AkamaiGHost
tcp/80
AkamaiNetStorage
tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1a8bcc6e55eee1cf16c1a59c86c1a59c86c1a59c86c1a59c8
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html - sample paths:
GET /v1/token
GET /v1/token/{accountToken}
Open service 81.243.1.208:80
2026-01-26 16:03
HTTP/1.0 400 Bad Request Server: AkamaiGHost Mime-Version: 1.0 Content-Type: text/html Content-Length: 312 Expires: Mon, 26 Jan 2026 16:03:36 GMT Date: Mon, 26 Jan 2026 16:03:36 GMT Connection: close Page title: Invalid URL <HTML><HEAD> <TITLE>Invalid URL</TITLE> </HEAD><BODY> <H1>Invalid URL</H1> The requested URL "[no URL]", is invalid.<p> Reference #9.cc01f351.1769443416.22a00878 <P>https://errors.edgesuite.net/9.cc01f351.1769443416.22a00878</P> </BODY></HTML>
Open service 81.243.1.208:80 · www-qa1.delhaize.be
2026-01-10 16:44
HTTP/1.1 403 Forbidden
Accept-Ranges: bytes
Content-Type: text/html
ETag: "974c38ea9b69d84f63c7203648b5b98d:1415353799"
Last-Modified: Fri, 07 Nov 2014 09:49:59 GMT
Server: AkamaiNetStorage
X-Akamai-Transformed: 0 - 0 -
Expires: Sat, 10 Jan 2026 16:45:06 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 10 Jan 2026 16:45:06 GMT
Connection: close
Set-Cookie: _abck=F668219520018BE7789981F787479E7C~-1~YAAQzAHzUUymAyqbAQAANxjMqA94uPUAwmQ+Z/0sRAUt4Fkj+B/PwXk8t/LFsFiSmi76J0HvVUmr6LKsW/0sak/RooE6TsVmx7nlOqbji08XuWbUQC78jpVBgNfUT7jZX0Dqh9nQlsKlEEcYTD+/yqXgnkkyt96+6UgDBTMYoDIiKI2JbR5Q2i0IN7qqve31rx0/TcQo4+lvHP8qluPULWN2uDQY+7pJPoUbjUc7rGv2bTYZPunH03AyVG4S88ybnnfODRkfpLQopC4P/H2vMxZwTB1ICmrp0nIaJmOT6hb/EwVl+1DaiSjyfnjcBP5o97WHr4QM9f07yzoAlhAwuSCuxtHmnZ1Qw7ApyFjzLCuKzEoxXr7f6QADssd1oufKzuSbc1l8~-1~-1~-1~-1~-1; Domain=.delhaize.be; Path=/; Expires=Sun, 10 Jan 2027 16:45:06 GMT; Max-Age=31536000
Set-Cookie: bm_sz=8C844354A2064D547D0AA9CE91CDA2F6~YAAQzAHzUU2mAyqbAQAANxjMqB7HFxD7b7bTtLLAixYhuOYGpvTgNbEaZ0uxWlFwIAtNNUysCkA6O4xmzW5F6n2iNtm2zEht6rOX38AWWR1CQRHjS9a57hYyW8iu1IAWukDn+8PRTBFU0asFDz/YdWWMF6EFwMEXiVinLCex01JQ1kBKGPb41wwMFVNnnymkNmdC0pL9E/If/w1iZpvb67nQcqCGOZgsWYfbKYKEofRgjW8mjhz2taUMIvXM83f5tpJ2SQoGpD2EGBJ00AcQ057TeV75OZ20n9BV0Wp89CdYAWOmwJl8MJsU73Q752aJXFTy6pf5DMUF+cUqUNA8QnUAYT5WASgKHCHAfLgvK4c=~4470081~4339268; Domain=.delhaize.be; Path=/; Expires=Sat, 10 Jan 2026 20:45:06 GMT; Max-Age=14400
Page title: Delhaize.be
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<title>Delhaize.be</title>
</head>
<body style="background-color:#cabfb1">
<div style="text-align:center; width:1170px; margin: 0 auto; position: relative;">
<div style="position: absolute; background-color: transparent; height: 320px; left: 740px; top: 210px; width: 310px; text-align: left; font-family: ff-netto-web,Tahoma,Geneva,sans-serif; font-size: 17px; color: #445763;">
<p style="padding-bottom: 20px; padding-top: 40px;">La page que vous désirez afficher ne répond pas. Merci de réessayer plus tard.</p>
<p>De pagina die je wil bekijken is niet beschikbaar. Probeer het later nog eens.</p>
</div>
<img src="/failover_objects/delhaizebe-onderhoudswerken.jpg">
</div>
<script type="text/javascript" src="/gIyILG/n/8/tOtnDH1aew/aph7tJSYEp7Q4p/c2JaKg/BA/FwbgQQHDsB"></script></body>
</html>
Open service 81.243.1.208:443 · ws.gcp-qa.credencewell-being.com
2026-01-10 15:46
HTTP/1.1 200 OK
Content-Type: text/html;charset=UTF-8
