Review the range of EXPOSE port numbers

Declare valid port numbers that match the service’s actual listeners.

Description

TCP and UDP port numbers range from 0 to 65535, with 0 reserved. Use an appropriate value from 1 to 65535 for a fixed service port. An out-of-range EXPOSE value can cause a build error.

EXPOSE declares port metadata. It does not make the application listen on that port or publish it on the host.

Potential impact

  • An invalid declaration can fail the build or mislead tools about the service port.
  • A mismatch with the actual listener can lead to an incorrect port mapping and an unreachable service.

Remediation

  • Set EXPOSE to the service’s actual port from 1 to 65535 and the required TCP or UDP protocol.
  • Check application listeners, runtime port publication and firewall policy separately. A valid port number alone does not enforce access controls.

Examples

The existing NGINX examples compare port declarations only. Use a supported image for actual deployment. Port 80 in the after-example matches the example image’s default HTTP listener.

Before

dockerfile
FROM nginx:1.27-alpine

EXPOSE 65536
CMD ["nginx", "-g", "daemon off;"]

After

dockerfile
FROM nginx:1.27-alpine

EXPOSE 80
CMD ["nginx", "-g", "daemon off;"]

Explanation:

  • Before: 65536 is outside the valid port-number range.
  • After: Port 80 matches NGINX’s default HTTP listener. Host port publication must be configured separately.

References