GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d67e802f4bb07003c9e8fd4154c928c844c43ea2d9
GraphQL introspection enabled at /api/graphql Types: 83 (by kind: ENUM: 11, INPUT_OBJECT: 18, OBJECT: 48, SCALAR: 6) Operations: - Query: Query | fields: deviceType, deviceTypes, facilities, specimenType, supportedDiseases - Mutation: Mutation | fields: addFacility, addUserToCurrentOrg, updateFacility, updateUser, updateUserPrivileges Directives: Pattern, Size, defer, deprecated, experimental_disableErrorPropagation, include, oneOf, requiredPermissions, skip, specifiedBy (total: 10)
Open service 23.50.131.157:443 · training.simplereport.gov
2026-01-23 14:52
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 24626
Content-MD5: YKIAMZQFuXvTMQ82NFeH0w==
Last-Modified: Thu, 22 Jan 2026 20:22:13 GMT
Accept-Ranges: bytes
ETag: "0x8DE59F3EE0C780B"
x-ms-request-id: 7b077854-d01e-003d-1f77-8c291e000000
x-ms-version: 2018-03-28
Expires: Fri, 23 Jan 2026 14:52:40 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 23 Jan 2026 14:52:40 GMT
Connection: close
Strict-Transport-Security: max-age=31536000 ; includeSubDomains ; preload
Page title:
Home | SimpleReport
Lock
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta name="viewport" content="width=device-width, initial-scale=1" />
<meta charset="UTF-8" />
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<title>
Home | SimpleReport
</title>
<meta name="pagemeta" content="SimpleReport is a COVID-19 testing and reporting tool that sends results to your public health department." />
<link rel="shortcut icon" type="image/ico"
href="/assets/favicons/favicon.ico">
<link rel="icon" type="image/png"
href="/assets/favicons/favicon.png">
<link rel="icon" type="image/png"
sizes="192x192"
href="/assets/favicons/favicon-192.png">
<link rel="apple-touch-icon-precomposed" type=""
href="/assets/favicons/favicon-57.png">
<link rel="apple-touch-icon-precomposed" type=""
sizes="72x72"
href="/assets/favicons/favicon-72.png">
<link rel="apple-touch-icon-precomposed" type=""
sizes="114x114"
href="/assets/favicons/favicon-114.png">
<link rel="apple-touch-icon-precomposed" type=""
sizes="144x144"
href="/assets/favicons/favicon-144.png">
<script src="/assets/js/uswds-init.min.js"></script>
<link
rel="stylesheet"
href="https://cdnjs.cloudflare.com/ajax/libs/animate.css/4.1.1/animate.min.css"
/>
<link rel="stylesheet"
href="/assets/uswds/css/styles.css?1769113330281946819">
<link rel="stylesheet"
href="/assets/uswds/css/touchpoints.css?1769113330281946819">
<!-- Digital Analytics Program roll-up, see https://analytics.usa.gov for data -->
<script id="_fed_an_ua_tag" src="https://dap.digitalgov.gov/Universal-Federated-Analytics-Min.js?agency=HHS&subagency=CDC"></script>
<meta name="robots" content="noindex nofollow" />
</head>
<body
class="site-body page-home "
>
<section
id="maintenance-banner"
class="usa-site-alert usa-site-alert--emergency usa-site-alert--no-heading display-none"
aria-label="Maintenance alert"
>
<div class="usa-alert">
<div class="usa-alert__body">
<p class="usa-alert__text">
<strong>SimpleReport is currently experiencing an outage.</strong>
<span
>We're working on getting this fixed as soon as possible.</span
>
</p>
</div>
</div>
</section>
<a class="usa-skipnav" href="#main-content">Skip to main content</a>
<section class="usa-banner" aria-label="Official government website">
<div class="usa-accordion">
<header class="usa-banner__header">
<div class="usa-banner__inner">
<div class="grid-col-auto">
<img class="usa-banner__header-flag" src="/assets/uswds/img/us_flag_small.png" alt="U.S. flag">
</div>
<div class="grid-col-fill tablet:grid-col-auto">
<p class="usa-banner__header-text">An official website of the United States government</p>
<p class="usa-banner__header-action" aria-hidden="true">Here’s how you know</p>
</div>
<button class="usa-accordion__button usa-banner__button"
aria-expanded="false" aria-controls="gov-banner" aria-label="Here's how you know this is an official website">
<span class="usa-banner__button-text">Here’s how you know</span>
</button>
</div>
</header>
<div class="usa-banner__content usa-accordion__content" id="gov-banner">
<div class="grid-row grid-gap-lg">
<div class="usa-banner__guidance tablet:grid-col-6">
<img class="usa-banner__icon usa-media-block__img" src="/assets/uswds/img/icon-dot-gov.svg" role="img" alt="Dot gov">
<div class="usa-media-block__body">
<p>
<strong>Official websites use .gov</strong>
<br/>
A <strong>.gov</strong> website belongs to an official government organization in the United States.
