Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 142.250.186.147:443 · tru-admin-service-dev.tmsystems.ai
2026-01-22 11:56
HTTP/1.1 401 Unauthorized
content-type: application/json; charset=utf-8
x-cloud-trace-context: 33dda7f576b7bd0cffec57fc6434761f
date: Thu, 22 Jan 2026 11:56:06 GMT
server: Google Frontend
Content-Length: 118
Connection: close
{"error":"Unauthorized - X-Request-ID header required. All requests must go through the API gateway.","success":false}
Open service 142.250.74.211:80 · tru-admin-service-dev.tmsystems.ai
2026-01-13 01:16
HTTP/1.1 302 Found location: https://tru-admin-service-dev.tmsystems.ai/ x-cloud-trace-context: f2de2c63da5b7b45ad97da29f053e7fd date: Tue, 13 Jan 2026 01:17:53 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 142.250.74.211:443 · tru-admin-service-dev.tmsystems.ai
2026-01-13 01:16
HTTP/1.1 401 Unauthorized
content-type: application/json; charset=utf-8
x-cloud-trace-context: ece2759542e0033f24202ef8ff524ba6
date: Tue, 13 Jan 2026 01:16:55 GMT
server: Google Frontend
Content-Length: 118
Connection: close
{"error":"Unauthorized - X-Request-ID header required. All requests must go through the API gateway.","success":false}
Open service 2a00:1450:4001:803::2013:443 · tru-admin-service-dev.tmsystems.ai
2026-01-13 01:16
HTTP/1.1 401 Unauthorized
content-type: application/json; charset=utf-8
x-cloud-trace-context: bfd025f011eb79a531c369f6dea6dd83
date: Tue, 13 Jan 2026 01:16:54 GMT
server: Google Frontend
Content-Length: 118
Connection: close
{"error":"Unauthorized - X-Request-ID header required. All requests must go through the API gateway.","success":false}
Open service 2a00:1450:4001:803::2013:80 · tru-admin-service-dev.tmsystems.ai
2026-01-13 01:16
HTTP/1.1 302 Found location: https://tru-admin-service-dev.tmsystems.ai/ x-cloud-trace-context: 968a525e91687f10076f8ae9244ec605;o=1 date: Tue, 13 Jan 2026 01:17:52 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 142.250.186.147:443 · tru-admin-service-dev.tmsystems.ai
2026-01-10 01:06
HTTP/1.1 401 Unauthorized
content-type: application/json; charset=utf-8
x-cloud-trace-context: a1a725d92dff88ca178b9009ba7f7777
date: Sat, 10 Jan 2026 01:06:30 GMT
server: Google Frontend
Content-Length: 118
Connection: close
{"error":"Unauthorized - X-Request-ID header required. All requests must go through the API gateway.","success":false}