Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549571c5c42ebe150c423a59acc2ad664dee2ef9a6f
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/Client
GET /api/Url/Kanttum
GET /api/User/data
GET /api/User/me
GET /api/User/me/overview
POST /api/Login
POST /api/Login/external/{provider}
POST /api/Login/register
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549571c5c4293bf2f4a5c69558427215561ed35fad9
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/Client
GET /api/User/data
GET /api/User/me
POST /api/Login
POST /api/Login/external/{provider}
POST /api/Login/register
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d603feec9489c86d93a658c1d652f88ec9a1e0526f8
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths:
GET /api/User/data
GET /api/User/me
POST /api/Client
POST /api/Login
POST /api/Login/external/{provider}
POST /api/Login/register
Open service 172.217.208.121:443 · dev.api.login.inteligenciadevida.tec.br
2026-01-10 02:08
HTTP/1.1 404 Not Found x-cloud-trace-context: b6c1d083b6acee95b293d5865f0028ee date: Sat, 10 Jan 2026 02:08:51 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 172.217.208.121:443 · dev.api.login.inteligenciadevida.tec.br
2026-01-02 23:48
HTTP/1.1 404 Not Found x-cloud-trace-context: 66a851d82eea8a55ce60036354bdaa26 date: Fri, 02 Jan 2026 23:48:49 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 172.217.208.121:443 · dev.api.login.inteligenciadevida.tec.br
2025-12-23 09:33
HTTP/1.1 301 Moved Permanently location: index.html x-cloud-trace-context: 0de0673885e8f56d6167165f9e0bc8ab date: Tue, 23 Dec 2025 09:33:44 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 172.217.208.121:443 · dev.api.login.inteligenciadevida.tec.br
2025-12-21 04:53
HTTP/1.1 301 Moved Permanently location: index.html x-cloud-trace-context: 6e7d4f2f1e6d1a3c0db74c293004feec date: Sun, 21 Dec 2025 04:53:14 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close