Heroku
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 13.248.244.96:443 · tes.callaway.cloud
2026-01-09 10:15
HTTP/1.1 200 OK
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Cache-Control: public, max-age=0
Content-Length: 667
Content-Type: text/html; charset=UTF-8
Date: Fri, 09 Jan 2026 10:15:31 GMT
Etag: W/"29b-1993a0652c8"
Last-Modified: Thu, 11 Sep 2025 18:25:17 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=W4FXvkhgh61MqHp4Eu3yKq47GU1NqNQ1hTOTmLguaCI%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767953731"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=W4FXvkhgh61MqHp4Eu3yKq47GU1NqNQ1hTOTmLguaCI%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767953731"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Page title: Callaway Time Tracking - production
<!doctype html><html lang="en"><head><meta charset="utf-8"/><link rel="icon" href="/favicon.ico"/><meta name="viewport" content="width=device-width,initial-scale=1"/><meta name="theme-color" content="#000000"/><meta name="description" content="Callaway Time Tracking App"/><link rel="apple-touch-icon" href="/logo192.png"/><link rel="manifest" href="/productionManifest.json"/><title>Callaway Time Tracking - production</title><script defer="defer" src="/static/js/main.880b03d9.js"></script><link href="/static/css/main.14ed7fef.css" rel="stylesheet"></head><body><noscript>You need to enable JavaScript to run this app.</noscript><div id="root"></div></body></html>
Open service 35.71.179.82:80 · tes.callaway.cloud
2026-01-08 22:10
HTTP/1.1 200 OK
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Cache-Control: public, max-age=0
Content-Length: 667
Content-Type: text/html; charset=UTF-8
Date: Thu, 08 Jan 2026 22:11:08 GMT
Etag: W/"29b-1993a0652c8"
Last-Modified: Thu, 11 Sep 2025 18:25:17 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=ZmQ1ZfRaXiKm60yyXKlMrNondm%2BJmWkg0anQketqgAc%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767910268"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=ZmQ1ZfRaXiKm60yyXKlMrNondm%2BJmWkg0anQketqgAc%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767910268"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Page title: Callaway Time Tracking - production
<!doctype html><html lang="en"><head><meta charset="utf-8"/><link rel="icon" href="/favicon.ico"/><meta name="viewport" content="width=device-width,initial-scale=1"/><meta name="theme-color" content="#000000"/><meta name="description" content="Callaway Time Tracking App"/><link rel="apple-touch-icon" href="/logo192.png"/><link rel="manifest" href="/productionManifest.json"/><title>Callaway Time Tracking - production</title><script defer="defer" src="/static/js/main.880b03d9.js"></script><link href="/static/css/main.14ed7fef.css" rel="stylesheet"></head><body><noscript>You need to enable JavaScript to run this app.</noscript><div id="root"></div></body></html>
Open service 13.248.244.96:443 · tes.callaway.cloud
2026-01-02 14:17
HTTP/1.1 200 OK
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Cache-Control: public, max-age=0
Content-Length: 667
Content-Type: text/html; charset=UTF-8
Date: Fri, 02 Jan 2026 14:17:30 GMT
Etag: W/"29b-1993a0652c8"
Last-Modified: Thu, 11 Sep 2025 18:25:17 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=cG7XuJTUZ46YfhbiiWzTB4nK%2BBuEIjFYkj370d7TuWM%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767363450"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=cG7XuJTUZ46YfhbiiWzTB4nK%2BBuEIjFYkj370d7TuWM%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767363450"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Page title: Callaway Time Tracking - production
<!doctype html><html lang="en"><head><meta charset="utf-8"/><link rel="icon" href="/favicon.ico"/><meta name="viewport" content="width=device-width,initial-scale=1"/><meta name="theme-color" content="#000000"/><meta name="description" content="Callaway Time Tracking App"/><link rel="apple-touch-icon" href="/logo192.png"/><link rel="manifest" href="/productionManifest.json"/><title>Callaway Time Tracking - production</title><script defer="defer" src="/static/js/main.880b03d9.js"></script><link href="/static/css/main.14ed7fef.css" rel="stylesheet"></head><body><noscript>You need to enable JavaScript to run this app.</noscript><div id="root"></div></body></html>
Open service 35.71.179.82:80 · tes.callaway.cloud
2026-01-02 11:54
HTTP/1.1 200 OK
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Cache-Control: public, max-age=0
Content-Length: 667
Content-Type: text/html; charset=UTF-8
Date: Fri, 02 Jan 2026 11:54:46 GMT
Etag: W/"29b-1993a0652c8"
Last-Modified: Thu, 11 Sep 2025 18:25:17 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=izyDtp4f5jXrqdngS%2FgYYOtxqQpfGO8XTkUgfHPYzTk%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767354886"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=izyDtp4f5jXrqdngS%2FgYYOtxqQpfGO8XTkUgfHPYzTk%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767354886"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Page title: Callaway Time Tracking - production
