Is there an existing issue for this?
Current Behavior
I noticed unusually high network utilization coming from my server. With some digging, I was able to narrow it down to it originating from the syncthing container. I have updated the container to the latest and after restarting the server and the container, the suspicious data comes back. So, what makes it suspicious? I have nothing configured to use syncthing that lives outside of my LAN, and yet syncthing was pulling ~10mbps (give or take 3mbps) consistently through my WAN connection. It would do this from a seemingly random IP:port combination. If I block one in my firewall then it would keep attempting the connection periodically before swapping to a new IP:port combination. It was always tcp traffic with the destination port (external to my lan) being 443.
Some example IPs that were connected to are: 45.41.204.213, 169.150.197.139, 103.214.71.33, 107.152.39.18.
The ports were always in the 40k-55k range, from what I could tell.
I do not know enough to know if this means the container is compromised, but I will not be running it on my network anymore.
Expected Behavior
It should not be transferring large amounts of data with suspicious WAN connections.
Steps To Reproduce
-
Run the container with this docker compose, where the "external" network is a bridge network.
-
Use your network observation tool of choice to see a spike in traffic attempting to traverse your WAN interface. I used Torch on my mikrotik router.
Environment
- OS: Ubuntu 24.04.2
- How docker service was installed: apt
CPU architecture
arm64
Docker creation
services:
syncthing:
image: lscr.io/linuxserver/syncthing
container_name: syncthing
environment:
- PUID=1000
- PGID=1000
- TZ=America/Chicago
volumes:
- /home/ubuntu/external/config/syncthing:/config
- /home/ubuntu/external/media:/data
- /home/ubuntu/external/config:/serviceConfigs
ports:
- 8384:8384
- 22000:22000
- 21027:21027/udp
restart: unless-stopped
networks:
- frontend
labels:
- traefik.enable=true
- traefik.http.routers.syncthing.rule=Host(`syncthing.fox.local`)
- traefik.http.routers.syncthing.entrypoints=web
- traefik.http.services.syncthing.loadbalancer.server.port=8384
networks:
frontend:
external: true
Container logs
6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1074-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1074-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-9-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-9-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-782-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-782-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1121-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1121-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-230-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-230-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1382-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1382-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-639-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-639-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-299-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-299-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-913-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-913-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-612-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-612-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-823-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-823-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-651-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-651-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-468-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-468-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-604-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-604-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1340-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1340-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-965-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-965-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-1238-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-1238-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-448-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-448-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1109-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1109-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-995-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-995-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-972-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-972-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-484-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-484-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-336-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-336-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-120-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-120-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1135-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1135-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-892-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-892-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-597-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-597-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1368-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1368-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-200-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-200-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-696-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-696-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-747-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-747-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-254-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-254-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1183-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1183-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1355-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1355-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-262-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-262-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-232-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-232-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-920-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-920-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-418-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-418-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-496-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-496-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1362-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1362-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-613-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-613-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-940-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-940-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-931-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-931-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1242-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1242-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-18-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-18-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-59-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-59-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1296-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1296-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1251-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1251-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-166-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-166-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1281-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1281-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-540-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-540-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-41-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-41-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-1233-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-1233-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-647-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-647-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1034-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1034-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-504-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-504-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1286-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1286-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1213-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1213-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-176-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-176-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-621-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-621-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1385-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1385-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-338-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-338-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-991-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-991-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-1139-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-1139-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-497-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-497-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1006-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1006-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-574-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-574-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1291-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1291-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-237-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-237-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-203-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-203-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-50-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-50-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-1301-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-1301-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-788-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-788-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-1255-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-1255-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-104-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-104-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-1308-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-1308-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-1357-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-1357-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-848-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-848-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-586-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-586-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-590-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-590-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/collection-142-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/collection-142-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-1087-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-1087-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "eapcontroller/data/db/index-712-1249969021906828905.wt"): hashing: open /serviceConfigs/eapcontroller/data/db/index-712-1249969021906828905.wt: permission denied
[6UC4J] 2025/03/20 20:50:15 INFO: Scanner (folder "Configs" (Configs), item "vpn/.token"): hashing: open /serviceConfigs/vpn/.token: permission denied
[6UC4J] 2025/03/20 20:50:20 INFO: Puller (folder "Configs" (Configs), item "adguardhome/work/data"): syncing: handling dir (setting permissions): chmod /serviceConfigs/adguardhome/work/data: operation not permitted
[6UC4J] 2025/03/20 20:50:20 INFO: "Configs" (Configs): Failed to sync 1 items
[6UC4J] 2025/03/20 20:50:20 INFO: Folder "Configs" (Configs) isn't making sync progress - retrying in 2m0s.
[6UC4J] 2025/03/20 20:50:20 INFO: Puller (folder "Configs" (Configs), item "adguardhome/work/data"): syncing: handling dir (setting permissions): chmod /serviceConfigs/adguardhome/work/data: operation not permitted
[6UC4J] 2025/03/20 20:50:20 INFO: "Configs" (Configs): Failed to sync 1 items
[6UC4J] 2025/03/20 20:50:20 INFO: Folder "Configs" (Configs) isn't making sync progress - retrying in 4m0s.
