Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 184.86.103.201:443 · buy.homangm.com
2026-02-07 09:59
HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-Trace-Id: a10c5ced76fffbc7f83916d6653d05a3
X-Span-Id: 18526f2dc9b52e91
brand:
x-azure-ref: 20260207T095909Z-16cbd5888ccjjz6shC1TEBz26n000000075g000000001ub9
X-Akamai-Transformed: 9 832 0 pmb=mRUM,2
Expires: Sat, 07 Feb 2026 09:59:09 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 07 Feb 2026 09:59:09 GMT
Content-Length: 6534
Connection: close
Server-Timing: cdn-cache; desc=MISS
Server-Timing: edge; dur=264
Server-Timing: origin; dur=95
x-tekion-validation-edgescape: X-Akamai-Edgescape: georegion=272,country_code=US,region_code=NJ,city=NORTHBERGEN,dma=501,pmsa=3640,msa=5602, areacode=201,county=HUDSON,fips=34017,lat=40.7933,long=-74.0263,timezone=EST,zip=07047, continent=NA,throughput=vhigh,network=,asnum=14061,network_type=hosted
tek-akamai-grn: 0.c96656b8.1770458348.e3a1c9f
Server-Timing: ak_p; desc="1770458348758_3092670153_238689439_35954_6792_87_94_-";dur=1
<!DOCTYPE html><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width"/><script id="new-relic-script" src="https://tkprodpublic.blob.core.windows.net/public-assets/aec-web/multibrand/scripts/real-time-monitoring.js" async=""></script><meta name="next-head-count" content="3"/> <link rel="preload" href="/_next/static/css/0d239232f63e41d3.css" as="style"/><link rel="stylesheet" href="/_next/static/css/0d239232f63e41d3.css" data-n-g=""/><link rel="preload" href="/_next/static/css/d300201644588d58.css" as="style"/><link rel="stylesheet" href="/_next/static/css/d300201644588d58.css" data-n-p=""/><noscript data-n-css=""></noscript><script defer="" nomodule="" src="/_next/static/chunks/polyfills-c67a75d1b6f99dc8.js"></script><script src="/_next/static/chunks/webpack-146274181410545f.js" defer=""></script><script src="/_next/static/chunks/framework-f5f38df2f52da672.js" defer=""></script><script src="/_next/static/chunks/main-fa12d6bde222855b.js" defer=""></script><script src="/_next/static/chunks/pages/_app-db368cedd5d49132.js" defer=""></script><script src="/_next/static/chunks/pages/index-198fc3e4281dc54f.js" defer=""></script><script src="/_next/static/1769067587312/_buildManifest.js" defer=""></script><script src="/_next/static/1769067587312/_ssgManifest.js" defer=""></script><style data-emotion="css "></style>
<script>(window.BOOMR_mq=window.BOOMR_mq||[]).push(["addVar",{"rua.upush":"false","rua.cpush":"false","rua.upre":"false","rua.cpre":"false","rua.uprl":"false","rua.cprl":"false","rua.cprf":"false","rua.trans":"","rua.cook":"false","rua.ims":"false","rua.ufprl":"false","rua.cfprl":"false","rua.isuxp":"false","rua.texp":"norulematch","rua.ceh":"false","rua.ueh":"false","rua.ieh.st":"0"}]);</script>
<script>!function(e){var n="https://s.go-mpulse.net/boomerang/";if("True"=="True")e.BOOMR_config=e.BOOMR_config||{},e.BOOMR_config.PageParams=e.BOOMR_config.PageParams||{},e.BOOMR_config.PageParams.pci=!0,n="https://s2.go-mpulse.net/boomerang/";if(window.BOOMR_API_key="SQG4M-27HJS-MDSTU-JE38T-CKRCQ",function(){function e(){if(!r){var e=document.createElement("script");e.id="boomr-scr-as",e.src=window.BOOMR.url,e.async=!0,o.appendChild(e),r=!0}}function t(e){r=!0;var n,t,a,i,d=document,O=window;if(window.BOOMR.snippetMethod=e?"if":"i",t=function(e,n){var t=d.createElement("script");t.id=n||"boomr-if-as",t.src=window.BOOMR.url,BOOMR_lstart=(new