Heroku
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Open service 13.248.132.87:443 · staging.fleetpanda.com
2026-01-09 04:19
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://staging.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=uj61YiJrfe%2FqUsoCTa7t8Lz4G0Z0C2SKpe8xeRnl%2BKk%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767932376"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=uj61YiJrfe%2FqUsoCTa7t8Lz4G0Z0C2SKpe8xeRnl%2BKk%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767932376"
Server: Heroku
Set-Cookie: _fleetpanda_session=X3jdjLw9A3lnmsCOHKQ7Xef4t0GGQ4neOVIsj2JuXjZhdLcEToXIDK2x8mvcb38wCoglYcBRhROcPBXeb9xSB0zYgIsZc05lFC6soboA0JPQKZw7lPMgznL8zbCsqvY6mtHzLssKMOrkhv3XbTXAoDh4JNYNV0H9ISLCkaqCcCB2gSUAntf6PBz7s%2Ft3WixnNhd2bSOfLus5hgeUSTSSv47czpZK--W351qQHnIxor%2BYaX--UrRod0mQLnoOEgn24yml4g%3D%3D; domain=.staging.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: 824bed46-e76c-aedb-8ab8-7ce917e520e3
X-Runtime: 0.008014
Date: Fri, 09 Jan 2026 04:19:36 GMT
Content-Length: 108
Connection: close
<html><body>You are being <a href="https://staging.fleetpanda.com/users/login">redirected</a>.</body></html>
Open service 13.248.132.87:443 · staging.fleetpanda.com
2026-01-02 05:11
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://staging.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=mNX9OS2qxxiR1A0lPqFRNG9go%2FJYR%2FDYSX0YcixlkmE%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767330665"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=mNX9OS2qxxiR1A0lPqFRNG9go%2FJYR%2FDYSX0YcixlkmE%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767330665"
Server: Heroku
Set-Cookie: _fleetpanda_session=dXWnKe2az%2FCZDObobaypxuoz1JnrD2eOjh7A77VWAJ1%2BuqZQdssU5GqE1EJYqKC5Nlo69qgltBDMR%2BYmbYkFnPxq18108wlrmBDChF883GDGcVd4o4hcOCRZ4ElPPlZ0oiWXabXc94qmkWJDt5%2FrYjhrCkRxlPk7PDa67vnru7D7UrdJfJ5YRNa1Z2Nq%2BK54%2B1Pcm9tBTR4gyNBmJYeh31tL6IDw--c6%2Fi39E1W3l6mqJD--ofNHug8kyJs5zparUWK7tQ%3D%3D; domain=.staging.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: 2e63c434-847d-1820-a7b9-1893744a35ff
X-Runtime: 0.099101
Date: Fri, 02 Jan 2026 05:11:05 GMT
Content-Length: 108
Connection: close
<html><body>You are being <a href="https://staging.fleetpanda.com/users/login">redirected</a>.</body></html>
Open service 13.248.132.87:443 · staging.fleetpanda.com
2025-12-22 13:47
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://staging.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=y4eLeWedKemMc%2BSEEf%2BRGvYMpFNR3JiVZL9LIjf%2FLF0%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766411238"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=y4eLeWedKemMc%2BSEEf%2BRGvYMpFNR3JiVZL9LIjf%2FLF0%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766411238"
Server: Heroku
Set-Cookie: _fleetpanda_session=reozxMWanE7CPuL97F76ZDBDUO7yetl0RsRD5iAyMdzJUbkDCYDFxYG1EZNISv2Ve3iG6hAqmLgE9f6cpvTbTQU9NGhBT03ykOd745r%2Fe8BDXjx6MvZDc3J1L0N6vD%2Bvg7gsGcO7PEMrK75Lo3KOkW6P1z8%2FQ0nV%2FmbvCD6EdbjIeQ2jnz1ityv94c36uaq%2B5oR%2Bgc7IamS%2B%2F%2Bt%2FAx4VHBSb7pkn--IFelDrhBGqo46suI--trisIenq512rLMSSpJLjnA%3D%3D; domain=.staging.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: f27fecd6-b47a-4f15-1805-14c56f46305b
X-Runtime: 0.050757
Date: Mon, 22 Dec 2025 13:47:18 GMT
Content-Length: 108
Connection: close
<html><body>You are being <a href="https://staging.fleetpanda.com/users/login">redirected</a>.</body></html>
Open service 13.248.132.87:443 · staging.fleetpanda.com
2025-12-20 13:27
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://staging.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=e0y%2BpJYtGIkpTwVyUkcocX5q6DvN%2FldlnNTQ8bxVg6Y%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766237237"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=e0y%2BpJYtGIkpTwVyUkcocX5q6DvN%2FldlnNTQ8bxVg6Y%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766237237"
Server: Heroku
Set-Cookie: _fleetpanda_session=onf32TTAp9x47LdPCINQzC28Ynvn6cK31Zz%2FSBBq8ze8ZZuevNp8zSarKQ%2FiAV46Vw45XVPH1ZL7CZR2gSm2jrQgmJeDYJ1EDkh3QQGx4bAvQdHtOBgP55ecKqGG0yfRx03VJZMK2BrMJT32MCQLQaHuBhy6KZh2iVaKz6XDrOR6xptMxZRg1x5sSMeNP4iAfhf%2BRbQwtorkUNlFMbltOboKamV5--xkfBzKkA6nEpU9Vs--nKhx3SheZrGmiGi8ToUalg%3D%3D; domain=.staging.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: cd4278bb-0115-2155-3445-443fcc9e1c91
X-Runtime: 0.057664
Date: Sat, 20 Dec 2025 13:27:17 GMT
Content-Length: 108
Connection: close
<html><body>You are being <a href="https://staging.fleetpanda.com/users/login">redirected</a>.</body></html>