Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 23.213.161.201:443 · test-user-1.databand.ai
2026-01-23 00:55
HTTP/1.1 302 Moved Temporarily Content-Type: text/html; charset=utf-8 Content-Length: 195 Location: /app X-Robots-Tag: noindex, nofollow Permissions-Policy: geolocation=() X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Content-Security-Policy: default-src 'self'; frame-src https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self'; object-src 'none'; style-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; font-src https://1.www.s81c.com 'self' data:; worker-src 'self' blob:; img-src https://*.googletagmanager.com https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io https://www.gravatar.com 'self' data:; script-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; script-src-elem https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; connect-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin X-INSTANA-L: 1 traceparent: 00-00000000000000002c9c1a8557f04684-2c9c1a8557f04684-01 tracestate: in=2c9c1a8557f04684;2c9c1a8557f04684 X-INSTANA-T: 2c9c1a8557f04684 X-INSTANA-S: 2c9c1a8557f04684 Server-Timing: intid;desc=2c9c1a8557f04684 Expires: Fri, 23 Jan 2026 00:55:13 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 23 Jan 2026 00:55:13 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Set-Cookie: X-CSRF-TOKEN=IjIwMjhlOTI3OTgzMmM2ZjRlNTliZTMzOTllNTMyOTRiYWRjODNiN2Qi.aXLG8Q.Wo-xfFetU5Y3Y_dvl9xGx-EGS18; Expires=Fri, 23 Jan 2026 01:55:13 GMT; Max-Age=3600; Secure; Path=/; SameSite=Lax Set-Cookie: dbnd_session=00d010e7-641f-44ed-88b6-ea70bb368c71; Expires=Fri, 23 Jan 2026 01:55:13 GMT; Secure; HttpOnly; Path=/; SameSite=Lax Page title: Redirecting... <!doctype html> <html lang=en> <title>Redirecting...</title> <h1>Redirecting...</h1> <p>You should be redirected automatically to the target URL: <a href="/app">/app</a>. If not, click the link.
Open service 23.213.161.201:443 · test-user-1.databand.ai
2026-01-09 12:01
HTTP/1.1 302 Moved Temporarily Content-Type: text/html; charset=utf-8 Content-Length: 195 Location: /app X-Robots-Tag: noindex, nofollow Permissions-Policy: geolocation=() X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Content-Security-Policy: default-src 'self'; frame-src https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self'; object-src 'none'; style-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; font-src https://1.www.s81c.com 'self' data:; worker-src 'self' blob:; img-src https://*.googletagmanager.com https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io https://www.gravatar.com 'self' data:; script-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; script-src-elem https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; connect-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin X-INSTANA-L: 1 traceparent: 00-000000000000000074f23b3abe6773ad-74f23b3abe6773ad-01 tracestate: in=74f23b3abe6773ad;74f23b3abe6773ad X-INSTANA-T: 74f23b3abe6773ad X-INSTANA-S: 74f23b3abe6773ad Server-Timing: intid;desc=74f23b3abe6773ad Expires: Fri, 09 Jan 2026 12:01:31 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 12:01:31 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Set-Cookie: X-CSRF-TOKEN=IjUxMGZhZTYyYjg0MjEwMGE5NmJjNmM2MTkzMzk0MWM3Zjk3N2JlNTYi.aWDuGw.nbmPSjGHBSja151L6HKZUC137qo; Expires=Fri, 09 Jan 2026 13:01:31 GMT; Max-Age=3600; Secure; Path=/; SameSite=Lax Set-Cookie: dbnd_session=dda361c4-5b7b-4cee-8465-98f7a7cf85a1; Expires=Fri, 09 Jan 2026 13:01:31 GMT; Secure; HttpOnly; Path=/; SameSite=Lax Page title: Redirecting... <!doctype html> <html lang=en> <title>Redirecting...</title> <h1>Redirecting...</h1> <p>You should be redirected automatically to the target URL: <a href="/app">/app</a>. If not, click the link.
