73,105 Airflow instances, 11,673 SonarQube and 33,837 Nexus: fingerprinting the build and quality toolchain
The counts
Three products that sit in the software delivery path returned measurable fingerprints in internet-wide scans on 26 September 2026. ZoomEye returned 73,105 results for app="Apache Airflow", 11,673 for app="SonarQube" and 33,837 for app="Nexus Repository".
These are application-level matches rather than bare port answers, which means the index recognised a product identity from a response. That makes each figure more specific than a port count, and it also makes each figure more conservative than the number of hosts that actually run the product.
Context and method
The queries were run on 26 September 2026 between 04:33 and 04:38 Beijing time, which is 2026-09-25T20:33 to 20:38 UTC:
app="Apache Airflow"app="SonarQube"app="Nexus Repository"
An application match reports that a response banner identified the product. It does not report the version, whether authentication is configured, whether the instance is production or a test deployment, or how much of the product's API surface is reachable. A host behind a reverse proxy that strips banners will be missed, and a host running the product on a non-standard path may also be missed. Index contents change between crawls, so these counts describe one collection window.
Why each product matters in a different way
Apache Airflow is a workflow orchestrator. It holds the connections that its tasks use to reach databases, object stores, APIs and clusters. Those connections are stored as configuration in the metadata database, and an Airflow instance that is reachable without authentication allows someone to read them and to trigger DAG runs. Triggering a run in an orchestrator that has credentials to production systems is equivalent to running code there. The count of 73,105 makes Airflow the largest of the three fingerprints, which fits a tool whose user base grew rapidly as data engineering expanded.
SonarQube analyses source code for quality and security issues. It holds the results of those analyses, and in most deployments it also holds the credentials and tokens used to connect to source repositories and to the pipelines that submit scans. It is usually placed on an internal network, and the 11,673 figure appears against that expectation. A reachable instance exposes code analysis history as well as any tokens it stores.
Nexus Repository is an artefact repository. It stores the build outputs and dependencies that pipelines consume, which makes it part of the supply chain rather than a reporting tool. The 33,837 fingerprints exceed the SonarQube figure, and an artefact repository is the more consequential of the two to expose, because the content it serves is what other systems install and deploy.
What the fingerprints do not settle
An application match does not distinguish an internet-facing production instance from a corporate instance that happens to answer on a public address for a client portal, and it does not report configuration. The version information that many of these products expose on their login page is often enough to identify a release line, which is useful for a maintainer and equally useful for someone deciding which public issue to try.
Next steps with ZoomEye
- Run the three application queries against the ranges you control, and treat the results as hosts that need internal confirmation of exposure and authentication rather than as confirmed exposures.
- Compare an application query with the port the product conventionally uses, so that confirmed fingerprints can be separated from hosts that merely open a port.
- Repeat the queries over time. Delivery tooling is provisioned and retired frequently, and a change in a controlled range reflects a deployment decision.
- For your own instances, verify whether the administrative interface, the API and the artefact or metadata store are exposed on the same listener, and confirm which of them requires authentication.
ZoomEye is useful in this comparison because application fingerprints can be queried separately from ports, which allows the same toolchain to be measured at two levels of confidence. The platform is documented at https://www.zoomeye.org/.
References
- ZoomEye search platform
- Apache Airflow documentation on security and connection management
- SonarQube documentation on authentication and token management
- Sonatype Nexus Repository documentation on deployment and security configuration
Top comments (0)