The 2026 Localhost Attack Surface Map
Every developer's machine is a goldmine of unauthenticated services. Ollama on :11434. Vite on :5173. Docker API on :2375. Jupyter on :8888. None of them require authentication by default. All of them are reachable from any website you visit through DNS rebinding.
We catalogued 284 common localhost services across 6 categories: web development, AI/ML, automation, infrastructure, developer tools, and databases. For each service, we documented the default port, authentication posture, DNS rebinding susceptibility, and potential impact.
The results are concerning. The majority of services that developers run locally have zero authentication and are vulnerable to DNS rebinding attacks. This means any website you visit can potentially interact with your local Ollama instance, read your Vite source code, execute commands through your Docker API, or dump your Redis cache.
The attack chain is straightforward:
1. Victim visits attacker.com 2. JavaScript probes localhost ports (timing-based fingerprinting) 3. Attacker's DNS server rebinds attacker.com -> 127.0.0.1 4. Browser now treats attacker.com as same-origin with localhost 5. JavaScript calls localhost APIs freely (Ollama, Docker, etc.) 6. Data exfiltrated to attacker's callback server
We built an interactive scanner that maps YOUR localhost attack surface. It runs entirely in your browser and only scans your own machine.
Launch Scanner View DashboardOllama (CVE-2024-28224): DNS rebinding confirmed. Attacker can read arbitrary files from the host, poison models, and exfiltrate data through the Ollama API. 175,000+ instances exposed on the internet, millions more on localhost.
Docker API (:2375): If TCP socket is enabled (common in dev setups), full container creation and host filesystem mount. This is instant host RCE.
Chrome DevTools Protocol (:9222): If remote debugging is enabled, complete browser takeover. Read all tabs, cookies, local storage, execute arbitrary JS in any origin.
MCP Servers: The new Model Context Protocol servers are designed to bridge AI agents with local tools. Most run on HTTP without authentication. DNS rebinding gives an attacker the same access as the AI agent: tool execution, API keys, backend access.
For service developers: validate the Host header. Require authentication even on localhost. Set restrictive CORS policies. For browser vendors: enforce Private Network Access (CORS-RFC1918) consistently. For developers: bind to 127.0.0.1 not 0.0.0.0. Use authentication on everything. Monitor what's listening on your machine.
This research maps a systemic issue, not a single vulnerability. Individual CVEs have been filed where appropriate (e.g., Ollama CVE-2024-28224). This tool is published to raise awareness about the scope of the problem and to help developers audit their own exposure.