nginx 1.18.0
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 18.173.154.64:443 · dev-suite-service-api.com
2026-01-09 11:51
HTTP/1.1 404 Not Found Content-Type: text/html; charset=utf-8 Content-Length: 139 Connection: close Server: nginx/1.18.0 (Ubuntu) Date: Fri, 09 Jan 2026 11:51:20 GMT X-Content-Type-Options: nosniff X-Powered-By: Express access-control-allow-origin: * access-control-allow-headers: * access-control-allow-methods: * Content-Security-Policy: default-src 'none' X-Cache: Error from cloudfront Via: 1.1 19392de11dadb918bd6f24e199ea180e.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P3 X-Amz-Cf-Id: oE5nVWDAnG6s0aOop28M3roD8toUsgBo_mSLIy5uKs_UfQn0juyyFg== Age: 2 Page title: Error <!DOCTYPE html> <html lang="en"> <head> <meta charset="utf-8"> <title>Error</title> </head> <body> <pre>Cannot GET /</pre> </body> </html>
Open service 18.173.154.64:443 · dev-suite-service-api.com
2026-01-02 20:54
HTTP/1.1 404 Not Found Content-Type: text/html; charset=utf-8 Content-Length: 139 Connection: close Server: nginx/1.18.0 (Ubuntu) Date: Fri, 02 Jan 2026 20:54:53 GMT X-Content-Type-Options: nosniff X-Powered-By: Express access-control-allow-origin: * access-control-allow-headers: * access-control-allow-methods: * Content-Security-Policy: default-src 'none' X-Cache: Error from cloudfront Via: 1.1 d11d7fba872e54649066e59f703ad3e6.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P3 X-Amz-Cf-Id: 5fHZt5hdFVr5Xz_rHr6g7_NIEJjrnCKOlFR9G-Xu2FQSnW6X-jG6cg== Page title: Error <!DOCTYPE html> <html lang="en"> <head> <meta charset="utf-8"> <title>Error</title> </head> <body> <pre>Cannot GET /</pre> </body> </html>
Open service 18.173.154.64:443 · dev-suite-service-api.com
2025-12-22 23:52
HTTP/1.1 404 Not Found Content-Type: text/html; charset=utf-8 Content-Length: 139 Connection: close Server: nginx/1.18.0 (Ubuntu) Date: Mon, 22 Dec 2025 23:52:02 GMT X-Content-Type-Options: nosniff X-Powered-By: Express access-control-allow-origin: * access-control-allow-headers: * access-control-allow-methods: * Content-Security-Policy: default-src 'none' X-Cache: Error from cloudfront Via: 1.1 08cfbbb6f1b1bf4bc1e8ab1a071b4154.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P3 X-Amz-Cf-Id: Sv5URK6UnXndrgQYg8KiqeVctpNN3_sApWo9LJyPabojBWl1rMSClA== Page title: Error <!DOCTYPE html> <html lang="en"> <head> <meta charset="utf-8"> <title>Error</title> </head> <body> <pre>Cannot GET /</pre> </body> </html>
Open service 18.173.154.64:443 · dev-suite-service-api.com
2025-12-21 03:43
HTTP/1.1 404 Not Found Content-Type: text/html; charset=utf-8 Content-Length: 139 Connection: close Server: nginx/1.18.0 (Ubuntu) Date: Sun, 21 Dec 2025 03:43:21 GMT X-Content-Type-Options: nosniff X-Powered-By: Express access-control-allow-origin: * access-control-allow-headers: * access-control-allow-methods: * Content-Security-Policy: default-src 'none' X-Cache: Error from cloudfront Via: 1.1 ca623c10f2a669c8a9af30362937ebac.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P3 X-Amz-Cf-Id: A0k_KqCyxMm9kBZegv7IlCXfrlj7WEIHFFO-9gGHFAFicv6ufXI2gw== Page title: Error <!DOCTYPE html> <html lang="en"> <head> <meta charset="utf-8"> <title>Error</title> </head> <body> <pre>Cannot GET /</pre> </body> </html>