Port 5000: Common application port (Flask dev server, AirPlay, Docker Registry)
IANA registers 5000 as commplex-main, but several unrelated products use it. The Flask development server runs on 127.0.0.1:5000 by default, Apple lists TCP 5000 for AirPlay, and the Docker Registry examples publish the registry on 5000. Identifying the listener is the first step when this port appears in a scan.
Port Details
Security Exposure
Flask's documentation warns that its debugger allows arbitrary Python code execution from the browser, which is why the development server only listens locally by default. The Docker Registry documentation states that its basic examples are for testing only and that a production registry must use TLS and should use access control. An exposed registry on 5000 can leak or accept container images.
Hardening
- +Never expose the Flask development server or its debugger to other networks, and run production applications behind a production WSGI server.
- +Protect Docker registries with TLS and authentication before allowing remote clients.
- +Turn off AirPlay Receiver in System Settings on Macs that do not need it; Flask notes macOS Monterey and later start a service on port 5000.
- +Firewall 5000 at the perimeter unless a specific, reviewed service requires it.
Monitoring
Identify the process listening on 5000 on each host and alert on new listeners. For registries, log pushes and pulls and review anonymous access.
Tools for Auditing and Monitoring Flask / AirPlay / Docker Registry
Trivy
Open SourceComprehensive security scanner for container images, file systems, Git repositories, and Kubernetes configurations to detect CVEs.
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
httpx
Open SourceFast HTTP toolkit that probes services, captures response metadata, and fingerprints technologies to verify external attack surfaces.
Related Tool Categories
Frequently Asked Questions
What uses port 5000?→
Common users include the Flask development server, Apple AirPlay and Docker Registry deployments. IANA's registration, commplex-main, does not describe these uses.
Why is port 5000 in use on my Mac?→
Apple lists TCP 5000 for AirPlay. Flask's documentation notes that macOS Monterey and later automatically start a service on port 5000, which can be disabled by turning off AirPlay Receiver in System Settings.
Is it safe to expose a Flask app on port 5000?→
The development server should not be exposed. Flask warns that the debugger allows arbitrary code execution and recommends a production server for deployment.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5000 is not guaranteed to be Flask / AirPlay / Docker Registry. Exploited-in-the-wild data from the CISA KEV catalog (CC0).