Heroku
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 99.83.217.1:80 · eu.api.lendtech.co
2026-01-09 08:49
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 30
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 08:50:17 GMT
Location: /swagger
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=FCz2KicP9%2BMY91na4SfbIlCw6MaH9eIdRC54HpjaK4U%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767948617"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=FCz2KicP9%2BMY91na4SfbIlCw6MaH9eIdRC54HpjaK4U%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767948617"
Server: Heroku
Vary: Accept
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /swagger
Open service 15.197.129.158:443 · eu.api.lendtech.co
2026-01-09 05:01
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 30
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 05:01:39 GMT
Location: /swagger
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=JfdqctS%2F2fhELj5s6Exu31IwblVl2R6AFzlo4xbwioE%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767934899"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=JfdqctS%2F2fhELj5s6Exu31IwblVl2R6AFzlo4xbwioE%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767934899"
Server: Heroku
Vary: Accept
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /swagger
Open service 15.197.129.158:443 · eu.api.lendtech.co
2026-01-02 12:11
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 30
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 12:11:59 GMT
Location: /swagger
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=o9P7INLvgxkECY1zyY%2BMAYojx24Av1VhR2Pjj7f8vOE%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767355919"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=o9P7INLvgxkECY1zyY%2BMAYojx24Av1VhR2Pjj7f8vOE%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767355919"
Server: Heroku
Vary: Accept
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /swagger
Open service 99.83.217.1:80 · eu.api.lendtech.co
2026-01-02 09:39
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 30
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 09:39:20 GMT
Location: /swagger
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=bIbrnaWHtUrDuZ%2FNDJ9eWyT1wtse5iGcR1KqkHEF8Co%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767346760"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=bIbrnaWHtUrDuZ%2FNDJ9eWyT1wtse5iGcR1KqkHEF8Co%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767346760"
Server: Heroku
Vary: Accept
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /swagger
Open service 15.197.129.158:443 · eu.api.lendtech.co
2025-12-30 13:29
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 30
Content-Type: text/plain; charset=utf-8
Date: Tue, 30 Dec 2025 13:29:13 GMT
Location: /swagger
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=D%2B2f%2BP1JjLsmvIvoqGjlrKs3DAgo6y5YbYooDeRjR6A%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767101353"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=D%2B2f%2BP1JjLsmvIvoqGjlrKs3DAgo6y5YbYooDeRjR6A%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767101353"
Server: Heroku
Vary: Accept
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /swagger
Open service 99.83.217.1:80 · eu.api.lendtech.co
2025-12-22 17:43
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 30
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 17:43:05 GMT
Location: /swagger
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=jYQZ0vnJfJMDm2iKdzUEh9Bvn0rMhRiQZ6ZJGCaLGWU%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766425385"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=jYQZ0vnJfJMDm2iKdzUEh9Bvn0rMhRiQZ6ZJGCaLGWU%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766425385"
Server: Heroku
Vary: Accept
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /swagger
Open service 15.197.129.158:443 · eu.api.lendtech.co
2025-12-22 14:29
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 30
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 14:29:33 GMT
Location: /swagger
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Co%2BOcIuedSOxTiJVsc4bhogR3Z2v5T7nd03Di3Wumaw%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766413773"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Co%2BOcIuedSOxTiJVsc4bhogR3Z2v5T7nd03Di3Wumaw%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766413773"
Server: Heroku
Vary: Accept
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /swagger
Open service 99.83.217.1:80 · eu.api.lendtech.co
2025-12-20 20:58
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 30
Content-Type: text/plain; charset=utf-8
Date: Sat, 20 Dec 2025 20:58:22 GMT
Location: /swagger
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=ZeX6ZSRJSXmqjKiwK%2Bs7sPJkW2kJTjtzuj3eReODUCc%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766264302"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=ZeX6ZSRJSXmqjKiwK%2Bs7sPJkW2kJTjtzuj3eReODUCc%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766264302"
Server: Heroku
Vary: Accept
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /swagger
Open service 15.197.129.158:443 · eu.api.lendtech.co
2025-12-20 13:14
HTTP/1.1 302 Found
Access-Control-Allow-Origin: *
Content-Length: 30
Content-Type: text/plain; charset=utf-8
Date: Sat, 20 Dec 2025 13:14:25 GMT
Location: /swagger
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=zzBd6DD9xClrz2SmsLExq0EXKGM9JkPwSLi4LLFnyhA%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766236465"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=zzBd6DD9xClrz2SmsLExq0EXKGM9JkPwSLi4LLFnyhA%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766236465"
Server: Heroku
Vary: Accept
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /swagger