Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549cf3cba6c3c89e2db9c06a5eef77e9ecf85824453
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: GET /auth/alexa/tokeninfo/v1 GET /auth/dgf/tokeninfo/v1 GET /auth/stv/tokeninfo/v1 GET /auth/tokeninfo/v1 GET /auth/v1 GET /auth/v3 GET /auth/v4 GET /auth/v5 GET /fiosauth/tokeninfo/v1 GET /poc/demo POST /auth/renew/v1 POST /auth/renew/v2 POST /auth/renew/v3 POST /auth/revoke/v1 POST /auth/revoke/v2 POST /auth/revoke/v3 POST /auth/stv/renew/v1 POST /auth/stv/revoke/v1 POST /auth/stv/revoke/v2 POST /auth/validate/v1 POST /fiosauth/renew/v1 POST /fiosauth/revoke/v1 POST /fiosauth/revoke/v2
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d60c2a2d0d11211dd6adfc3c8b351e5c5a226260a1e
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths: GET /auth/alexa/tokeninfo/v1 GET /auth/dgf/tokeninfo/v1 GET /auth/stv/tokeninfo/v1 GET /auth/tokeninfo/v1 GET /auth/v1 GET /auth/v3 GET /auth/v4 GET /auth/v5 GET /fiosauth/tokeninfo/v1 GET /poc/demo POST /auth/renew/v1 POST /auth/renew/v2 POST /auth/renew/v3 POST /auth/revoke/v1 POST /auth/revoke/v2 POST /auth/revoke/v3 POST /auth/stv/renew/v1 POST /auth/stv/revoke/v1 POST /auth/stv/revoke/v2 POST /auth/validate/v1 POST /fiosauth/renew/v1 POST /fiosauth/revoke/v1 POST /fiosauth/revoke/v2
Open service 184.24.77.52:443 · ottinitializer-dit.cdn.fios.tv
2026-01-10 02:48
HTTP/1.1 404 Not Found Content-Length: 0 Expires: Sat, 10 Jan 2026 02:49:03 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 10 Jan 2026 02:49:03 GMT Connection: close Akamai-GRN: 0.40cf3617.1768013343.2606f209
Open service 2.16.183.213:443 · ottinitializer-dit.cdn.fios.tv
2026-01-08 05:36
HTTP/1.1 404 Not Found Content-Length: 0 Expires: Thu, 08 Jan 2026 05:36:50 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 08 Jan 2026 05:36:50 GMT Connection: close Akamai-GRN: 0.22f5d517.1767850610.e506003
Open service 2.16.183.226:443 · ottinitializer-dit.cdn.fios.tv
2026-01-08 05:36
HTTP/1.1 404 Not Found Content-Length: 0 Expires: Thu, 08 Jan 2026 05:36:50 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 08 Jan 2026 05:36:50 GMT Connection: close Akamai-GRN: 0.15f5d517.1767850610.1272255d
Open service 184.24.77.52:443 · ottinitializer-dit.cdn.fios.tv
2026-01-02 10:27
HTTP/1.1 404 Not Found Content-Length: 0 Expires: Fri, 02 Jan 2026 10:27:34 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 10:27:34 GMT Connection: close Akamai-GRN: 0.34cf3617.1767349654.d975e66
Open service 184.24.77.52:443 · ottinitializer-dit.cdn.fios.tv
2025-12-22 09:23
HTTP/1.1 404 Not Found Content-Length: 0 Expires: Mon, 22 Dec 2025 09:23:44 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 22 Dec 2025 09:23:44 GMT Connection: close Akamai-GRN: 0.40cf3617.1766395424.29051521
Open service 184.24.77.52:443 · ottinitializer-dit.cdn.fios.tv
2025-12-20 12:55
HTTP/1.1 404 Not Found Content-Length: 0 Expires: Sat, 20 Dec 2025 12:55:57 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sat, 20 Dec 2025 12:55:57 GMT Connection: close Akamai-GRN: 0.34cf3617.1766235356.15792ca0