BunnyCDN-DE1-1328
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff43893010f60b0aa35ab9191069b44dca723402b0ef
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /debug/settings/config
GET /debug/settings/pprof
GET /genesis
GET /health
GET /metrics
GET /ready
GET /swagger.json
GET /v2/accounts/{address}
GET /v2/accounts/{address}/applications/{application-id}
GET /v2/accounts/{address}/assets
GET /v2/accounts/{address}/assets/{asset-id}
GET /v2/accounts/{address}/transactions/pending
GET /v2/applications/{application-id}
GET /v2/applications/{application-id}/box
GET /v2/applications/{application-id}/boxes
GET /v2/assets/{asset-id}
GET /v2/blocks/{round}
GET /v2/blocks/{round}/hash
GET /v2/blocks/{round}/lightheader/proof
GET /v2/blocks/{round}/logs
GET /v2/blocks/{round}/transactions/{txid}/proof
GET /v2/blocks/{round}/txids
GET /v2/deltas/txn/group/{id}
GET /v2/deltas/{round}
GET /v2/deltas/{round}/txn/group
GET /v2/devmode/blocks/offset
GET /v2/experimental
GET /v2/ledger/supply
GET /v2/ledger/sync
GET /v2/participation
GET /v2/participation/{participation-id}
GET /v2/stateproofs/{round}
GET /v2/status
GET /v2/status/wait-for-block-after/{round}
GET /v2/transactions/params
GET /v2/transactions/pending
GET /v2/transactions/pending/{txid}
GET /versions
POST /v2/catchup/{catchpoint}
POST /v2/devmode/blocks/offset/{offset}
POST /v2/ledger/sync/{round}
POST /v2/participation/generate/{address}
POST /v2/shutdown
POST /v2/teal/compile
POST /v2/teal/disassemble
POST /v2/teal/dryrun
POST /v2/transactions
POST /v2/transactions/async
POST /v2/transactions/simulate
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff43893010f60b0aa35ab9191069b44dca723402b0ef
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /debug/settings/config
GET /debug/settings/pprof
GET /genesis
GET /health
GET /metrics
GET /ready
GET /swagger.json
GET /v2/accounts/{address}
GET /v2/accounts/{address}/applications/{application-id}
GET /v2/accounts/{address}/assets
GET /v2/accounts/{address}/assets/{asset-id}
GET /v2/accounts/{address}/transactions/pending
GET /v2/applications/{application-id}
GET /v2/applications/{application-id}/box
GET /v2/applications/{application-id}/boxes
GET /v2/assets/{asset-id}
GET /v2/blocks/{round}
GET /v2/blocks/{round}/hash
GET /v2/blocks/{round}/lightheader/proof
GET /v2/blocks/{round}/logs
GET /v2/blocks/{round}/transactions/{txid}/proof
GET /v2/blocks/{round}/txids
GET /v2/deltas/txn/group/{id}
GET /v2/deltas/{round}
GET /v2/deltas/{round}/txn/group
GET /v2/devmode/blocks/offset
GET /v2/experimental
GET /v2/ledger/supply
GET /v2/ledger/sync
GET /v2/participation
GET /v2/participation/{participation-id}
GET /v2/stateproofs/{round}
GET /v2/status
GET /v2/status/wait-for-block-after/{round}
GET /v2/transactions/params
GET /v2/transactions/pending
GET /v2/transactions/pending/{txid}
GET /versions
POST /v2/catchup/{catchpoint}
POST /v2/devmode/blocks/offset/{offset}
POST /v2/ledger/sync/{round}
POST /v2/participation/generate/{address}
POST /v2/shutdown
POST /v2/teal/compile
POST /v2/teal/disassemble
POST /v2/teal/dryrun
POST /v2/transactions
POST /v2/transactions/async
POST /v2/transactions/simulate
Open service 185.111.111.154:443 · mainnet-api.algonode.xyz
