gofiber/fiber · error
Domain pattern ' ' has parameters, which exceeds the…
Error message
Domain pattern '%s' has %d parameters, which exceeds the maximum of %d
What it means
The domain pattern declares more parameters (':param' segments) than fiber/v3's internal maxParams cap. Each parameter is tracked in parallel slices (paramIdx, paramNames), and the cap bounds match-time memory and complexity. Exceeding it is treated as a malformed/abusive pattern.
Solutions
- Reduce the number of ':param' segments by making low-value labels literal (e.g. keep a fixed TLD like '.com' as a constant label).
- Re-design the routing so most labels are matched as a single suffix/wildcard rather than individual params.
- Cap and validate the param count on the generated pattern string before passing it to the router.
Example fix
// before
app.Use(":a.:b.:c.:d.:e.:f.:g.:h.example.com", handler) // too many params
// after
app.Use(":tenant.example.com", handler) // capture only what you need Defensive patterns
Strategy: validation
Validate before calling
const maxParams = /* mirror fiber's cap; use a conservative local ceiling */ 8
func countParams(pattern string) int {
n := 0
for _, lbl := range strings.Split(pattern, ".") {
if strings.HasPrefix(lbl, ":") {
n++
}
}
return n
}
if n := countParams(domainPattern); n > maxParams {
return fmt.Errorf("pattern has %d params, max %d", n, maxParams)
} Try / catch
defer func() {
if r := recover(); r != nil {
log.Fatalf("too many domain params: %v", r)
}
}()
app.Use(domainPattern, handler) Prevention
- Capture only the labels you actually need; make the rest literal.
- Cap and validate param count in your pattern-generation helper.
- Avoid auto-generated ':a.:b.:c...' patterns from unbounded user input.
When it happens
Trigger: Calling a domain-routing API with a pattern containing more ':param' tokens than maxParams, e.g. ":a.:b.:c.:d.:e..." with each label as a separate parameter beyond the configured ceiling.
Common situations: Dynamically generating a domain pattern from user input where each label becomes a param; overusing capture-everything patterns instead of matching a concrete suffix; porting a wildcard-heavy Express/Fastify route verbatim.
Related errors
- Domain pattern cannot be empty
- Domain pattern ' ' contains empty label at position
- Domain pattern ' ' contains empty parameter name at position
- Domain pattern ' ' contains invalid character '%c' in label
- Domain pattern ' ' contains invalid parameter name ' ' with…
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/b763513a2f9ed0c0.
Report an issue: GitHub.
Appendix: source
Thrown at domain.go:128
// Enforce RFC 1035 per-label length limit (63 characters)
if len(part) > 63 {
panic(fmt.Sprintf("Domain pattern '%s' has label '%s' exceeding RFC 1035 limit of 63 characters (%d chars)",
pattern, part, len(part)))
}
// Validate label contains only valid ASCII domain characters (a-z, 0-9, hyphen).
normalized := utilsstrings.ToLower(part)
for _, ch := range normalized {
if !isASCIIAlphanumeric(ch) && ch != '-' {
panic(fmt.Sprintf("Domain pattern '%s' contains invalid character '%c' in label '%s'", pattern, ch, part))
}
}
m.parts[i] = normalized
}
}
// Check if the domain pattern has too many parameters
if len(m.paramNames) > maxParams {
panic(fmt.Sprintf("Domain pattern '%s' has %d parameters, which exceeds the maximum of %d",
pattern, len(m.paramNames), maxParams))
}
return m
}
// match checks if a hostname matches the domain pattern.
// It returns true if matched and a slice of parameter values (parallel to paramNames).
// Uses a stack-allocated buffer to avoid heap allocation for typical domain names.
// Validates hostname to prevent DoS attacks from malicious input.
func (m *domainMatcher) match(hostname string) (bool, []string) { //nolint:gocritic // unnamedResult: named returns conflict with nonamedreturns linter
// Trim trailing dot of a fully-qualified domain name (RFC 3986),
// consistent with Fiber's own host normalization in Subdomains().
hostname = utils.TrimRight(hostname, '.')
// Validate hostname is not empty and not excessively long (DoS protection)
// RFC 1035 limits domain names to 253 characters
if hostname == "" || len(hostname) > 253 {View on GitHub (pinned to a105acad6c)