Heroku
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b6e67656b6e67656b6e67656b6e67656b6e67656b6e67656
Public Swagger UI/API detected at path: /swagger-ui.html
Open service 75.2.43.161:443 · reader-gateway.paperview-services.com
2026-01-09 14:43
HTTP/1.1 404 Not Found
Access-Control-Allow-Origin: *
Content-Length: 23
Content-Security-Policy: img-src 'self' data: https:;script-src 'self' 'unsafe-inline' https://unpkg.com/ https://cdn.paperview-services.com/;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 14:43:42 GMT
Etag: W/"17-fKvpew7FzE9DyWAQDRo3kRWZ/PE"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Origin-Agent-Cluster: ?1
Referrer-Policy: no-referrer
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=SuPQgVOcVYvhR5Dc4zL0e1aNkqFDExT%2Bkpxmny%2FOMXo%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767969822"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=SuPQgVOcVYvhR5Dc4zL0e1aNkqFDExT%2Bkpxmny%2FOMXo%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767969822"
Server: Heroku
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Permitted-Cross-Domain-Policies: none
X-Xss-Protection: 0
Connection: close
Sorry, can't find that!
Open service 75.2.43.161:443 · reader-gateway.paperview-services.com
2026-01-02 12:49
HTTP/1.1 404 Not Found
Access-Control-Allow-Origin: *
Content-Length: 23
Content-Security-Policy: img-src 'self' data: https:;script-src 'self' 'unsafe-inline' https://unpkg.com/ https://cdn.paperview-services.com/;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 12:49:15 GMT
Etag: W/"17-fKvpew7FzE9DyWAQDRo3kRWZ/PE"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Origin-Agent-Cluster: ?1
Referrer-Policy: no-referrer
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=X7ujD9iCRCF9Cp0%2B9tLUNMidkqkdotK562YUTVDxMic%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767358155"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=X7ujD9iCRCF9Cp0%2B9tLUNMidkqkdotK562YUTVDxMic%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767358155"
Server: Heroku
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Permitted-Cross-Domain-Policies: none
X-Xss-Protection: 0
Connection: close
Sorry, can't find that!
Open service 75.2.43.161:443 · reader-gateway.paperview-services.com
2025-12-22 09:37
HTTP/1.1 404 Not Found
Access-Control-Allow-Origin: *
Content-Length: 23
Content-Security-Policy: img-src 'self' data: https:;script-src 'self' 'unsafe-inline' https://unpkg.com/ https://cdn.paperview-services.com/;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 09:37:31 GMT
Etag: W/"17-fKvpew7FzE9DyWAQDRo3kRWZ/PE"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Origin-Agent-Cluster: ?1
Referrer-Policy: no-referrer
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=63j3HytmIwPUzec%2BFalRTlhTvbVl4Exxv7zJvk%2B0tXA%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766396251"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=63j3HytmIwPUzec%2BFalRTlhTvbVl4Exxv7zJvk%2B0tXA%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766396251"
Server: Heroku
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Permitted-Cross-Domain-Policies: none
X-Xss-Protection: 0
Connection: close
Sorry, can't find that!
Open service 75.2.43.161:443 · reader-gateway.paperview-services.com
2025-12-20 08:39
HTTP/1.1 404 Not Found
Access-Control-Allow-Origin: *
Content-Length: 23
Content-Security-Policy: img-src 'self' data: https:;script-src 'self' 'unsafe-inline' https://unpkg.com/ https://cdn.paperview-services.com/;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
Content-Type: text/html; charset=utf-8
Date: Sat, 20 Dec 2025 08:39:37 GMT
Etag: W/"17-fKvpew7FzE9DyWAQDRo3kRWZ/PE"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Origin-Agent-Cluster: ?1
Referrer-Policy: no-referrer
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=5UcImFrBJdn%2BiyoTrFsULOVRUJbXDSs63%2BTMYKTdjgE%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766219977"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=5UcImFrBJdn%2BiyoTrFsULOVRUJbXDSs63%2BTMYKTdjgE%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766219977"
Server: Heroku
Strict-Transport-Security: max-age=15552000; includeSubDomains; preload
Vary: Accept-Encoding
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Dns-Prefetch-Control: off
X-Download-Options: noopen
X-Permitted-Cross-Domain-Policies: none
X-Xss-Protection: 0
Connection: close
Sorry, can't find that!