Open service 23.213.161.201:443 · test-user-1.databand.ai
2026-01-02 15:47
HTTP/1.1 302 Moved Temporarily Content-Type: text/html; charset=utf-8 Content-Length: 195 Location: /app X-Robots-Tag: noindex, nofollow Permissions-Policy: geolocation=() X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Content-Security-Policy: default-src 'self'; frame-src https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self'; object-src 'none'; style-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; font-src https://1.www.s81c.com 'self' data:; worker-src 'self' blob:; img-src https://*.googletagmanager.com https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io https://www.gravatar.com 'self' data:; script-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; script-src-elem https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; connect-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin X-INSTANA-L: 1 traceparent: 00-0000000000000000e57178a1505bcaf3-e57178a1505bcaf3-01 tracestate: in=e57178a1505bcaf3;e57178a1505bcaf3 X-INSTANA-T: e57178a1505bcaf3 X-INSTANA-S: e57178a1505bcaf3 Server-Timing: intid;desc=e57178a1505bcaf3 Expires: Fri, 02 Jan 2026 15:47:57 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 15:47:57 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Set-Cookie: X-CSRF-TOKEN=ImZjMmI5YmYyNmRlMjU4NTYxM2Y2OWMzNmE5OWQxYzZiMDIxNDFkMWUi.aVforQ.hAI7JGUFiNa0SRrRnQZ0g5Gq2Fc; Expires=Fri, 02 Jan 2026 16:47:57 GMT; Max-Age=3600; Secure; Path=/; SameSite=Lax Set-Cookie: dbnd_session=5126aae0-7830-4b6c-962a-ec49aae0b3ec; Expires=Fri, 02 Jan 2026 16:47:57 GMT; Secure; HttpOnly; Path=/; SameSite=Lax Page title: Redirecting... <!doctype html> <html lang=en> <title>Redirecting...</title> <h1>Redirecting...</h1> <p>You should be redirected automatically to the target URL: <a href="/app">/app</a>. If not, click the link.
Open service 23.213.161.201:443 · test-user-1.databand.ai
2025-12-22 10:13
HTTP/1.1 302 Moved Temporarily Content-Type: text/html; charset=utf-8 Content-Length: 195 Location: /app X-Robots-Tag: noindex, nofollow Permissions-Policy: geolocation=() X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: nosniff Content-Security-Policy: default-src 'self'; frame-src https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self'; object-src 'none'; style-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; font-src https://1.www.s81c.com 'self' data:; worker-src 'self' blob:; img-src https://*.googletagmanager.com https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io https://www.gravatar.com 'self' data:; script-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; script-src-elem https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' 'unsafe-inline'; connect-src https://*.googletagmanager.com https://*.walkme.com https://*.amplitude.com https://*.instana.io https://*.newrelic.com https://*.nr-data.net https://1.www.s81c.com https://*.ibm.com https://*.ibmcloud.com https://*.truste.com https://*.trustarc.com https://*.segment.com https://*.segment.io 'self' Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin X-INSTANA-L: 1 traceparent: 00-0000000000000000b8b43c49adc5b557-b8b43c49adc5b557-01 tracestate: in=b8b43c49adc5b557;b8b43c49adc5b557 X-INSTANA-T: b8b43c49adc5b557 X-INSTANA-S: b8b43c49adc5b557 Server-Timing: intid;desc=b8b43c49adc5b557 Expires: Mon, 22 Dec 2025 10:13:26 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 22 Dec 2025 10:13:26 GMT Alt-Svc: h3=":443"; ma=93600 Connection: close Set-Cookie: X-CSRF-TOKEN=IjIwMjVmMzAzZDdmODExN2QyYjIzYzM0MDNiNmJlY2M3MjI4MjA4Yzki.aUkZxg.SaQn2BHDFJ61fBX8mvdzpKcXsgs; Expires=Mon, 22 Dec 2025 11:13:26 GMT; Max-Age=3600; Secure; Path=/; SameSite=Lax Set-Cookie: dbnd_session=152bc8db-24cf-4f8e-a2c4-a3500d6e9d7c; Expires=Mon, 22 Dec 2025 11:13:26 GMT; Secure; HttpOnly; Path=/; SameSite=Lax Page title: Redirecting... <!doctype html> <html lang=en> <title>Redirecting...</title> <h1>Redirecting...</h1> <p>You should be redirected automatically to the target URL: <a href="/app">/app</a>. If not, click the link.