37 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Server: cloudflare CF-Ray: 9c26dfcf495a36ac-YYZ CF-Cache-Status: HIT Age: 1 Last-Modified: Fri, 23 Jan 2026 11:15:36 GMT Strict-Transport-Security: max-age=2592000 Vary: Accept-Encoding uc-cache-status: HIT, min-ttl=60, ttl=1800 x-powered-by: ASP.NET Set-Cookie: __cf_bm=vdYYeqtOvIZJhFfUO3cfOqiJtg1_EGRdRbavwyqYQdM-1769166937-1.0.1.1-ag6b8CJ0LNlxpD44KHGP5HAP8zy0PleJliSM7s4r5WWXfNDq__o1wzEAfXjZVLa3OPcyNt8CV8OS8CrUHoQGKLlSvOs1vGqOH2fo6xLS4So; path=/; expires=Fri, 23-Jan-26 11:45:37 GMT; domain=.dev-contentapi.pwtcxstest.com; HttpOnly; Secure; SameSite=None alt-svc: h3=":8443"; ma=86400 <h1>Nothing to see here</h1>
Open service 162.159.140.127:443 · dev-contentapi.pwtcxstest.com
2026-01-23 11:15
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 11:15:37 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Server: cloudflare CF-Ray: 9c26dfcfae965cb9-EWR CF-Cache-Status: HIT Age: 1 Last-Modified: Fri, 23 Jan 2026 11:15:36 GMT Strict-Transport-Security: max-age=2592000 Vary: Accept-Encoding uc-cache-status: HIT, min-ttl=60, ttl=1800 x-powered-by: ASP.NET Set-Cookie: __cf_bm=momMn1DA6PJ.o1bWyinqXpc3NsoC4Rd.bFztKn.K2EA-1769166937-1.0.1.1-6vXofrP21goCivgGcQMTAlLK6otLN9sQAfuelCvwcQep03BC.cMcUO0j5_g82VMsrF7jTAuAcMj803W26uOvmrUK7ddNRUiNCXZiaroZZYA; path=/; expires=Fri, 23-Jan-26 11:45:37 GMT; domain=.dev-contentapi.pwtcxstest.com; HttpOnly; Secure; SameSite=None alt-svc: h3=":443"; ma=86400 <h1>Nothing to see here</h1>
Open service 162.159.140.127:8443 · dev-contentapi.pwtcxstest.com
2026-01-23 11:15
HTTP/1.1 200 OK Date: Fri, 23 Jan 2026 11:15:37 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Server: cloudflare CF-Ray: 9c26dfceaa6b9fba-AMS CF-Cache-Status: HIT Age: 1 Last-Modified: Fri, 23 Jan 2026 11:15:36 GMT Strict-Transport-Security: max-age=2592000 Vary: Accept-Encoding uc-cache-status: HIT, min-ttl=60, ttl=1800 x-powered-by: ASP.NET Set-Cookie: __cf_bm=uGomgRZ0f.dmX4WBJfeH0s1ISlaoNJGDmTWu2KzVbk4-1769166937-1.0.1.1-sN210culXTGeecPZ5pKjpFGKleuRtQksIim7qARMHdnSNDYmZX4p3ikvM0cIM6Als8ko9GE_1mf6RZiNLzkFsViB_knTw0_b0pcqdse5rts; path=/; expires=Fri, 23-Jan-26 11:45:37 GMT; domain=.dev-contentapi.pwtcxstest.com; HttpOnly; Secure; SameSite=None alt-svc: h3=":8443"; ma=86400 <h1>Nothing to see here</h1>
Open service 172.66.0.125:80 · dev-contentapi.pwtcxstest.com
2026-01-23 11:15
HTTP/1.1 301 Moved Permanently Date: Fri, 23 Jan 2026 11:15:37 GMT Content-Type: text/html Content-Length: 167 Connection: close Cache-Control: max-age=3600 Expires: Fri, 23 Jan 2026 12:15:37 GMT Location: https://dev-contentapi.pwtcxstest.com/ Set-Cookie: __cf_bm=SwmynjPYTCOY.ypW7CFpwAqvyAYhaToRh74HobQG8e0-1769166937-1.0.1.1-Be5BVYyo4J9_BfHc4zqDkNvZo2_G_ThNoJUwiRdaRy9QkYsrVC4rg2CdIOC4ShUtKghODpO9gWiH1s_Soe4W0UFsBtIhGTQyCql3CUDzVn4; path=/; expires=Fri, 23-Jan-26 11:45:37 GMT; domain=.dev-contentapi.pwtcxstest.com; HttpOnly Server: cloudflare CF-RAY: 9c26dfce09768153-EWR alt-svc: h3=":443"; ma=86400 Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>cloudflare</center> </body> </html>
Open service 162.159.140.127:80 · dev-contentapi.pwtcxstest.com
2026-01-23 11:15
HTTP/1.1 301 Moved Permanently Date: Fri, 23 Jan 2026 11:15:37 GMT Content-Type: text/html Content-Length: 167 Connection: close Cache-Control: max-age=3600 Expires: Fri, 23 Jan 2026 12:15:37 GMT Location: https://dev-contentapi.pwtcxstest.com/ Set-Cookie: __cf_bm=nBT3EBq1xveumJfmsMFH64NY4KIDFrSSL_04j3c3YeA-1769166937-1.0.1.1-46OsiP0jQuAvhiLGIw2ZpXVXPFM0YTBeXxdy.Ph9OTN_sNYVOJilwfPe1HdKsWluyqgjPFfsPtGQawbWzuuZwOsO2CBhzOtAb5q5AIq3QK4; path=/; expires=Fri, 23-Jan-26 11:45:37 GMT; domain=.dev-contentapi.pwtcxstest.com; HttpOnly Server: cloudflare CF-RAY: 9c26dfcd7c99d288-FRA alt-svc: h3=":443"; ma=86400 Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>cloudflare</center> </body> </html>