Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549ca6a13684491f246915d8f94412b36280daf7e20
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /.well-known/oauth-authorization-server
GET /api/config
GET /api/design-system/branding
GET /api/limits
GET /api/products
GET /api/products/all-organizations
GET /health
GET /open-api/{service}/swagger.json
GET /proxy-openapi/swagger.json
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549ca6a13684491f246e7b5d1bea34626ce8f393592
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /.well-known/oauth-authorization-server
GET /api/config
GET /api/limits
GET /api/products
GET /api/products/all-organizations
GET /health
GET /open-api/{service}/swagger.json
GET /proxy-openapi/swagger.json
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549ca6a13684491f246e7b5d1bea34626ce7f76b4f9
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /.well-known/oauth-authorization-server
GET /api/config
GET /api/limits
GET /api/products
GET /health
GET /open-api/{service}/swagger.json
GET /proxy-openapi/swagger.json
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035493b3b73509b9c7a87891c30cfc00c33911884ccb5
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /
GET /.well-known/oauth-authorization-server
GET /api/config
GET /api/limits
GET /api/products
GET /open-api/{service}/swagger.json
GET /proxy-openapi/swagger.json
Open service 20.105.224.45:443 · graph.intranet.dev.workai.cloud
2026-01-23 16:51
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Fri, 23 Jan 2026 16:52:16 GMT Set-Cookie: ARRAffinity=ffbca59b025949de884b4d868d5979b22329f43e038fd0828f4548a11a1dec35;Path=/;HttpOnly;Secure;Domain=graph.intranet.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=ffbca59b025949de884b4d868d5979b22329f43e038fd0828f4548a11a1dec35;Path=/;HttpOnly;SameSite=None;Secure;Domain=graph.intranet.dev.workai.cloud
Open service 20.105.224.45:443 · graph.intranet.dev.workai.cloud
2026-01-09 10:56
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Fri, 09 Jan 2026 10:57:14 GMT Set-Cookie: ARRAffinity=e8c3b4220b9f97cf537feeb7ca8d7ede0c132f0c307819c4775a3815213a81d8;Path=/;HttpOnly;Secure;Domain=graph.intranet.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=e8c3b4220b9f97cf537feeb7ca8d7ede0c132f0c307819c4775a3815213a81d8;Path=/;HttpOnly;SameSite=None;Secure;Domain=graph.intranet.dev.workai.cloud
Open service 20.105.224.45:443 · graph.intranet.dev.workai.cloud
2026-01-05 17:04
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Mon, 05 Jan 2026 17:05:27 GMT Set-Cookie: ARRAffinity=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;Secure;Domain=graph.intranet.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;SameSite=None;Secure;Domain=graph.intranet.dev.workai.cloud
Open service 20.105.224.45:80 · graph.intranet.dev.workai.cloud
2026-01-05 17:04
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Mon, 05 Jan 2026 17:05:27 GMT Location: https://graph.intranet.dev.workai.cloud/
Open service 20.105.224.45:443 · graph.intranet.dev.workai.cloud
2026-01-02 18:55
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Fri, 02 Jan 2026 18:55:04 GMT Set-Cookie: ARRAffinity=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;Secure;Domain=graph.intranet.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;SameSite=None;Secure;Domain=graph.intranet.dev.workai.cloud
Open service 20.105.224.45:443 · graph.intranet.dev.workai.cloud
2025-12-22 14:57
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Mon, 22 Dec 2025 14:57:08 GMT Set-Cookie: ARRAffinity=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;Secure;Domain=graph.intranet.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;SameSite=None;Secure;Domain=graph.intranet.dev.workai.cloud