Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1f5e22fb4b2be48fd5e4490484533fdd34ff668b74a456759
Public Swagger UI/API detected at path: /api/swagger.json - sample paths:
GET /applications/{applicationId}/attachments
POST /api/v1/approveApplicationTransferOrganization
POST /api/v1/archiveUser
POST /api/v1/cancelApplicationTransferOrganization
POST /api/v1/changeUserPassword
POST /api/v1/cleanUnusedApplicationAttachments
POST /api/v1/createApplicationTransferOrganization
POST /api/v1/createUser
POST /api/v1/getApplicationSubmission
POST /api/v1/getManyApplicationSubmissions
POST /api/v1/getUnusedApplicationAttachments
POST /api/v1/getUser
POST /api/v1/rejectApplicationTransferOrganization
POST /api/v1/transitionApplicationState
POST /api/v1/unarchiveUser
POST /api/v1/updateUser
Open service 74.125.29.121:443 路 service.thaismefund.com
2026-01-09 05:08
HTTP/1.1 200 OK content-type: text/plain;charset=UTF-8 x-cloud-trace-context: 48e8b8b87aaefb2925332154ef2f1819 date: Fri, 09 Jan 2026 05:08:33 GMT server: Google Frontend Content-Length: 32 Connection: close Welcome to Thaismefund API 馃帀
Open service 74.125.29.121:443 路 service.thaismefund.com
2026-01-02 12:04
HTTP/1.1 200 OK content-type: text/plain;charset=UTF-8 x-cloud-trace-context: 7ab099ab6ec386afebb812afaf13b9e8 date: Fri, 02 Jan 2026 12:04:50 GMT server: Google Frontend Content-Length: 32 Connection: close Welcome to Thaismefund API 馃帀
Open service 74.125.29.121:443 路 service.thaismefund.com
2025-12-30 13:35
HTTP/1.1 200 OK content-type: text/plain;charset=UTF-8 x-cloud-trace-context: a3a3aeca1599baddc146dd9be264dc03 date: Tue, 30 Dec 2025 13:35:21 GMT server: Google Frontend Content-Length: 32 Connection: close Welcome to Thaismefund API 馃帀
Open service 74.125.29.121:443 路 service.thaismefund.com
2025-12-22 13:08
HTTP/1.1 200 OK content-type: text/plain;charset=UTF-8 x-cloud-trace-context: 4ab168c8587870af2f2be4f1d89ce619 date: Mon, 22 Dec 2025 13:08:47 GMT server: Google Frontend Content-Length: 32 Connection: close Welcome to Thaismefund API 馃帀
Open service 74.125.29.121:443 路 service.thaismefund.com
2025-12-20 09:17
HTTP/1.1 200 OK content-type: text/plain;charset=UTF-8 x-cloud-trace-context: 607bb60d508cce9eaaf13645796f6a8a date: Sat, 20 Dec 2025 09:17:43 GMT server: Google Frontend Content-Length: 32 Connection: close Welcome to Thaismefund API 馃帀