Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd110a331ec1fc9f56ab358aedd37214211a75978701754869d
Public Swagger UI/API detected at path: /v2/api-docs - sample paths:
GET /actuator
GET /actuator/health
GET /actuator/health/**
GET /actuator/info
GET /error
GET /v1/leads
GET /v1/leads/{leadId}
Open service 74.125.29.121:443 · lead-svc.api.dev.lazyxchange.com
2026-01-09 14:48
HTTP/1.1 404 Not Found
vary: Origin,Access-Control-Request-Method,Access-Control-Request-Headers
content-type: application/json
x-cloud-trace-context: ac0d616937b562ab7a48d2129498214b
date: Fri, 09 Jan 2026 14:49:06 GMT
server: Google Frontend
Content-Length: 121
Connection: close
{"timestamp":"2026-01-09T14:49:06.251+0000","status":404,"error":"Not Found","message":"No message available","path":"/"}
Open service 74.125.29.121:443 · lead-svc.api.dev.lazyxchange.com
2026-01-02 12:43
HTTP/1.1 404 Not Found
vary: Origin,Access-Control-Request-Method,Access-Control-Request-Headers
content-type: application/json
x-cloud-trace-context: 575f508c727dcf3fa18306be0c553ecb
date: Fri, 02 Jan 2026 12:44:05 GMT
server: Google Frontend
Content-Length: 121
Connection: close
{"timestamp":"2026-01-02T12:44:05.537+0000","status":404,"error":"Not Found","message":"No message available","path":"/"}
Open service 74.125.29.121:443 · lead-svc.api.dev.lazyxchange.com
2025-12-22 09:47
HTTP/1.1 404 Not Found
vary: Origin,Access-Control-Request-Method,Access-Control-Request-Headers
content-type: application/json
x-cloud-trace-context: 172b8fa4b6e838fa4198aa84c7982add
date: Mon, 22 Dec 2025 09:47:45 GMT
server: Google Frontend
Content-Length: 121
Connection: close
{"timestamp":"2025-12-22T09:47:45.692+0000","status":404,"error":"Not Found","message":"No message available","path":"/"}
Open service 74.125.29.121:443 · lead-svc.api.dev.lazyxchange.com
2025-12-20 08:24
HTTP/1.1 404 Not Found
vary: Origin,Access-Control-Request-Method,Access-Control-Request-Headers
content-type: application/json
x-cloud-trace-context: e81b69e914ebb1c338d016b07cee8fef
date: Sat, 20 Dec 2025 08:25:19 GMT
server: Google Frontend
Content-Length: 121
Connection: close
{"timestamp":"2025-12-20T08:25:19.726+0000","status":404,"error":"Not Found","message":"No message available","path":"/"}