istio-envoy
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 35.208.61.96:443 ยท api.hpdp.dlp.adeptmind.net
2026-01-23 12:34
HTTP/1.1 200 OK
access-control-allow-credentials: true
access-control-allow-headers: *
access-control-allow-methods: POST,HEAD,OPTIONS,GET
access-control-allow-origin: *
cache-control: no-store
content-security-policy: default-src 'self'; connect-src *; font-src *; script-src-elem * 'unsafe-inline'; img-src * data:; style-src * 'unsafe-inline';
content-type: application/json; charset=utf-8
permissions-policy: geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()
referrer-policy: strict-origin
strict-transport-security: max-age=31536000; includeSubDomains
x-content-type-options: nosniff
x-frame-options: DENY
x-xss-protection: 1; mode=block
date: Fri, 23 Jan 2026 12:34:21 GMT
content-length: 184
x-envoy-upstream-service-time: 3
server: istio-envoy
connection: close
{"message":"Welcome to the AdeptMind HPDP API ๐","swagger":"https://api.hpdp.dlp.adeptmind.net/swagger/index.html","docs":"https://api.hpdp.dlp.adeptmind.net/static/stoplight.html"}
Open service 35.208.61.96:443 ยท api.hpdp.adeptmind.ai
2026-01-23 09:33
HTTP/1.1 200 OK
access-control-allow-credentials: true
access-control-allow-headers: *
access-control-allow-methods: POST,HEAD,OPTIONS,GET
access-control-allow-origin: *
cache-control: no-store
content-security-policy: default-src 'self'; connect-src *; font-src *; script-src-elem * 'unsafe-inline'; img-src * data:; style-src * 'unsafe-inline';
content-type: application/json; charset=utf-8
permissions-policy: geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()
referrer-policy: strict-origin
strict-transport-security: max-age=31536000; includeSubDomains
x-content-type-options: nosniff
x-frame-options: DENY
x-xss-protection: 1; mode=block
date: Fri, 23 Jan 2026 09:33:13 GMT
content-length: 174
x-envoy-upstream-service-time: 1
server: istio-envoy
connection: close
{"message":"Welcome to the AdeptMind HPDP API ๐","swagger":"https://api.hpdp.adeptmind.ai/swagger/index.html","docs":"https://api.hpdp.adeptmind.ai/static/stoplight.html"}
Open service 35.208.61.96:443 ยท api.hpdp.dlp.adeptmind.net
2026-01-10 01:29
HTTP/1.1 200 OK
access-control-allow-credentials: true
access-control-allow-headers: *
access-control-allow-methods: POST,HEAD,OPTIONS,GET
access-control-allow-origin: *
cache-control: no-store
content-security-policy: default-src 'self'; connect-src *; font-src *; script-src-elem * 'unsafe-inline'; img-src * data:; style-src * 'unsafe-inline';
content-type: application/json; charset=utf-8
permissions-policy: geolocation=(),midi=(),sync-xhr=(),microphone=(),camera=(),magnetometer=(),gyroscope=(),fullscreen=(self),payment=()
referrer-policy: strict-origin
strict-transport-security: max-age=31536000; includeSubDomains
x-content-type-options: nosniff
x-frame-options: DENY
x-xss-protection: 1; mode=block
date: Sat, 10 Jan 2026 01:29:13 GMT
content-length: 184
x-envoy-upstream-service-time: 1
server: istio-envoy
connection: close
{"message":"Welcome to the AdeptMind HPDP API ๐","swagger":"https://api.hpdp.dlp.adeptmind.net/swagger/index.html","docs":"https://api.hpdp.dlp.adeptmind.net/static/stoplight.html"}