[6UC4J] 2025/03/20 20:52:41 INFO: Established secure connection to PH3OJME at 172.18.0.12:46396-209.145.63.115:22067/relay-server/TLS1.3-TLS_AES_128_GCM_SHA256/WAN-P50-61ELPUTFPRB6S4Q0PJN01IFVLQ
[6UC4J] 2025/03/20 20:52:41 INFO: Device PH3OJME client is "syncthing v1.29.2" named "nixos" at 172.18.0.12:46396-209.145.63.115:22067/relay-server/TLS1.3-TLS_AES_128_GCM_SHA256/WAN-P50-61ELPUTFPRB6S4Q0PJN01IFVLQ
[6UC4J] 2025/03/20 20:52:42 INFO: Puller (folder "Configs" (Configs), item "adguardhome/work/data"): syncing: handling dir (setting permissions): chmod /serviceConfigs/adguardhome/work/data: operation not permitted
[6UC4J] 2025/03/20 20:52:42 INFO: "Configs" (Configs): Failed to sync 1 items
[6UC4J] 2025/03/20 20:52:42 INFO: Folder "Configs" (Configs) isn't making sync progress - retrying in 4m0s.
[6UC4J] 2025/03/20 20:52:42 INFO: Puller (folder "Configs" (Configs), item "adguardhome/work/data"): syncing: handling dir (setting permissions): chmod /serviceConfigs/adguardhome/work/data: operation not permitted
[6UC4J] 2025/03/20 20:52:42 INFO: "Configs" (Configs): Failed to sync 1 items
[6UC4J] 2025/03/20 20:52:42 INFO: Folder "Configs" (Configs) isn't making sync progress - retrying in 4m0s.
[6UC4J] 2025/03/20 20:52:44 INFO: Puller (folder "Configs" (Configs), item "adguardhome/work/data"): syncing: handling dir (setting permissions): chmod /serviceConfigs/adguardhome/work/data: operation not permitted
[6UC4J] 2025/03/20 20:52:44 INFO: "Configs" (Configs): Failed to sync 1 items
[6UC4J] 2025/03/20 20:52:44 INFO: Folder "Configs" (Configs) isn't making sync progress - retrying in 4m0s.
[monitor] 2025/03/20 20:53:16 INFO: Signal 15 received; exiting
[6UC4J] 2025/03/20 20:53:16 INFO: Relay listener (dynamic+https://relays.syncthing.net/endpoint) shutting down
[6UC4J] 2025/03/20 20:53:16 INFO: QUIC listener ([::]:22000) shutting down
[6UC4J] 2025/03/20 20:53:16 INFO: TCP listener ([::]:22000) shutting down
[6UC4J] 2025/03/20 20:53:16 INFO: Lost primary connection to PH3OJME at 172.18.0.12:46396-209.145.63.115:22067/relay-server/TLS1.3-TLS_AES_128_GCM_SHA256/WAN-P50-61ELPUTFPRB6S4Q0PJN01IFVLQ: reading length: EOF (0 remain)
[6UC4J] 2025/03/20 20:53:16 INFO: Connection to PH3OJME at 172.18.0.12:46396-209.145.63.115:22067/relay-server/TLS1.3-TLS_AES_128_GCM_SHA256/WAN-P50-61ELPUTFPRB6S4Q0PJN01IFVLQ closed: reading length: EOF
[6UC4J] 2025/03/20 20:53:16 INFO: Exiting
My log file is too long. I can provide the .log if requested.
Is there an existing issue for this?
Current Behavior
I noticed unusually high network utilization coming from my server. With some digging, I was able to narrow it down to it originating from the syncthing container. I have updated the container to the latest and after restarting the server and the container, the suspicious data comes back. So, what makes it suspicious? I have nothing configured to use syncthing that lives outside of my LAN, and yet syncthing was pulling ~10mbps (give or take 3mbps) consistently through my WAN connection. It would do this from a seemingly random IP:port combination. If I block one in my firewall then it would keep attempting the connection periodically before swapping to a new IP:port combination. It was always tcp traffic with the destination port (external to my lan) being 443.
Some example IPs that were connected to are: 45.41.204.213, 169.150.197.139, 103.214.71.33, 107.152.39.18.
The ports were always in the 40k-55k range, from what I could tell.
I do not know enough to know if this means the container is compromised, but I will not be running it on my network anymore.
Expected Behavior
It should not be transferring large amounts of data with suspicious WAN connections.
Steps To Reproduce
Run the container with this docker compose, where the "external" network is a bridge network.
Use your network observation tool of choice to see a spike in traffic attempting to traverse your WAN interface. I used Torch on my mikrotik router.
Environment
CPU architecture
arm64
Docker creation
services: syncthing: image: lscr.io/linuxserver/syncthing container_name: syncthing environment: - PUID=1000 - PGID=1000 - TZ=America/Chicago volumes: - /home/ubuntu/external/config/syncthing:/config - /home/ubuntu/external/media:/data - /home/ubuntu/external/config:/serviceConfigs ports: - 8384:8384 - 22000:22000 - 21027:21027/udp restart: unless-stopped networks: - frontend labels: - traefik.enable=true - traefik.http.routers.syncthing.rule=Host(`syncthing.fox.local`) - traefik.http.routers.syncthing.entrypoints=web - traefik.http.services.syncthing.loadbalancer.server.port=8384 networks: frontend: external: trueContainer logs