Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549e01bff5dacb3bb10ffc0722064b666a327b1d6d6
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /v1/Organizations/Search
GET /v1/Organizations/{id}
POST /v1/Admin/DeleteTestOrganizations
POST /v1/Organizations
POST /v1/Organizations/{id}/refresh
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 2.16.204.69:443 · organizations.dev-submittable.com
2026-01-09 15:40
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 09 Jan 2026 15:40:23 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 15:40:23 GMT Connection: close Server-Timing: edge; dur=1 Server-Timing: origin; dur=101 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767973223399_34610501_401260718_10142_6892_17_20_-";dur=1
Open service 23.62.15.40:443 · organizations.dev-submittable.com
2026-01-08 15:48
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Thu, 08 Jan 2026 15:48:37 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 08 Jan 2026 15:48:37 GMT Connection: close Server-Timing: edge; dur=19 Server-Timing: origin; dur=101 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767887317311_389811496_685843919_11931_6181_101_106_-";dur=1
Open service 2a02:26f0:2780:67::217:e39a:80 · organizations.dev-submittable.com
2026-01-08 15:48
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://organizations-api.dev-submittable.com Expires: Thu, 08 Jan 2026 15:49:18 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 08 Jan 2026 15:49:18 GMT Connection: close Server-Timing: edge; dur=1 Server-Timing: origin; dur=89 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767887358206_34915482_81393816_8917_3837_119_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 23.62.15.40:80 · organizations.dev-submittable.com
2026-01-08 15:48
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://organizations-api.dev-submittable.com Expires: Thu, 08 Jan 2026 15:49:18 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 08 Jan 2026 15:49:18 GMT Connection: close Server-Timing: edge; dur=1 Server-Timing: origin; dur=94 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767887358862_389811496_685872483_9516_5268_209_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a02:26f0:2780:67::217:e39a:443 · organizations.dev-submittable.com
2026-01-08 15:48
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Thu, 08 Jan 2026 15:48:41 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 08 Jan 2026 15:48:41 GMT Connection: close Server-Timing: edge; dur=1 Server-Timing: origin; dur=92 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767887321481_34915472_214761154_9218_3198_18_21_-";dur=1
Open service 23.62.15.47:80 · organizations.dev-submittable.com
2026-01-08 15:48
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://organizations-api.dev-submittable.com Expires: Thu, 08 Jan 2026 15:49:17 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 08 Jan 2026 15:49:17 GMT Connection: close Server-Timing: edge; dur=1 Server-Timing: origin; dur=97 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767887357381_389811503_536237105_9818_6384_13_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a02:26f0:2780:67::217:e390:80 · organizations.dev-submittable.com
2026-01-08 15:48
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://organizations-api.dev-submittable.com Expires: Thu, 08 Jan 2026 15:49:18 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 08 Jan 2026 15:49:18 GMT Connection: close Server-Timing: edge; dur=1 Server-Timing: origin; dur=93 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767887358070_34915472_214864550_9322_3527_81_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a02:26f0:2780:67::217:e390:443 · organizations.dev-submittable.com
2026-01-08 15:48
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Thu, 08 Jan 2026 15:48:37 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 08 Jan 2026 15:48:37 GMT Connection: close Server-Timing: edge; dur=30 Server-Timing: origin; dur=107 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767887317173_34915472_214752796_13663_3629_159_243_-";dur=1
Open service 23.62.15.47:443 · organizations.dev-submittable.com
2026-01-08 15:48
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Thu, 08 Jan 2026 15:48:37 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 08 Jan 2026 15:48:37 GMT Connection: close Server-Timing: edge; dur=1 Server-Timing: origin; dur=100 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767887316905_389811503_536202943_10087_8314_88_95_-";dur=1
Open service 2.16.204.69:443 · organizations.dev-submittable.com
2026-01-02 22:51
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 02 Jan 2026 22:51:55 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 22:51:55 GMT Connection: close Server-Timing: edge; dur=1 Server-Timing: origin; dur=97 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767394315783_34610501_3362362815_9790_7797_81_86_-";dur=1
Open service 2.16.204.69:443 · organizations.dev-submittable.com
2025-12-30 13:22
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 30 Dec 2025 13:22:45 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 30 Dec 2025 13:22:45 GMT Connection: close Server-Timing: edge; dur=1 Server-Timing: origin; dur=937 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767100964597_34610504_298993031_93830_6070_18_34_-";dur=1
Open service 2.16.204.69:443 · organizations.dev-submittable.com
2025-12-22 14:45
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Mon, 22 Dec 2025 14:45:12 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 22 Dec 2025 14:45:12 GMT Connection: close Server-Timing: edge; dur=3 Server-Timing: origin; dur=602 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1766414711202_34610501_1041403345_60468_8476_177_221_-";dur=1
Open service 2.16.204.69:443 · organizations.dev-submittable.com
2025-12-20 12:32
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Sat, 20 Dec 2025 12:33:00 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 20 Dec 2025 12:33:00 GMT Connection: close Server-Timing: edge; dur=14 Server-Timing: origin; dur=275 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1766233980486_34610504_937846953_28978_32749_98_140_-";dur=1