Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff43714a58ce9796ef3d7a64264c82309776e28afcac
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /
GET /api/v1/templates
GET /api/v1/templates/meta
GET /api/v1/templates/{template_id}
GET /api/v1/validate-token
GET /debug/headers
GET /health
GET /webhooks/whatsapp
POST /api/v1/notifications/batch
POST /api/v1/send-notification
POST /api/v1/templates/sync
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff43714a58ce9796ef3d4cb117ad8efcfb566bdb5823
Public Swagger UI/API detected at path: /swagger.json - sample paths:
GET /
GET /api/v1/templates
GET /api/v1/templates/{template_id}
GET /health
GET /webhooks/whatsapp
POST /api/v1/notifications/batch
POST /api/v1/send-notification
Open service 172.217.208.121:443 · notifications.infinitytechgy.com
2026-01-09 06:01
HTTP/1.1 200 OK
content-type: application/json
access-control-allow-origin: http://localhost:5173
access-control-expose-headers: Authorization, Content-Type
access-control-allow-credentials: true
vary: Origin
x-cloud-trace-context: a6874efb54f56ff527a3cfbf15a9c353
date: Fri, 09 Jan 2026 06:02:00 GMT
server: Google Frontend
Content-Length: 100
Connection: close
{"docs":"/api/docs","service":"WhatsApp Notification Service","status":"running","version":"1.0.0"}
Open service 172.217.208.121:443 · notifications.infinitytechgy.com
2026-01-02 04:33
HTTP/1.1 200 OK
content-type: application/json
access-control-allow-origin: http://localhost:5173
access-control-expose-headers: Authorization, Content-Type
access-control-allow-credentials: true
vary: Origin
x-cloud-trace-context: 4651fd0e31afa0ea8baa250e63c3ad61
date: Fri, 02 Jan 2026 04:33:57 GMT
server: Google Frontend
Content-Length: 100
Connection: close
{"docs":"/api/docs","service":"WhatsApp Notification Service","status":"running","version":"1.0.0"}
Open service 172.217.208.121:443 · notifications.infinitytechgy.com
2025-12-22 10:09
HTTP/1.1 200 OK
content-type: application/json
access-control-allow-origin: http://localhost:5173
access-control-expose-headers: Authorization, Content-Type
access-control-allow-credentials: true
vary: Origin
x-cloud-trace-context: e38283a6c33fe024136a00fa64d01e88
date: Mon, 22 Dec 2025 10:09:10 GMT
server: Google Frontend
Content-Length: 100
Connection: close
{"docs":"/api/docs","service":"WhatsApp Notification Service","status":"running","version":"1.0.0"}
Open service 172.217.208.121:443 · notifications.infinitytechgy.com
2025-12-20 07:12
HTTP/1.1 200 OK
content-type: application/json
access-control-allow-origin: http://localhost:5173
access-control-expose-headers: Authorization, Content-Type
access-control-allow-credentials: true
vary: Origin
x-cloud-trace-context: fedce92e153fe4288ab65f4347a1c5d5
date: Sat, 20 Dec 2025 07:12:24 GMT
server: Google Frontend
Content-Length: 100
Connection: close
{"docs":"/api/docs","service":"WhatsApp Notification Service","status":"running","version":"1.0.0"}