Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1f5e22fb4a8fc7059d7fd5cbd0a6d6519bf02632a6755ec20
Public Swagger UI/API detected at path: /api/swagger.json - sample paths:
GET /auth/initiate
GET /auth/protocols/email/callback
GET /auth/protocols/email/initiate
GET /auth/protocols/message/callback
GET /auth/protocols/message/initiate
GET /auth/protocols/oauth2/callback
GET /auth/protocols/oauth2/initiate
GET /auth/protocols/otp/generate
GET /auth/protocols/otp/initiate
GET /cookies
GET /cookies/{id}
GET /data-processing
GET /data-processing/{id}
GET /locations/{id}
GET /privacy-centers
GET /privacy-centers/{id}
GET /sign/{id}
GET /vendors
GET /vendors/{id}
POST /amp/check-consent
POST /auth/protocols/otp/verify
POST /batch-sign
POST /consents/users/batch-load
POST /events
POST /metrics
POST /sign
POST /sync
POST /tcf
Open service 18.66.192.86:443 · privacy.winklepickerdust.com
2026-01-09 00:32
HTTP/1.1 302 Moved Temporarily Content-Type: text/plain; charset=utf-8 Content-Length: 26 Connection: close Date: Fri, 09 Jan 2026 00:32:33 GMT Location: /en/ Strict-Transport-Security: max-age=15552000; includeSubDomains X-Response-Time: 1.887ms Vary: Accept X-Cache: Hit from cloudfront Via: 1.1 878a01abbb158ab50d28bd4e882dc33a.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 X-Amz-Cf-Id: 7DkWf8Ldr9KVmDnF6YigrLUWloG5kTEPIlprozJx0Qo2Eac37LNssA== Age: 2 Found. Redirecting to /en/
Open service 18.66.192.86:443 · privacy.winklepickerdust.com
2026-01-02 00:33
HTTP/1.1 302 Moved Temporarily Content-Type: text/plain; charset=utf-8 Content-Length: 26 Connection: close Date: Fri, 02 Jan 2026 00:33:58 GMT Location: /en/ Strict-Transport-Security: max-age=15552000; includeSubDomains X-Response-Time: 0.514ms Vary: Accept X-Cache: Hit from cloudfront Via: 1.1 551f2461af0b3bf4faaad831ee6e5b1e.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 X-Amz-Cf-Id: ZIVxaxxHpXcL3ZHKO5l8z62dPnblFHnz0A5iX40cOVLAxiI8sSaHLQ== Found. Redirecting to /en/
Open service 18.66.192.86:443 · privacy.winklepickerdust.com
2025-12-30 08:11
HTTP/1.1 302 Moved Temporarily Content-Type: text/plain; charset=utf-8 Content-Length: 26 Connection: close Date: Tue, 30 Dec 2025 08:11:50 GMT Location: /en/ Strict-Transport-Security: max-age=15552000; includeSubDomains X-Response-Time: 0.553ms Vary: Accept X-Cache: Hit from cloudfront Via: 1.1 f8d34d99bd5a267bad6857ae101ea8e2.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 X-Amz-Cf-Id: SLvCaf12PSPRRHSBOJAQRvdXhphi0BjN_XbLSb0FhYxcVoEUUCmpgg== Found. Redirecting to /en/
Open service 18.66.192.86:443 · privacy.winklepickerdust.com
2025-12-22 08:51
HTTP/1.1 302 Moved Temporarily Content-Type: text/plain; charset=utf-8 Content-Length: 26 Connection: close Date: Mon, 22 Dec 2025 08:51:28 GMT Location: /en/ Strict-Transport-Security: max-age=15552000; includeSubDomains X-Response-Time: 1.808ms Vary: Accept X-Cache: Hit from cloudfront Via: 1.1 f8d34d99bd5a267bad6857ae101ea8e2.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 X-Amz-Cf-Id: va4ETGhnwC8Cp6QaaztAADoZBG-i8Ch9TeJmex8jSeKxPGwm-nUpPg== Found. Redirecting to /en/
Open service 18.66.192.86:443 · privacy.winklepickerdust.com
2025-12-20 12:38
HTTP/1.1 302 Moved Temporarily Content-Type: text/plain; charset=utf-8 Content-Length: 26 Connection: close Date: Sat, 20 Dec 2025 12:38:05 GMT Location: /en/ Strict-Transport-Security: max-age=15552000; includeSubDomains X-Response-Time: 1.933ms Vary: Accept X-Cache: Hit from cloudfront Via: 1.1 ec12d3de4ccd821a7e749609dcc62010.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 X-Amz-Cf-Id: bvF_-6Hx71Ce5MSc8hnzQ1hFQEns3Jp-X2-X88nhfj1QoixsvKZu0w== Found. Redirecting to /en/