</p>
</div>
</div>
<div class="usa-banner__guidance tablet:grid-col-6">
<img class="usa-banner__icon usa-media-block__img" src="/assets/uswds/img/icon-https.svg" role="img" alt="Https">
<div class="usa-med
Open service 23.50.131.157:443 · training.simplereport.gov
2026-01-09 20:22
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 24626
Content-MD5: 8cm7jx9AljZ6Pg8KFH+T0g==
Last-Modified: Mon, 05 Jan 2026 16:03:25 GMT
Accept-Ranges: bytes
ETag: "0x8DE4C73F56BDC2F"
x-ms-request-id: b42f6c06-b01e-002b-5da5-81dfc9000000
x-ms-version: 2018-03-28
Expires: Fri, 09 Jan 2026 20:22:56 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 09 Jan 2026 20:22:56 GMT
Connection: close
Strict-Transport-Security: max-age=31536000 ; includeSubDomains ; preload
Page title:
Home | SimpleReport
Lock
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta name="viewport" content="width=device-width, initial-scale=1" />
<meta charset="UTF-8" />
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<title>
Home | SimpleReport
</title>
<meta name="pagemeta" content="SimpleReport is a COVID-19 testing and reporting tool that sends results to your public health department." />
<link rel="shortcut icon" type="image/ico"
href="/assets/favicons/favicon.ico">
<link rel="icon" type="image/png"
href="/assets/favicons/favicon.png">
<link rel="icon" type="image/png"
sizes="192x192"
href="/assets/favicons/favicon-192.png">
<link rel="apple-touch-icon-precomposed" type=""
href="/assets/favicons/favicon-57.png">
<link rel="apple-touch-icon-precomposed" type=""
sizes="72x72"
href="/assets/favicons/favicon-72.png">
<link rel="apple-touch-icon-precomposed" type=""
sizes="114x114"
href="/assets/favicons/favicon-114.png">
<link rel="apple-touch-icon-precomposed" type=""
sizes="144x144"
href="/assets/favicons/favicon-144.png">
<script src="/assets/js/uswds-init.min.js"></script>
<link
rel="stylesheet"
href="https://cdnjs.cloudflare.com/ajax/libs/animate.css/4.1.1/animate.min.css"
/>
<link rel="stylesheet"
href="/assets/uswds/css/styles.css?1767629000930168341">
<link rel="stylesheet"
href="/assets/uswds/css/touchpoints.css?1767629000930168341">
<!-- Digital Analytics Program roll-up, see https://analytics.usa.gov for data -->
<script id="_fed_an_ua_tag" src="https://dap.digitalgov.gov/Universal-Federated-Analytics-Min.js?agency=HHS&subagency=CDC"></script>
<meta name="robots" content="noindex nofollow" />
</head>
<body
class="site-body page-home "
>
<section
id="maintenance-banner"
class="usa-site-alert usa-site-alert--emergency usa-site-alert--no-heading display-none"
aria-label="Maintenance alert"
>
<div class="usa-alert">
<div class="usa-alert__body">
<p class="usa-alert__text">
<strong>SimpleReport is currently experiencing an outage.</strong>
<span
>We're working on getting this fixed as soon as possible.</span
>
</p>
</div>
</div>
</section>
<a class="usa-skipnav" href="#main-content">Skip to main content</a>
<section class="usa-banner" aria-label="Official government website">
<div class="usa-accordion">
<header class="usa-banner__header">
<div class="usa-banner__inner">
<div class="grid-col-auto">
<img class="usa-banner__header-flag" src="/assets/uswds/img/us_flag_small.png" alt="U.S. flag">
</div>
<div class="grid-col-fill tablet:grid-col-auto">
<p class="usa-banner__header-text">An official website of the United States government</p>
<p class="usa-banner__header-action" aria-hidden="true">Here’s how you know</p>
</div>
<button class="usa-accordion__button usa-banner__button"
aria-expanded="false" aria-controls="gov-banner" aria-label="Here's how you know this is an official website">
<span class="usa-banner__button-text">Here’s how you know</span>
</button>
</div>
</header>
<div class="usa-banner__content usa-accordion__content" id="gov-banner">
<div class="grid-row grid-gap-lg">
<div class="usa-banner__guidance tablet:grid-col-6">
<img class="usa-banner__icon usa-media-block__img" src="/assets/uswds/img/icon-dot-gov.svg" role="img" alt="Dot gov">
<div class="usa-media-block__body">
<p>
<strong>Official websites use .gov</strong>
<br/>
A <strong>.gov</strong> website belongs to an official government organization in the United States.
