Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549ad37022d44f31065ed26938c820e264cf167836a
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: GET /GetPending POST /Autoriza POST /PorAutorizar POST /PorAutorizarAuto POST /Valida
Open service 2a00:1450:4001:806::2013:80 · dev.token.api.pchsfonline.com
2026-02-08 10:54
HTTP/1.1 302 Found location: https://dev.token.api.pchsfonline.com/ x-cloud-trace-context: ec67b731773622abe6b2158c0a222b59 date: Sun, 08 Feb 2026 10:55:05 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 142.250.201.83:80 · dev.token.api.pchsfonline.com
2026-02-08 10:54
HTTP/1.1 302 Found location: https://dev.token.api.pchsfonline.com/ x-cloud-trace-context: 0f0c6237af4e2733a15d2bea2f99f52e;o=1 date: Sun, 08 Feb 2026 10:55:05 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 142.250.186.147:443 · dev.token.api.pchsfonline.com
2026-01-09 07:15
HTTP/1.1 404 Not Found x-cloud-trace-context: 3dc76863418f1540e57b6e9acc918f4d date: Fri, 09 Jan 2026 07:15:37 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 142.250.186.147:443 · dev.token.api.pchsfonline.com
2026-01-02 06:28
HTTP/1.1 404 Not Found x-cloud-trace-context: d2fa67c19d5eca24c78d5da51f19fbff date: Fri, 02 Jan 2026 06:28:43 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 142.250.186.147:443 · dev.token.api.pchsfonline.com
2025-12-22 12:37
HTTP/1.1 404 Not Found x-cloud-trace-context: 715735a6658119964277bdbe98ede983 date: Mon, 22 Dec 2025 12:37:30 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close