Date).getTime(),e=e||d.body,e.appendChild(t)},!window.addEventListener&&window.attachEvent&&navigator.userAgent.match(/MSIE [67]\./))return window.BOOMR.snippetMethod="s",void t(o,"boomr-async");a=document.createElement("IFRAME"),a.src="about:blank",a.title="",a.role="presentation",a.loading="eager",i=(a.frameElement||a).style,i.width=0,i.height=0,i.border=0,i.display="none",o.appendChild(a);try{O=a.contentWindow,d=O.document.open()}catch(_){n=document.domain,a.src="javascript:var d=document.open();d.domain='"+n+"';void 0;",O=a.contentWindow,d=O.document.open()}if(n)d._boomrl=function(){this.domain=n,t()},d.write("<bo"+"dy onload='document._boomrl();'>");else if(O._boomrl=function(){t()},O.addEventListener)O.addEventListener("load",O._boomrl,!1);else if(O.attachEvent)O.attachEvent("onload",O._boomrl);d.close()}function a(e){window.BOOMR_onload=e&&e.timeStamp||(new Date).getTime()}if(!window.BOOMR||!window.BOOMR.version&&!window.BOOMR.snippetExecuted){window.BOOMR=window.BOOMR||{},window.BOOMR.snippetStart=(new Date).getTime(),window.BOOMR.snippetExecuted=!0,window.BOOMR.snippetVersion=14,window.BOOMR.url=n+"SQG4M-27HJS-MDSTU-JE38T-CKRCQ";var i=document.currentScript||document.getElementsByTagName("script")[0],o=i.parentNode,r=!1,d=document.createElement("link");if(d.relList&&"function"==typeof d.relList.supports&&d.relList.supports("preload")&&"as"in d)window.BOOMR.snippetMethod="p",d.href=window.BOOMR.url,d.rel="preload",d.as="script",d.addEventListener("load",e),d.addEventListener("error",function(){t(!0)}),setTimeout(function(){if(!r)t(!0)},3e3),BOOMR_lstart=(new Date).getTime(),o.appendChild(d);else t(!1);if(window.
Open service 184.86.103.201:80 · neutrogenaaveenoproductrecall.com
2026-01-25 11:34
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 383 Expires: Sun, 25 Jan 2026 11:34:53 GMT Cache-Control: max-age=0, no-cache Pragma: no-cache Date: Sun, 25 Jan 2026 11:34:53 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Akamai-GRN: 0.c96656b8.1769340893.2512854d Server-Timing: ak_p; desc="1769340893655_3092670153_621970765_12_8219_99_0_-";dur=1 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://neutrogenaaveenoproductrecall.com/" on this server.<P> Reference #18.c96656b8.1769340893.2512854d <P>https://errors.edgesuite.net/18.c96656b8.1769340893.2512854d</P> </BODY> </HTML>
Open service 184.86.103.201:443 · neutrogenaaveenoproductrecall.com
2026-01-25 11:34
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 383 Expires: Sun, 25 Jan 2026 11:34:31 GMT Cache-Control: max-age=0, no-cache Pragma: no-cache Date: Sun, 25 Jan 2026 11:34:31 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Akamai-GRN: 0.c96656b8.1769340871.2511990d Server-Timing: ak_p; desc="1769340871132_3092670153_621910285_16_21762_0_3_-";dur=1 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://neutrogenaaveenoproductrecall.com/" on this server.<P> Reference #18.c96656b8.1769340871.2511990d <P>https://errors.edgesuite.net/18.c96656b8.1769340871.2511990d</P> </BODY> </HTML>
Open service 184.86.103.201:443 · rhinocort.com.au
2026-01-25 11:15
