Skip to main content

Port Details

Port
2375
Transport
TCP
Service
Docker API
IANA service name
docker
Range
User port (1024-49151)
Related ports
2376

Security Exposure

Docker warns that accepting remote connections can leave the host open to unauthorized access, and that without protection remote non-root users can gain root on the host. An unauthenticated API on 2375 lets any client that reaches it create containers and control the engine. Shadowserver scans the internet for accessible Docker services on 2375 and rates the report critical.

Hardening

  • +Keep the Docker daemon on its default UNIX socket and do not bind it to TCP unless remote management is required.
  • +When remote access is needed, use SSH contexts or TLS with client certificate verification on 2376 instead of plaintext 2375.
  • +If a TCP listener is unavoidable, bind it to 127.0.0.1 or a management interface and firewall it from all other networks.
  • +Limit membership of the docker group, which Docker documents as granting root-level privileges.

Monitoring

Alert on any listener on TCP 2375 and on dockerd started with -H tcp:// options. Review Docker daemon logs and API requests for container creation from unexpected clients.

Tools for Auditing and Monitoring Docker API

Trivy

Open Source
Cloud Security Tools

Comprehensive security scanner for container images, file systems, Git repositories, and Kubernetes configurations to detect CVEs.

LicenseApache-2.0
PlatformLinux, macOS, Windows

Falco

Open Source
Cloud Security Tools

Cloud-native runtime security engine that monitors Linux kernel system calls to detect anomalous behavior in containers.

LicenseApache-2.0
PlatformLinux

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Frequently Asked Questions

What is the difference between ports 2375 and 2376?→

IANA registers 2375 for the Docker REST API in plain text and 2376 for the API over TLS. Docker's documentation uses 2376 with --tlsverify for protected remote access.

Is it safe to expose the Docker API on port 2375?→

No. Docker states that remote access without TLS is not recommended and that an unprotected daemon can let remote users gain root access on the host.

Does Docker listen on port 2375 by default?→

No. By default Docker runs through a non-networked UNIX socket, and a TCP listener has to be configured explicitly.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 2375 is not guaranteed to be Docker API. Exploited-in-the-wild data from the CISA KEV catalog (CC0).