<!doctype html><html lang="en"><head><meta charset="utf-8"/><link rel="icon" href="/favicon.ico"/><meta name="viewport" content="width=device-width,initial-scale=1"/><meta name="theme-color" content="#000000"/><meta name="description" content="Callaway Time Tracking App"/><link rel="apple-touch-icon" href="/logo192.png"/><link rel="manifest" href="/productionManifest.json"/><title>Callaway Time Tracking - production</title><script defer="defer" src="/static/js/main.880b03d9.js"></script><link href="/static/css/main.14ed7fef.css" rel="stylesheet"></head><body><noscript>You need to enable JavaScript to run this app.</noscript><div id="root"></div></body></html>
Open service 35.71.179.82:80 · tes.callaway.cloud
2025-12-22 16:55
HTTP/1.1 200 OK
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Cache-Control: public, max-age=0
Content-Length: 667
Content-Type: text/html; charset=UTF-8
Date: Mon, 22 Dec 2025 16:55:56 GMT
Etag: W/"29b-1993a0652c8"
Last-Modified: Thu, 11 Sep 2025 18:25:17 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=vO0FR4P73sjkdf96%2FbGa%2Bf8CeuALTEeW355224GjW7Y%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766422556"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=vO0FR4P73sjkdf96%2FbGa%2Bf8CeuALTEeW355224GjW7Y%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766422556"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Page title: Callaway Time Tracking - production
<!doctype html><html lang="en"><head><meta charset="utf-8"/><link rel="icon" href="/favicon.ico"/><meta name="viewport" content="width=device-width,initial-scale=1"/><meta name="theme-color" content="#000000"/><meta name="description" content="Callaway Time Tracking App"/><link rel="apple-touch-icon" href="/logo192.png"/><link rel="manifest" href="/productionManifest.json"/><title>Callaway Time Tracking - production</title><script defer="defer" src="/static/js/main.880b03d9.js"></script><link href="/static/css/main.14ed7fef.css" rel="stylesheet"></head><body><noscript>You need to enable JavaScript to run this app.</noscript><div id="root"></div></body></html>
Open service 35.71.179.82:80 · tes.callaway.cloud
2025-12-20 15:05
HTTP/1.1 200 OK
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Cache-Control: public, max-age=0
Content-Length: 667
Content-Type: text/html; charset=UTF-8
Date: Sat, 20 Dec 2025 15:05:36 GMT
Etag: W/"29b-1993a0652c8"
Last-Modified: Thu, 11 Sep 2025 18:25:17 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=fptOpKKUWfzp%2FRTAN%2FJsmovQtwZwDBcKEhP739kVP8g%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766243136"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=fptOpKKUWfzp%2FRTAN%2FJsmovQtwZwDBcKEhP739kVP8g%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766243136"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Page title: Callaway Time Tracking - production
<!doctype html><html lang="en"><head><meta charset="utf-8"/><link rel="icon" href="/favicon.ico"/><meta name="viewport" content="width=device-width,initial-scale=1"/><meta name="theme-color" content="#000000"/><meta name="description" content="Callaway Time Tracking App"/><link rel="apple-touch-icon" href="/logo192.png"/><link rel="manifest" href="/productionManifest.json"/><title>Callaway Time Tracking - production</title><script defer="defer" src="/static/js/main.880b03d9.js"></script><link href="/static/css/main.14ed7fef.css" rel="stylesheet"></head><body><noscript>You need to enable JavaScript to run this app.</noscript><div id="root"></div></body></html>
Open service 13.248.244.96:443 · tes.callaway.cloud
2025-12-20 11:39
HTTP/1.1 200 OK
Accept-Ranges: bytes
Access-Control-Allow-Origin: *
Cache-Control: public, max-age=0
Content-Length: 667
Content-Type: text/html; charset=UTF-8
Date: Sat, 20 Dec 2025 11:39:51 GMT
Etag: W/"29b-1993a0652c8"
Last-Modified: Thu, 11 Sep 2025 18:25:17 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=in4iBaeRxI%2F3Ly3ECTTiY%2BZu9UWMdezffzWNcAILKd0%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766230791"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=in4iBaeRxI%2F3Ly3ECTTiY%2BZu9UWMdezffzWNcAILKd0%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766230791"
Server: Heroku
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Page title: Callaway Time Tracking - production
<!doctype html><html lang="en"><head><meta charset="utf-8"/><link rel="icon" href="/favicon.ico"/><meta name="viewport" content="width=device-width,initial-scale=1"/><meta name="theme-color" content="#000000"/><meta name="description" content="Callaway Time Tracking App"/><link rel="apple-touch-icon" href="/logo192.png"/><link rel="manifest" href="/productionManifest.json"/><title>Callaway Time Tracking - production</title><script defer="defer" src="/static/js/main.880b03d9.js"></script><link href="/static/css/main.14ed7fef.css" rel="stylesheet"></head><body><noscript>You need to enable JavaScript to run this app.</noscript><div id="root"></div></body></html>