cloudflare
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d603073f8703073f8703073f8703073f8703073f87
GraphQL introspection enabled at /api/graphql Detected: GitLab
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
Open service 172.67.75.211:443 · gitlab.orphlab.com
2026-01-09 09:00
HTTP/1.1 522 <none> Date: Fri, 09 Jan 2026 09:00:34 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Referrer-Policy: same-origin Server-Timing: cfEdge;dur=19546,cfOrigin;dur=0 X-Frame-Options: SAMEORIGIN Server: cloudflare CF-RAY: 9bb2be4139f787d9-LHR error code: 522
Open service 172.67.75.211:443 · gitlab.orphlab.com
2026-01-02 13:12
HTTP/1.1 302 Found
Date: Fri, 02 Jan 2026 13:12:04 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=7,cfOrigin;dur=338
Cache-Control: no-cache
Content-Security-Policy:
Location: http://gitlab.orphlab.com/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KDZDCBVEBWTYYJ6E3SP2F7P1","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KDZDCBVEBWTYYJ6E3SP2F7P1
X-Runtime: 0.044676
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Referrer-Policy: strict-origin-when-cross-origin
cf-cache-status: DYNAMIC
CF-RAY: 9b7a8183ed1f1705-EWR
<html><body>You are being <a href="https://gitlab.orphlab.com/users/sign_in">redirected</a>.<script defer src="https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015" integrity="sha512-ZpsOmlRQV6y907TI0dKBHq9Md29nnaEIPlkf84rnaERnq6zvWvPUqr2ft8M1aS28oN72PdrCzSjY4U6VaAw1EQ==" data-cf-beacon='{"version":"2024.11.0","token":"7c4604ca9c174e6ab39bce2b0fcf918c","server_timing":{"name":{"cfCacheStatus":true,"cfEdge":true,"cfExtPri":true,"cfL4":true,"cfOrigin":true,"cfSpeedBrain":true},"location_startswith":null}}' crossorigin="anonymous"></script>
</body></html>
Open service 172.67.75.211:443 · gitlab.orphlab.com
2025-12-22 18:10
HTTP/1.1 302 Found
Date: Mon, 22 Dec 2025 18:10:03 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=9,cfOrigin;dur=347
Cache-Control: no-cache
Content-Security-Policy:
Location: http://gitlab.orphlab.com/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KD3M22K2K5TBB25DJVNG58C6","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KD3M22K2K5TBB25DJVNG58C6
X-Runtime: 0.054049
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Referrer-Policy: strict-origin-when-cross-origin
cf-cache-status: DYNAMIC
CF-RAY: 9b2192e23f766109-EWR
<html><body>You are being <a href="https://gitlab.orphlab.com/users/sign_in">redirected</a>.<script defer src="https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015" integrity="sha512-ZpsOmlRQV6y907TI0dKBHq9Md29nnaEIPlkf84rnaERnq6zvWvPUqr2ft8M1aS28oN72PdrCzSjY4U6VaAw1EQ==" data-cf-beacon='{"version":"2024.11.0","token":"7c4604ca9c174e6ab39bce2b0fcf918c","server_timing":{"name":{"cfCacheStatus":true,"cfEdge":true,"cfExtPri":true,"cfL4":true,"cfOrigin":true,"cfSpeedBrain":true},"location_startswith":null}}' crossorigin="anonymous"></script>
</body></html>
Open service 172.67.75.211:443 · gitlab.orphlab.com
2025-12-20 19:13
HTTP/1.1 302 Found
Date: Sat, 20 Dec 2025 19:13:03 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=12,cfOrigin;dur=113
Cache-Control: no-cache
Content-Security-Policy:
Location: http://gitlab.orphlab.com/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KCYJVZQBRYHF4Z4K1JW3B6YH","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KCYJVZQBRYHF4Z4K1JW3B6YH
X-Runtime: 0.044799
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
Referrer-Policy: strict-origin-when-cross-origin
cf-cache-status: DYNAMIC
CF-RAY: 9b11746aa8cad346-FRA
<html><body>You are being <a href="https://gitlab.orphlab.com/users/sign_in">redirected</a>.<script defer src="https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015" integrity="sha512-ZpsOmlRQV6y907TI0dKBHq9Md29nnaEIPlkf84rnaERnq6zvWvPUqr2ft8M1aS28oN72PdrCzSjY4U6VaAw1EQ==" data-cf-beacon='{"version":"2024.11.0","token":"7c4604ca9c174e6ab39bce2b0fcf918c","server_timing":{"name":{"cfCacheStatus":true,"cfEdge":true,"cfExtPri":true,"cfL4":true,"cfOrigin":true,"cfSpeedBrain":true},"location_startswith":null}}' crossorigin="anonymous"></script>
</body></html>