BunnyCDN-DE1-1330
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d6f3ccd36fa695f43dcc58998d7abecf037f0cb208
GraphQL introspection enabled at /api/graphql Types: 52 (by kind: ENUM: 5, INPUT_OBJECT: 19, OBJECT: 23, SCALAR: 5) Operations: - Query: Query | fields: currentUser, plans, project, projectInvitations, projects - Mutation: Mutation | fields: createProject, updateProject, updateProjectAccessAdd, updateProjectAccessRemove, updateProjectAccessRole Directives: defer, deprecated, include, oneOf, skip, specifiedBy (total: 6)
Open service 185.111.111.156:443 · dev.collingo.app
2026-01-09 22:41
HTTP/1.1 401 Unauthorized Date: Fri, 09 Jan 2026 22:41:29 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Server: BunnyCDN-DE1-1330 CDN-PullZone: 3736741 CDN-RequestCountryCode: CA Cache-Control: public, max-age=0 Location: https://auth.collingo.app/?rd=https%3A%2F%2Fdev.collingo.app%2F&rm=GET Set-Cookie: authelia_session=64FcqJPxllwLSot7HDKAkPgRxGUCeL_e; expires=Fri, 09 Jan 2026 23:41:29 GMT; domain=.collingo.app; path=/; HttpOnly; secure; SameSite=Lax Permissions-Policy: accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), screen-wake-lock=(), sync-xhr=(), xr-spatial-tracking=(), interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin X-Content-Type-Options: nosniff X-Dns-Prefetch-Control: off X-Frame-Options: DENY CDN-ProxyVer: 1.43 CDN-RequestPullSuccess: True CDN-RequestPullCode: 401 CDN-CachedAt: 01/09/2026 22:41:29 CDN-EdgeStorageId: 1332 CDN-RequestId: 5aa5940bf079601f36ac3a9f182f7c69 CDN-Cache: BYPASS CDN-Status: 401 CDN-RequestTime: 0 <a href="https://auth.collingo.app/?rd=https%3A%2F%2Fdev.collingo.app%2F&rm=GET">401 Unauthorized</a>
Open service 185.111.111.156:443 · dev.collingo.app
2025-12-30 12:21
HTTP/1.1 401 Unauthorized Date: Tue, 30 Dec 2025 12:21:32 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Server: BunnyCDN-DE1-1330 CDN-PullZone: 3736741 CDN-RequestCountryCode: DE Cache-Control: public, max-age=0 Location: https://auth.collingo.app/?rd=https%3A%2F%2Fdev.collingo.app%2F&rm=GET Set-Cookie: authelia_session=ba3^GoCHDwOmvZtJynJgRUIyqGoK#aeQ; expires=Tue, 30 Dec 2025 13:21:32 GMT; domain=.collingo.app; path=/; HttpOnly; secure; SameSite=Lax Permissions-Policy: accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), screen-wake-lock=(), sync-xhr=(), xr-spatial-tracking=(), interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin X-Content-Type-Options: nosniff X-Dns-Prefetch-Control: off X-Frame-Options: DENY CDN-ProxyVer: 1.43 CDN-RequestPullSuccess: True CDN-RequestPullCode: 401 CDN-CachedAt: 12/30/2025 12:21:32 CDN-EdgeStorageId: 1332 CDN-RequestId: 2754df403fb64af840646001640d1285 CDN-Cache: BYPASS CDN-Status: 401 CDN-RequestTime: 0 <a href="https://auth.collingo.app/?rd=https%3A%2F%2Fdev.collingo.app%2F&rm=GET">401 Unauthorized</a>
Open service 185.111.111.156:443 · dev.collingo.app
2025-12-22 21:57