2026-01-09 22:33
HTTP/1.1 302 Found Date: Fri, 09 Jan 2026 22:33:10 GMT Content-Type: text/html Content-Length: 142 Connection: close Server: BunnyCDN-DE1-1328 CDN-PullZone: 903044 CDN-RequestCountryCode: US Location: https://nodely.io/swagger/index.html?url=/swagger/api/4160/algod.oas3.yml CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 12/22/2025 23:53:53 CDN-EdgeStorageId: 1332 CDN-RequestId: 90d9f30de7d1537ede2742d99e16c659 CDN-Cache: HIT CDN-Status: 302 CDN-RequestTime: 0 Page title: 302 Found <html> <head><title>302 Found</title></head> <body> <center><h1>302 Found</h1></center> <hr><center>openresty</center> </body> </html>
Open service 185.111.111.154:80 · mainnet-api.algonode.xyz
2026-01-09 16:39
HTTP/1.1 302 Found Date: Fri, 09 Jan 2026 16:39:22 GMT Content-Type: text/html Content-Length: 142 Connection: close Server: BunnyCDN-DE1-1328 CDN-PullZone: 903044 CDN-RequestCountryCode: NL Location: https://nodely.io/swagger/index.html?url=/swagger/api/4160/algod.oas3.yml CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 12/22/2025 23:53:53 CDN-EdgeStorageId: 1332 CDN-RequestId: 059796e9824dc50ecda23a0b53f57554 CDN-Cache: HIT CDN-Status: 302 CDN-RequestTime: 0 Page title: 302 Found <html> <head><title>302 Found</title></head> <body> <center><h1>302 Found</h1></center> <hr><center>openresty</center> </body> </html>
Open service 185.111.111.154:443 · mainnet-api.algonode.xyz
2026-01-02 20:53
HTTP/1.1 302 Found Date: Fri, 02 Jan 2026 20:53:42 GMT Content-Type: text/html Content-Length: 142 Connection: close Server: BunnyCDN-DE1-1328 CDN-PullZone: 903044 CDN-RequestCountryCode: CA Location: https://nodely.io/swagger/index.html?url=/swagger/api/4160/algod.oas3.yml CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 12/22/2025 23:53:53 CDN-EdgeStorageId: 1332 CDN-RequestId: d146cbe26dbfa9df1943976e01e1318c CDN-Cache: HIT CDN-Status: 302 CDN-RequestTime: 0 Page title: 302 Found <html> <head><title>302 Found</title></head> <body> <center><h1>302 Found</h1></center> <hr><center>openresty</center> </body> </html>
Open service 185.111.111.154:80 · mainnet-api.algonode.xyz
2026-01-02 01:48
HTTP/1.1 302 Found Date: Fri, 02 Jan 2026 01:48:56 GMT Content-Type: text/html Content-Length: 142 Connection: close Server: BunnyCDN-DE1-1328 CDN-PullZone: 903044 CDN-RequestCountryCode: DE Location: https://nodely.io/swagger/index.html?url=/swagger/api/4160/algod.oas3.yml CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 12/22/2025 23:53:53 CDN-EdgeStorageId: 1332 CDN-RequestId: 5f5c941c7dcbb7ca6a86208b5c66abef CDN-Cache: HIT CDN-Status: 302 CDN-RequestTime: 0 Page title: 302 Found <html> <head><title>302 Found</title></head> <body> <center><h1>302 Found</h1></center> <hr><center>openresty</center> </body> </html>
Open service 185.111.111.154:80 · mainnet-api.algonode.xyz
2025-12-30 12:24
HTTP/1.1 302 Found Date: Tue, 30 Dec 2025 12:24:10 GMT Content-Type: text/html Content-Length: 142 Connection: close Server: BunnyCDN-DE1-1328 CDN-PullZone: 903044 CDN-RequestCountryCode: US Location: https://nodely.io/swagger/index.html?url=/swagger/api/4160/algod.oas3.yml CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 12/22/2025 23:53:53 CDN-EdgeStorageId: 1332 CDN-RequestId: 807c162afed7feb37f6eb0d0b2589890 CDN-Cache: HIT CDN-Status: 302 CDN-RequestTime: 0 Page title: 302 Found <html> <head><title>302 Found</title></head> <body> <center><h1>302 Found</h1></center> <hr><center>openresty</center> </body> </html>
