{"record":{"id":"ce91b904f071b2ab","repo":"gofiber/fiber","slug":"errupstreamhostinvalid","errorCode":"ErrUpstreamHostInvalid","errorMessage":"proxy: upstream host is empty or invalid","messagePattern":"proxy: upstream host is empty or invalid","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"middleware/proxy/security.go","lineNumber":55,"sourceCode":"// SecurityPolicy.AllowedSchemes field, so nothing outside this file can\n// mutate the backing array.\nvar defaultAllowedSchemes = []string{schemeHTTP, schemeHTTPS}\n\n// httpsSchemeBytes is the byte form of \"https\" used by redirect\n// downgrade checks. Stored once so the resolveRedirect hot path doesn't\n// allocate []byte(\"https\") on every hop.\nvar httpsSchemeBytes = []byte(schemeHTTPS)\n\n// Sentinel errors returned when an upstream target violates the configured\n// proxy security policy.\nvar (\n\t// ErrUpstreamSchemeNotAllowed is returned when the proxied URL uses a\n\t// scheme outside the configured allowlist (default: http, https).\n\tErrUpstreamSchemeNotAllowed = errors.New(\"proxy: upstream scheme is not allowed\")\n\n\t// ErrUpstreamHostInvalid is returned when the proxied URL is missing a\n\t// host or cannot be parsed.\n\tErrUpstreamHostInvalid = errors.New(\"proxy: upstream host is empty or invalid\")\n\n\t// ErrUpstreamHostBlocked is returned when the proxied URL resolves to\n\t// an address inside a blocked range (loopback, RFC 1918 private,\n\t// link-local, multicast, unspecified, or CGNAT) and AllowPrivateIPs\n\t// is false.\n\tErrUpstreamHostBlocked = errors.New(\"proxy: upstream host resolves to a blocked address\")\n\n\t// ErrRedirectDowngrade is returned when DoRedirects encounters a\n\t// redirect from an HTTPS upstream to a plaintext HTTP target and\n\t// AllowHTTPSDowngrade is false.\n\tErrRedirectDowngrade = errors.New(\"proxy: HTTPS to HTTP redirect blocked\")\n)\n\n// SecurityPolicy controls runtime security restrictions applied to the\n// proxy.Do, proxy.Forward, proxy.DoRedirects, proxy.DoTimeout, and\n// proxy.DoDeadline runtime helpers as well as Balancer instances that\n// do not supply their own policy via Config.SecurityPolicy.\ntype SecurityPolicy struct {","sourceCodeStart":37,"sourceCodeEnd":73,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/proxy/security.go#L37-L73","documentation":"The proxy middleware requires the upstream URL to parse cleanly and contain a non-empty host. ErrUpstreamHostInvalid is returned when url.Parse succeeds but the Host field is empty, or the URL cannot be parsed at all. This blocks malformed URLs that would either fail downstream or be used for DNS/host-based attacks.","triggerScenarios":"Calling proxy helpers with a URL like \"http://\" (no host), \"http:///path\", \"/relative/path\", or any string that url.Parse rejects. Also when Host header forwarding produces an empty upstream host.","commonSituations":"Empty Host header being used to construct the upstream; typos in proxy target config (missing host); user-supplied URLs without a host; reverse-proxy setups where the host is computed from request parts that are absent.","solutions":["Parse the target URL in the handler and reject it if u.Host == \"\".","Provide a default/fallback host when none is supplied.","Verify proxy.Config.Hosts and upstream target configuration are populated.","Sanitize user input before constructing the upstream URL."],"exampleFix":"// before\nreturn proxy.Do(c, c.Query(\"url\"))\n\n// after\nu, err := url.Parse(c.Query(\"url\"))\nif err != nil || u.Host == \"\" {\n    return fiber.NewError(fiber.StatusBadRequest, \"upstream host required\")\n}\nreturn proxy.Do(c, u.String())","handlingStrategy":"validation","validationCode":"u, err := url.Parse(target)\nif err != nil || u.Host == \"\" {\n    return fiber.NewError(fiber.StatusBadRequest, \"upstream host required\")\n}","typeGuard":"func hasHost(u *url.URL) bool { return u != nil && u.Host != \"\" }","tryCatchPattern":null,"preventionTips":["Always validate Host is non-empty before proxying.","Provide a default upstream host in config.","Log empty-host attempts to spot probing."],"tags":["proxy","url-validation","config","host"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}