Port 2375: Docker Engine REST API (unencrypted)
IANA registers TCP 2375 for the Docker REST API in plain text and 2376 for the TLS version. By default the Docker daemon listens on a Unix socket for local clients, and remote access over TCP must be configured explicitly. Docker's remote access examples bind the daemon to tcp://127.0.0.1:2375.
Port Details
Security Exposure
Docker warns that accepting remote connections can leave the host open to unauthorized access, and that without protection remote non-root users can gain root on the host. An unauthenticated API on 2375 lets any client that reaches it create containers and control the engine. Shadowserver scans the internet for accessible Docker services on 2375 and rates the report critical.
Hardening
- +Keep the Docker daemon on its default UNIX socket and do not bind it to TCP unless remote management is required.
- +When remote access is needed, use SSH contexts or TLS with client certificate verification on 2376 instead of plaintext 2375.
- +If a TCP listener is unavoidable, bind it to 127.0.0.1 or a management interface and firewall it from all other networks.
- +Limit membership of the docker group, which Docker documents as granting root-level privileges.
Monitoring
Alert on any listener on TCP 2375 and on dockerd started with -H tcp:// options. Review Docker daemon logs and API requests for container creation from unexpected clients.
Tools for Auditing and Monitoring Docker API
Trivy
Open SourceComprehensive security scanner for container images, file systems, Git repositories, and Kubernetes configurations to detect CVEs.
Falco
Open SourceCloud-native runtime security engine that monitors Linux kernel system calls to detect anomalous behavior in containers.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Related Tool Categories
Frequently Asked Questions
What is the difference between ports 2375 and 2376?→
IANA registers 2375 for the Docker REST API in plain text and 2376 for the API over TLS. Docker's documentation uses 2376 with --tlsverify for protected remote access.
Is it safe to expose the Docker API on port 2375?→
No. Docker states that remote access without TLS is not recommended and that an unprotected daemon can let remote users gain root access on the host.
Does Docker listen on port 2375 by default?→
No. By default Docker runs through a non-networked UNIX socket, and a TCP listener has to be configured explicitly.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 2375 is not guaranteed to be Docker API. Exploited-in-the-wild data from the CISA KEV catalog (CC0).