</p>
</div>
</div>
<div class="usa-banner__guidance tablet:grid-col-6">
<img class="usa-banner__icon usa-media-block__img" src="/assets/uswds/img/icon-https.svg" role="img" alt="Https">
<div class="usa-med
Open service 23.50.131.157:443 · training.simplereport.gov
2026-01-03 00:45
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 24626
Content-MD5: JNbUQ9dQ1TQYimltLYNW+A==
Last-Modified: Mon, 17 Nov 2025 16:24:12 GMT
Accept-Ranges: bytes
ETag: "0x8DE25F5BE894F73"
x-ms-request-id: 7cad093f-001e-003e-084a-7cc87a000000
x-ms-version: 2018-03-28
Expires: Sat, 03 Jan 2026 00:45:53 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 03 Jan 2026 00:45:53 GMT
Connection: close
Strict-Transport-Security: max-age=31536000 ; includeSubDomains ; preload
Page title:
Home | SimpleReport
Lock
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta name="viewport" content="width=device-width, initial-scale=1" />
<meta charset="UTF-8" />
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<title>
Home | SimpleReport
</title>
<meta name="pagemeta" content="SimpleReport is a COVID-19 testing and reporting tool that sends results to your public health department." />
<link rel="shortcut icon" type="image/ico"
href="/assets/favicons/favicon.ico">
<link rel="icon" type="image/png"
href="/assets/favicons/favicon.png">
<link rel="icon" type="image/png"
sizes="192x192"
href="/assets/favicons/favicon-192.png">
<link rel="apple-touch-icon-precomposed" type=""
href="/assets/favicons/favicon-57.png">
<link rel="apple-touch-icon-precomposed" type=""
sizes="72x72"
href="/assets/favicons/favicon-72.png">
<link rel="apple-touch-icon-precomposed" type=""
sizes="114x114"
href="/assets/favicons/favicon-114.png">
<link rel="apple-touch-icon-precomposed" type=""
sizes="144x144"
href="/assets/favicons/favicon-144.png">
<script src="/assets/js/uswds-init.min.js"></script>
<link
rel="stylesheet"
href="https://cdnjs.cloudflare.com/ajax/libs/animate.css/4.1.1/animate.min.css"
/>
<link rel="stylesheet"
href="/assets/uswds/css/styles.css?1763396646677043957">
<link rel="stylesheet"
href="/assets/uswds/css/touchpoints.css?1763396646677043957">
<!-- Digital Analytics Program roll-up, see https://analytics.usa.gov for data -->
<script id="_fed_an_ua_tag" src="https://dap.digitalgov.gov/Universal-Federated-Analytics-Min.js?agency=HHS&subagency=CDC"></script>
<meta name="robots" content="noindex nofollow" />
</head>
<body
class="site-body page-home "
>
<section
id="maintenance-banner"
class="usa-site-alert usa-site-alert--emergency usa-site-alert--no-heading display-none"
aria-label="Maintenance alert"
>
<div class="usa-alert">
<div class="usa-alert__body">
<p class="usa-alert__text">
<strong>SimpleReport is currently experiencing an outage.</strong>
<span
>We're working on getting this fixed as soon as possible.</span
>
</p>
</div>
</div>
</section>
<a class="usa-skipnav" href="#main-content">Skip to main content</a>
<section class="usa-banner" aria-label="Official government website">
<div class="usa-accordion">
<header class="usa-banner__header">
<div class="usa-banner__inner">
<div class="grid-col-auto">
<img class="usa-banner__header-flag" src="/assets/uswds/img/us_flag_small.png" alt="U.S. flag">
</div>
<div class="grid-col-fill tablet:grid-col-auto">
<p class="usa-banner__header-text">An official website of the United States government</p>
<p class="usa-banner__header-action" aria-hidden="true">Here’s how you know</p>
</div>
<button class="usa-accordion__button usa-banner__button"
aria-expanded="false" aria-controls="gov-banner" aria-label="Here's how you know this is an official website">
<span class="usa-banner__button-text">Here’s how you know</span>
</button>
</div>
</header>
<div class="usa-banner__content usa-accordion__content" id="gov-banner">
<div class="grid-row grid-gap-lg">
<div class="usa-banner__guidance tablet:grid-col-6">
<img class="usa-banner__icon usa-media-block__img" src="/assets/uswds/img/icon-dot-gov.svg" role="img" alt="Dot gov">
<div class="usa-media-block__body">
<p>
<strong>Official websites use .gov</strong>
<br/>
A <strong>.gov</strong> website belongs to an official government organization in the United States.
