Heroku
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff43339d009ac8efbf1e464fa51b06df62d2a3c86c38
Public Swagger UI/API detected at path: /swagger.json - sample paths: POST /v2/AddressVerification POST /v2/AutoComplete POST /v2/CSVBuilder POST /v2/MLSDetail POST /v2/MLSSearch POST /v2/PropGPT POST /v2/PropertyAvm POST /v2/PropertyDetail POST /v2/PropertyDetailBulk POST /v2/PropertySearch POST /v2/Reports/Documents POST /v2/Reports/PropertyLiens POST /v2/Reports/PropertyReports POST /v3/PropertyComps
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff43339d009ac8efbf1e464fa51b06df62d2a3c86c38
Public Swagger UI/API detected at path: /swagger.json - sample paths: POST /v2/AddressVerification POST /v2/AutoComplete POST /v2/CSVBuilder POST /v2/MLSDetail POST /v2/MLSSearch POST /v2/PropGPT POST /v2/PropertyAvm POST /v2/PropertyDetail POST /v2/PropertyDetailBulk POST /v2/PropertySearch POST /v2/Reports/Documents POST /v2/Reports/PropertyLiens POST /v2/Reports/PropertyReports POST /v3/PropertyComps
Open service 15.197.149.68:443 · reports.realestateapi.com
2026-01-09 23:19
HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: no-cache
Content-Length: 18
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 23:19:37 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=UPOM%2FSvTd5z1kfAFMa7xQfiCKuizFEu%2FQXYCXqqxEdc%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1768000777"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=UPOM%2FSvTd5z1kfAFMa7xQfiCKuizFEu%2FQXYCXqqxEdc%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1768000777"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
REAPI Proxy Server
Open service 3.33.241.96:80 · reports.realestateapi.com
2026-01-09 04:18
HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: no-cache
Content-Length: 18
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 04:19:10 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=PbVEIlea1aBmOK2rbc0ek4BnK0ciOxIqt2KhEU9PBf0%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767932350"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=PbVEIlea1aBmOK2rbc0ek4BnK0ciOxIqt2KhEU9PBf0%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767932350"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
REAPI Proxy Server
Open service 15.197.149.68:443 · reports.realestateapi.com
2026-01-02 12:41
HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: no-cache
Content-Length: 18
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 12:41:27 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=f%2FD5IUsPcCl3XM4d3weshQ5ZPemqKxIreaSBFHhkBhY%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767357687"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=f%2FD5IUsPcCl3XM4d3weshQ5ZPemqKxIreaSBFHhkBhY%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767357687"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
REAPI Proxy Server
Open service 3.33.241.96:80 · reports.realestateapi.com
2026-01-02 05:12
HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: no-cache
Content-Length: 18
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 05:12:52 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=C8AiTw%2BmZzKAuIfLEo8Pi0SQt%2FiDVULWHUYu2a4XeNs%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767330772"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=C8AiTw%2BmZzKAuIfLEo8Pi0SQt%2FiDVULWHUYu2a4XeNs%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767330772"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
REAPI Proxy Server
Open service 3.33.241.96:80 · reports.realestateapi.com
2025-12-26 11:27
HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: no-cache
Content-Length: 18
Content-Type: text/html; charset=utf-8
Date: Fri, 26 Dec 2025 11:27:24 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=dh%2FT6zldfLStgd3WQK7I0G9epr4ukN9k%2FEIPYD9JM%2Bo%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766748444"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=dh%2FT6zldfLStgd3WQK7I0G9epr4ukN9k%2FEIPYD9JM%2Bo%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766748444"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
REAPI Proxy Server
Open service 15.197.149.68:443 · reports.realestateapi.com
2025-12-22 17:59
HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: no-cache
Content-Length: 18
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 17:59:06 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=ZmU0IiGT1EqFrxdPt0yPLGF%2FJdB4%2Bv%2BjTbgh31Qvk20%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766426346"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=ZmU0IiGT1EqFrxdPt0yPLGF%2FJdB4%2Bv%2BjTbgh31Qvk20%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766426346"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
REAPI Proxy Server
Open service 3.33.241.96:80 · reports.realestateapi.com
2025-12-22 13:45
HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: no-cache
Content-Length: 18
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 13:45:15 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=YDaebahXLtVs1bhTymiVy2EyRxzs8W7N4hT2uLXh1as%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766411115"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=YDaebahXLtVs1bhTymiVy2EyRxzs8W7N4hT2uLXh1as%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766411115"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
REAPI Proxy Server
Open service 15.197.149.68:443 · reports.realestateapi.com
2025-12-20 20:41
HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: no-cache
Content-Length: 18
Content-Type: text/html; charset=utf-8
Date: Sat, 20 Dec 2025 20:41:05 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=sIanoOC7s8DLUyZlbCNezGRrVyJ32chAM2C1l%2FN3zug%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766263265"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=sIanoOC7s8DLUyZlbCNezGRrVyJ32chAM2C1l%2FN3zug%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766263265"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
REAPI Proxy Server
Open service 3.33.241.96:80 · reports.realestateapi.com
2025-12-20 13:31
HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: no-cache
Content-Length: 18
Content-Type: text/html; charset=utf-8
Date: Sat, 20 Dec 2025 13:31:15 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=5I%2B7efSAxQa2YP22Dsg31oOjXhaDq70R6R4XqzEVr18%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766237475"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=5I%2B7efSAxQa2YP22Dsg31oOjXhaDq70R6R4XqzEVr18%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766237475"
Server: Heroku
Via: 1.1 heroku-router
Connection: close
REAPI Proxy Server