gofiber/fiber · error
ErrUpstreamHostInvalid
ErrUpstreamHostInvalid
Error message
proxy: upstream host is empty or invalid
What it means
The proxy middleware requires the upstream URL to parse cleanly and contain a non-empty host. ErrUpstreamHostInvalid is returned when url.Parse succeeds but the Host field is empty, or the URL cannot be parsed at all. This blocks malformed URLs that would either fail downstream or be used for DNS/host-based attacks.
Solutions
- Parse the target URL in the handler and reject it if u.Host == "".
- Provide a default/fallback host when none is supplied.
- Verify proxy.Config.Hosts and upstream target configuration are populated.
- Sanitize user input before constructing the upstream URL.
Example fix
// before
return proxy.Do(c, c.Query("url"))
// after
u, err := url.Parse(c.Query("url"))
if err != nil || u.Host == "" {
return fiber.NewError(fiber.StatusBadRequest, "upstream host required")
}
return proxy.Do(c, u.String()) Defensive patterns
Strategy: validation
Validate before calling
u, err := url.Parse(target)
if err != nil || u.Host == "" {
return fiber.NewError(fiber.StatusBadRequest, "upstream host required")
} Type guard
func hasHost(u *url.URL) bool { return u != nil && u.Host != "" } Prevention
- Always validate Host is non-empty before proxying.
- Provide a default upstream host in config.
- Log empty-host attempts to spot probing.
When it happens
Trigger: Calling proxy helpers with a URL like "http://" (no host), "http:///path", "/relative/path", or any string that url.Parse rejects. Also when Host header forwarding produces an empty upstream host.
Common situations: Empty Host header being used to construct the upstream; typos in proxy target config (missing host); user-supplied URLs without a host; reverse-proxy setups where the host is computed from request parts that are absent.
Related errors
- client: invalid proxy URL
- ErrUpstreamHostBlocked
- ErrUpstreamHostInvalid
- ErrUpstreamSchemeNotAllowed
- proxy: invalid dial address
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/ce91b904f071b2ab.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/proxy/security.go:55
// SecurityPolicy.AllowedSchemes field, so nothing outside this file can
// mutate the backing array.
var defaultAllowedSchemes = []string{schemeHTTP, schemeHTTPS}
// httpsSchemeBytes is the byte form of "https" used by redirect
// downgrade checks. Stored once so the resolveRedirect hot path doesn't
// allocate []byte("https") on every hop.
var httpsSchemeBytes = []byte(schemeHTTPS)
// Sentinel errors returned when an upstream target violates the configured
// proxy security policy.
var (
// ErrUpstreamSchemeNotAllowed is returned when the proxied URL uses a
// scheme outside the configured allowlist (default: http, https).
ErrUpstreamSchemeNotAllowed = errors.New("proxy: upstream scheme is not allowed")
// ErrUpstreamHostInvalid is returned when the proxied URL is missing a
// host or cannot be parsed.
ErrUpstreamHostInvalid = errors.New("proxy: upstream host is empty or invalid")
// ErrUpstreamHostBlocked is returned when the proxied URL resolves to
// an address inside a blocked range (loopback, RFC 1918 private,
// link-local, multicast, unspecified, or CGNAT) and AllowPrivateIPs
// is false.
ErrUpstreamHostBlocked = errors.New("proxy: upstream host resolves to a blocked address")
// ErrRedirectDowngrade is returned when DoRedirects encounters a
// redirect from an HTTPS upstream to a plaintext HTTP target and
// AllowHTTPSDowngrade is false.
ErrRedirectDowngrade = errors.New("proxy: HTTPS to HTTP redirect blocked")
)
// SecurityPolicy controls runtime security restrictions applied to the
// proxy.Do, proxy.Forward, proxy.DoRedirects, proxy.DoTimeout, and
// proxy.DoDeadline runtime helpers as well as Balancer instances that
// do not supply their own policy via Config.SecurityPolicy.
type SecurityPolicy struct {View on GitHub (pinned to a105acad6c)