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 370 Expires: Sun, 25 Jan 2026 11:15:46 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 25 Jan 2026 11:15:46 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Akamai-GRN: 0.d26656b8.1769339746.1fb3a627 Server-Timing: ak_p; desc="1769339746893_3092670162_531867175_14_8277_0_3_-";dur=1 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://rhinocort.com.au/" on this server.<P> Reference #18.d26656b8.1769339746.1fb3a627 <P>https://errors.edgesuite.net/18.d26656b8.1769339746.1fb3a627</P> </BODY> </HTML>
Open service 184.86.103.201:80 · rhinocort.com.au
2026-01-25 11:15
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 370 Expires: Sun, 25 Jan 2026 11:16:08 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Sun, 25 Jan 2026 11:16:08 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 Akamai-GRN: 0.c96656b8.1769339768.24e8a2cb Server-Timing: ak_p; desc="1769339768812_3092670153_619225803_13_9095_1_0_-";dur=1 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://rhinocort.com.au/" on this server.<P> Reference #18.c96656b8.1769339768.24e8a2cb <P>https://errors.edgesuite.net/18.c96656b8.1769339768.24e8a2cb</P> </BODY> </HTML>
Open service 184.86.103.201:443 · api.omniai-dev.omnicomgroup.com
2026-01-23 06:09
HTTP/1.1 403 Forbidden
Content-Type: application/json
Content-Length: 42
x-amzn-RequestId: 117003f7-bc06-410d-9f9a-5ffa16e40637
x-amzn-ErrorType: MissingAuthenticationTokenException
x-amz-apigw-id: Xn-JyH0sIAMEWuQ=
Expires: Fri, 23 Jan 2026 06:09:40 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 23 Jan 2026 06:09:40 GMT
Connection: close
Akamai-GRN: 0.d26656b8.1769148580.14614064
{"message":"Missing Authentication Token"}
Open service 184.86.103.201:443 · synthetics.cloud.ibm.com
2026-01-07 21:20
HTTP/1.1 302 Moved Temporarily Location: https://us-east.appid.cloud.ibm.com/oauth/v4/f60b0df0-5331-4dcf-989b-7ac436792275/authorization?client_id=e807cdf7-f8c0-4b93-afff-87400cc8566d&response_type=code&redirect_uri=https://synthetics.cloud.ibm.com/op/callback&scope=appid_default&state=U_7GPssFsMFhNtfN6PvgSwRVtc8%3D Content-Length: 0 x-envoy-upstream-service-time: 7 Expires: Wed, 07 Jan 2026 21:20:58 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Wed, 07 Jan 2026 21:20:58 GMT Connection: close Set-Cookie: connect.sid=s%3ASp0xA7GNijS8Q6h85azKAJWJgLNebds6.4bqJD3DYXDM9VqiaaKdQxww44FZ8tpjkiaTfqVGOma0; Path=/; Expires=Wed, 07 Jan 2026 21:50:58 GMT; HttpOnly Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=46 Server-Timing: origin; dur=12 Server-Timing: ak_p; desc="1767820858473_3092670153_2634601857_5794_8823_99_102_-";dur=1
Open service 184.86.103.201:80 · ai-assistant.cloud.ibm.com
2026-01-05 14:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://ai-assistant.cloud.ibm.com/ Expires: Mon, 05 Jan 2026 14:13:35 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 05 Jan 2026 14:13:35 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 AIContextualHelp-GRN: 0.c96656b8.1767622415.860b0611 Server-Timing: ak_p; desc="1767622415855_3092670153_2248869393_10_10226_94_0_-";dur=1
Open service 184.86.103.201:443 · ai-assistant.cloud.ibm.com
2026-01-05 14:13
HTTP/1.1 404 Not Found Content-Length: 0 Expires: Mon, 05 Jan 2026 14:13:32 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Mon, 05 Jan 2026 14:13:32 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=5 Server-Timing: origin; dur=92 Alt-Svc: h3=":443"; ma=93600 AIContextualHelp-GRN: 0.d96656b8.1767622412.d0be168 Strict-Transport-Security: max-age=15768000 ; includeSubDomains Server-Timing: ak_p; desc="1767622412576_3092670169_218882408_9603_12400_18_33_-";dur=1