HTTP/1.1 401 Unauthorized Date: Mon, 22 Dec 2025 21:57:18 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Server: BunnyCDN-DE1-1330 CDN-PullZone: 3736741 CDN-RequestCountryCode: CA Cache-Control: public, max-age=0 Location: https://auth.collingo.app/?rd=https%3A%2F%2Fdev.collingo.app%2F&rm=GET Set-Cookie: authelia_session=JnPbfbU*3Djw68h%0Sy15Xp1VQQ-NifT; expires=Mon, 22 Dec 2025 22:57:18 GMT; domain=.collingo.app; path=/; HttpOnly; secure; SameSite=Lax Permissions-Policy: accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), screen-wake-lock=(), sync-xhr=(), xr-spatial-tracking=(), interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin X-Content-Type-Options: nosniff X-Dns-Prefetch-Control: off X-Frame-Options: DENY CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 401 CDN-CachedAt: 12/22/2025 21:57:18 CDN-EdgeStorageId: 1332 CDN-RequestId: ecd614e562a528b9a6a3ab2525993a5a CDN-Cache: BYPASS CDN-Status: 401 CDN-RequestTime: 0 <a href="https://auth.collingo.app/?rd=https%3A%2F%2Fdev.collingo.app%2F&rm=GET">401 Unauthorized</a>
Open service 185.111.111.156:443 · dev.collingo.app
2025-12-21 04:18
HTTP/1.1 401 Unauthorized Date: Sun, 21 Dec 2025 04:18:28 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Server: BunnyCDN-DE1-1330 CDN-PullZone: 3736741 CDN-RequestCountryCode: DE Cache-Control: public, max-age=0 Location: https://auth.collingo.app/?rd=https%3A%2F%2Fdev.collingo.app%2F&rm=GET Set-Cookie: authelia_session=LAf19t1fsnBFQwDJaBXe75J-%l8eCquq; expires=Sun, 21 Dec 2025 05:18:28 GMT; domain=.collingo.app; path=/; HttpOnly; secure; SameSite=Lax Permissions-Policy: accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), screen-wake-lock=(), sync-xhr=(), xr-spatial-tracking=(), interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin X-Content-Type-Options: nosniff X-Dns-Prefetch-Control: off X-Frame-Options: DENY CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 401 CDN-CachedAt: 12/21/2025 04:18:28 CDN-EdgeStorageId: 1332 CDN-RequestId: 21d7451bf3bea6a4fced5f142f103b72 CDN-Cache: BYPASS CDN-Status: 401 CDN-RequestTime: 0 <a href="https://auth.collingo.app/?rd=https%3A%2F%2Fdev.collingo.app%2F&rm=GET">401 Unauthorized</a>
Open service 185.111.111.156:443 · dev.collingo.app
2025-12-19 01:57
HTTP/1.1 401 Unauthorized Date: Fri, 19 Dec 2025 01:57:12 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Server: BunnyCDN-DE1-1330 CDN-PullZone: 3736741 CDN-RequestCountryCode: GB Cache-Control: public, max-age=0 Location: https://auth.collingo.app/?rd=https%3A%2F%2Fdev.collingo.app%2F&rm=GET Set-Cookie: authelia_session=fWEDJF46xd4FNl*m#tMH1AXAXP*k5uWp; expires=Fri, 19 Dec 2025 02:57:12 GMT; domain=.collingo.app; path=/; HttpOnly; secure; SameSite=Lax Permissions-Policy: accelerometer=(), autoplay=(), camera=(), display-capture=(), geolocation=(), gyroscope=(), keyboard-map=(), magnetometer=(), microphone=(), midi=(), payment=(), picture-in-picture=(), screen-wake-lock=(), sync-xhr=(), xr-spatial-tracking=(), interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin X-Content-Type-Options: nosniff X-Dns-Prefetch-Control: off X-Frame-Options: DENY CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 401 CDN-CachedAt: 12/19/2025 01:57:12 CDN-EdgeStorageId: 1332 CDN-RequestId: 6f7f7fb150cea2da3565a76e4457c5eb CDN-Cache: BYPASS CDN-Status: 401 CDN-RequestTime: 0 <a href="https://auth.collingo.app/?rd=https%3A%2F%2Fdev.collingo.app%2F&rm=GET">401 Unauthorized</a>