Open service 185.111.111.154:443 · mainnet-api.algonode.xyz
2025-12-22 23:53
HTTP/1.1 302 Found Date: Mon, 22 Dec 2025 23:53:53 GMT Content-Type: text/html Content-Length: 142 Connection: close Server: BunnyCDN-DE1-1328 CDN-PullZone: 903044 CDN-RequestCountryCode: DE Location: https://nodely.io/swagger/index.html?url=/swagger/api/4160/algod.oas3.yml CDN-ProxyVer: 1.41 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 12/22/2025 23:53:53 CDN-EdgeStorageId: 1332 CDN-RequestId: dcf1f7e96015087a812e41cac02cee01 CDN-Cache: HIT CDN-Status: 302 CDN-RequestTime: 0 Page title: 302 Found <html> <head><title>302 Found</title></head> <body> <center><h1>302 Found</h1></center> <hr><center>openresty</center> </body> </html>
Open service 185.111.111.154:80 · mainnet-api.algonode.xyz
2025-12-22 08:20
HTTP/1.1 302 Found Date: Mon, 22 Dec 2025 08:21:00 GMT Content-Type: text/html Content-Length: 142 Connection: close Server: BunnyCDN-DE1-1328 CDN-PullZone: 903044 CDN-RequestCountryCode: US Location: https://nodely.io/swagger/index.html?url=/swagger/api/4160/algod.oas3.yml CDN-ProxyVer: 1.40 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 11/22/2025 19:08:35 CDN-EdgeStorageId: 1332 CDN-RequestId: 8a35ccf7e30c0af44b88ce04f6c5932e CDN-Cache: HIT CDN-Status: 302 CDN-RequestTime: 0 Page title: 302 Found <html> <head><title>302 Found</title></head> <body> <center><h1>302 Found</h1></center> <hr><center>openresty</center> </body> </html>
Open service 185.111.111.154:443 · mainnet-api.algonode.xyz
2025-12-21 03:40
HTTP/1.1 302 Found Date: Sun, 21 Dec 2025 03:40:02 GMT Content-Type: text/html Content-Length: 142 Connection: close Server: BunnyCDN-DE1-1328 CDN-PullZone: 903044 CDN-RequestCountryCode: US Location: https://nodely.io/swagger/index.html?url=/swagger/api/4160/algod.oas3.yml CDN-ProxyVer: 1.40 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 11/22/2025 19:08:35 CDN-EdgeStorageId: 1332 CDN-RequestId: 4f463950ab82e39f0b564799b28fa8f4 CDN-Cache: HIT CDN-Status: 302 CDN-RequestTime: 0 Page title: 302 Found <html> <head><title>302 Found</title></head> <body> <center><h1>302 Found</h1></center> <hr><center>openresty</center> </body> </html>
Open service 185.111.111.154:80 · mainnet-api.algonode.xyz
2025-12-20 05:38
HTTP/1.1 302 Found Date: Sat, 20 Dec 2025 05:38:57 GMT Content-Type: text/html Content-Length: 142 Connection: close Server: BunnyCDN-DE1-1328 CDN-PullZone: 903044 CDN-RequestCountryCode: SG Location: https://nodely.io/swagger/index.html?url=/swagger/api/4160/algod.oas3.yml CDN-ProxyVer: 1.40 CDN-RequestPullSuccess: True CDN-RequestPullCode: 302 CDN-CachedAt: 11/22/2025 19:08:35 CDN-EdgeStorageId: 1332 CDN-RequestId: de73d56b4dfd8b2bad921847e63c7478 CDN-Cache: HIT CDN-Status: 302 CDN-RequestTime: 0 Page title: 302 Found <html> <head><title>302 Found</title></head> <body> <center><h1>302 Found</h1></center> <hr><center>openresty</center> </body> </html>