Request-Id: 5a5b347b-8a52-4b9a-97b7-31f17ba183f8
Last-Modified: Mon, 05 Jan 2026 23:45:20 GMT
Accept-Ranges: bytes
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
Strict-Transport-Security: max-age=31536000; includeSubDomains
X-Frame-Options: DENY
Content-Language: en-US
X-Akamai-Transformed: 9 1537 0 pmb=mRUM,1
Date: Sat, 10 Jan 2026 15:46:34 GMT
Content-Length: 4639
Connection: close
Server-Timing: cdn-cache; desc=MISS
Server-Timing: edge; dur=574
Server-Timing: origin; dur=88
X-Refcode: 0.5601f351.1768059993.1b6816a8
Set-Cookie: _abck=371809B23D131DA6A027E2623237DA56~-1~YAAQVgHzUbRnNyubAQAAwn+WqA9/IwRLWxiBoVTsHsmTVeEkZf1nXePfGk4zAPi5b4XHD4UGSIj4qyx3OW+NaJnUGtDcE9LFK65djpTXWCVTl726gkSjxj/zBueJqUaZZtMllky9hqr1SfvjKfMV2NkiXRJg+u/PsJu1IlXkuJpGiGW8qX0T/dveMQvVVwg5rzMzT8q65dCzCmI0vZdUqDw35AMm1nsKwaAcnltvAZ7931I2ugSrfxmQazaySYg6NIWDOTALmjTsoiDPyCnwRMe/QExuYxQ3MGM015A4GkOVcfxjomtGc/5VSAybOkUuMi91/syT01GcIuwc9BUKRQ9Vib5hOQKZ2togMOyAjDYvZsEPLG8mdwnAyincab29LbaoLCMQH6pmNI4f7cZwbT+SNcH2dUSnuO26Yor6xM+vkciVp3SrBtwDRqCOwBYepfVyu2YKK69VzSHuYGgSNqo=~-1~-1~-1~-1~-1; Domain=.credencewell-being.com; Path=/; Expires=Sun, 10 Jan 2027 15:46:34 GMT; Max-Age=31536000; SameSite=None; Secure
Set-Cookie: bm_sz=0558E0F1300FBC94F704C956783A0D1C~YAAQVgHzUbVnNyubAQAAwn+WqB5tD0YKjzfM/XRSq8RhnJdSU4wWieT4Gi0kPxhMC0pFaNTkRhh1ILh42pPcNwUDKfvKxGZpXIM/D4cJViVhk6Iz9/wMEl8+pw/z5+UxVxSnWX+qyFBWi794oAmLcpLwVrNq/acABsFoHT1B2tO//QJlImgNyXd3WhsdEPscHBRSPd6auNSeTFkmTgHrJrEJa19yyTb+gCiJ10I5Tuw7boWuTI1GLttw4so4ifqyMTpSs2XpTXYnrCpLxjlWE4OvxVKze/w6dNZGVr0SNxJb+T4Z6bvbjr/KHMOHw/3DouEgx2G/TgB/Z1qUjCEPjRjEQ9r0dNZYWotEx34jPwMc/+kI7QhT0bxx~3289137~3422256; Domain=.credencewell-being.com; Path=/; Expires=Sat, 10 Jan 2026 19:46:33 GMT; Max-Age=14399; SameSite=None; Secure
Server-Timing: ak_p; desc="1768059993363_1374880086_459806376_66266_13327_6_9_-";dur=1
<html>
<head>
<meta charset="utf-8"/>
<script src="/webjars/jquery/jquery.min.js"></script>
<script src="/webjars/sockjs-client/sockjs.min.js"></script>
<script src="/webjars/stomp-websocket/stomp.min.js"></script>
<script src="/app.js"></script>
<link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/bootstrap/3.4.1/css/bootstrap.min.css">
<style type="text/css">
canvas { border: 1px solid black; overflow: scroll; display: inline-block}
</style>
<script>!function(a){var e="https://s.go-mpulse.net/boomerang/",t="addEventListener";if("False"=="True")a.BOOMR_config=a.BOOMR_config||{},a.BOOMR_config.PageParams=a.BOOMR_config.PageParams||{},a.BOOMR_config.PageParams.pci=!0,e="https://s2.go-mpulse.net/boomerang/";if(window.BOOMR_API_key="ACCJT-UATJA-EGUNH-BBLSP-RMP8C",function(){function n(e){a.BOOMR_onload=e&&e.timeStamp||(new Date).getTime()}if(!a.BOOMR||!a.BOOMR.version&&!a.BOOMR.snippetExecuted){a.BOOMR=a.BOOMR||{},a.BOOMR.snippetExecuted=!0;var i,_,o,r=document.createElement("iframe");if(a[t])a[t]("load",n,!1);else if(a.attachEvent)a.attachEvent("onload",n);r.src="javascript:void(0)",r.title="",r.role="presentation",(r.frameElement||r).style.cssText="width:0;height:0;border:0;display:none;",o=document.getElementsByTagName("script")[0],o.parentNode.insertBefore(r,o);try{_=r.contentWindow.document}catch(O){i=document.domain,r.src="javascript:var d=document.open();d.domain='"+i+"';void(0);",_=r.contentWindow.document}_.open()._l=function(){var