</p>
</div>
</div>
<div class="usa-banner__guidance tablet:grid-col-6">
<img class="usa-banner__icon usa-media-block__img" src="/assets/uswds/img/icon-https.svg" role="img" alt="Https">
<div class="usa-med
Open service 23.50.131.157:443 · training.simplereport.gov
2025-12-23 08:09
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 24626
Content-MD5: JNbUQ9dQ1TQYimltLYNW+A==
Last-Modified: Mon, 17 Nov 2025 16:24:12 GMT
Accept-Ranges: bytes
ETag: "0x8DE25F5BE894F73"
x-ms-request-id: e46d4a7d-901e-0003-28e3-73be61000000
x-ms-version: 2018-03-28
Expires: Tue, 23 Dec 2025 08:09:59 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Tue, 23 Dec 2025 08:09:59 GMT
Connection: close
Strict-Transport-Security: max-age=31536000 ; includeSubDomains ; preload
Page title:
Home | SimpleReport
Lock
<!DOCTYPE html>
<html lang="en-US">
<head>
<meta name="viewport" content="width=device-width, initial-scale=1" />
<meta charset="UTF-8" />
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<title>
Home | SimpleReport
</title>
<meta name="pagemeta" content="SimpleReport is a COVID-19 testing and reporting tool that sends results to your public health department." />
<link rel="shortcut icon" type="image/ico"
href="/assets/favicons/favicon.ico">
<link rel="icon" type="image/png"
href="/assets/favicons/favicon.png">
<link rel="icon" type="image/png"
sizes="192x192"
href="/assets/favicons/favicon-192.png">
<link rel="apple-touch-icon-precomposed" type=""
href="/assets/favicons/favicon-57.png">
<link rel="apple-touch-icon-precomposed" type=""
sizes="72x72"
href="/assets/favicons/favicon-72.png">
<link rel="apple-touch-icon-precomposed" type=""
sizes="114x114"
href="/assets/favicons/favicon-114.png">
<link rel="apple-touch-icon-precomposed" type=""
sizes="144x144"
href="/assets/favicons/favicon-144.png">
<script src="/assets/js/uswds-init.min.js"></script>
<link
rel="stylesheet"
href="https://cdnjs.cloudflare.com/ajax/libs/animate.css/4.1.1/animate.min.css"
/>
<link rel="stylesheet"
href="/assets/uswds/css/styles.css?1763396646677043957">
<link rel="stylesheet"
href="/assets/uswds/css/touchpoints.css?1763396646677043957">
<!-- Digital Analytics Program roll-up, see https://analytics.usa.gov for data -->
<script id="_fed_an_ua_tag" src="https://dap.digitalgov.gov/Universal-Federated-Analytics-Min.js?agency=HHS&subagency=CDC"></script>
<meta name="robots" content="noindex nofollow" />
</head>
<body
class="site-body page-home "
>
<section
id="maintenance-banner"
class="usa-site-alert usa-site-alert--emergency usa-site-alert--no-heading display-none"
aria-label="Maintenance alert"
>
<div class="usa-alert">
<div class="usa-alert__body">
<p class="usa-alert__text">
<strong>SimpleReport is currently experiencing an outage.</strong>
<span
>We're working on getting this fixed as soon as possible.</span
>
</p>
</div>
</div>
</section>
<a class="usa-skipnav" href="#main-content">Skip to main content</a>
<section class="usa-banner" aria-label="Official government website">
<div class="usa-accordion">
<header class="usa-banner__header">
<div class="usa-banner__inner">
<div class="grid-col-auto">
<img class="usa-banner__header-flag" src="/assets/uswds/img/us_flag_small.png" alt="U.S. flag">
</div>
<div class="grid-col-fill tablet:grid-col-auto">
<p class="usa-banner__header-text">An official website of the United States government</p>
<p class="usa-banner__header-action" aria-hidden="true">Here’s how you know</p>
</div>
<button class="usa-accordion__button usa-banner__button"
aria-expanded="false" aria-controls="gov-banner" aria-label="Here's how you know this is an official website">
<span class="usa-banner__button-text">Here’s how you know</span>
</button>
</div>
</header>
<div class="usa-banner__content usa-accordion__content" id="gov-banner">
<div class="grid-row grid-gap-lg">
<div class="usa-banner__guidance tablet:grid-col-6">
<img class="usa-banner__icon usa-media-block__img" src="/assets/uswds/img/icon-dot-gov.svg" role="img" alt="Dot gov">
<div class="usa-media-block__body">
<p>
<strong>Official websites use .gov</strong>
<br/>
A <strong>.gov</strong> website belongs to an official government organization in the United States.
</p>
</div>
</div>
<div class="usa-banner__guidance tablet:grid-col-6">
<img class="usa-banner__icon usa-media-block__img" src="/assets/uswds/img/icon-https.svg" role="img" alt="Https">
<div class="usa-med