a=this.createElement("script");if(i)this.domain=i;a.id="boomr-if-as",a.src=e+"ACCJT-UATJA-EGUNH-BBLSP-RMP8C",BOOMR_lstart=(new Date).getTime(),this.body.appendChild(a)},_.write("<bo"+'dy onload="document._l();">'),_.close()}}(),"".length>0)if(a&&"performance"in a&&a.performance&&"function"==typeof a.performance.setResourceTimingBufferSize)a.performance.setResourceTimingBufferSize();!function(){if(BOOMR=a.BOOMR||{},BOOMR.plugins=BOOMR.plugins||{},!BOOMR.plugins.AK){var e=""=="true"?1:0,t="",n="2etpqekr6ma5a2lcormq-f-83252615a-clientnsv4-s.akamaihd.net",i="false"=="true"?2:1,_={"ak.v":"39","ak.cp":"1170288","ak.ai":parseInt("789902",10),"ak.ol":"0","ak.cr":6,"ak.ipv":4,"ak.proto":"http/1.1","ak.rid":"1b6816a8","ak.r":36907,"ak.a2":e,"ak.m":"dsca","ak.n":"essl","ak.bpcip":"209.38.248.0","ak.cport":44218,"ak.gh":"81.243.1.86","ak.quicv":"","ak.tlsv":"tls1.3","ak.0rtt":"","ak.0rtt.ed":"","ak.csrc":"-","ak.acc":"bbr","ak.t":"1768059993","ak.ak":"hOBiQwZUYzCg5VSAfCLimQ==+/8PdmS5RnXmfYqKh21XjSm24G20TxisYChnN4mtiOHmEiGEE6XgO46zqaZmextSrnu5s5ZU1FWgl5LXZbhKDP3jerk4HkOSAFedYuBUvkvZrw3AZUTqS0GIT97u7nu9245DKNltnf0tnQJwYsdBXpIB56Y9aXWUFCW/TZThPRs4Rg0kkFf+JZY8Ypgo0LAlsFGKvTPr8nXaILUX2qEybj1xpwM5kISthDzd4Ekdf+k2Egy8w0fEsqqIzKmEu3YQ/btNmSDu+twnlhZRHzr+lWA2fsSFlJXeI15erBzFm6l45WaL5+qABoj0jfVtDNT7dayMquyl7NTfevr0+yNQuyLwsgtdnmLd/hQ4WNlCZ5zPB6JT7r8S8Au1KvFKfZjY98ScT8c2dlWKjAKjAqbP3HrIxaCyf2ZOT1uUHPO6L5A=","ak.pv":"171","ak.dpoabenc":"","ak.tf":i};if(""!==t)_["ak.ruds"]=t;var o={i:!1,av:function(e){var t="http.initiator";if(e&&(!e[t]||"spa_hard"===e[t]))_["ak.feo"]=void 0!==a.aFeoApplied?1:0,BOOMR.addVar(_)},rv:function(){var a=["ak.bpcip","ak.cport","ak.cr","ak.csrc","ak.gh","ak.ipv","ak.m","ak.n","ak.ol","ak.proto","ak.quicv","ak.tlsv","ak.0rtt","ak.0rtt.ed","ak.r","ak.acc","ak.t","ak.tf"];BOOMR.removeVar(a)}};BOOMR.plugins.AK={akVars:_,akDNSPreFetchDomain:n,init:function(){if(!o.i){var a=BOOMR.subscribe;a("before_beacon",o.av,null,null),a("onbeacon",o.rv,null,null),o.i=!0}return this},is_complete:function(){return!0}}}}()}(window);</script></head>
<body>
<div id="whiteboard" hidden>
<h2>Whiteboard! Mode: <button id="mode" class="btn btn-success" onclick="toggleMode()">Draw</button></h2>
<div id="info"></div>
<div id="container" style="padding: 5px; width: 100%; height: 100%; position:fixed; overflow: hidden;">
<div style="overflow: scroll; width: 100%; height: 100%; border: 1px solid black;">
<canvas id="canvas" width="1600" height="900"></canvas>
</div>
</div>
</div>
<div id="loginForm">
<h2>Login with Castlight</h2>
<form>
<div class
Open service 81.243.1.208:80 · www.stg.zyn.com
2026-01-10 12:12
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 373 Cache-Control: max-age=0 Date: Sat, 10 Jan 2026 12:13:18 GMT Connection: close Server-Timing: cdn-cache; desc=HIT Server-Timing: edge; dur=1 aem-akamai-edgescape: countrycode=GB,lat=51.50,long=-0.12,trueclient=157.245.36.108,city= Server-Timing: ak_p; desc="1768047198557_1374880204_1302614014_21_113861_16_0_-";dur=1 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://www.stg.zyn.com/" on this server.<P> Reference #18.cc01f351.1768047198.4da44ffe <P>https://errors.edgesuite.net/18.cc01f351.1768047198.4da44ffe</P> </BODY> </HTML>