affaan-m/ECC · warning · anyhow::Error
HTTP request headers too large
Error message
HTTP request headers too large
What it means
While accumulating request bytes the HTTP reader enforces a 64 KiB cap on the header section. If no `\r\n\r\n` terminator is found before the buffer exceeds 64 * 1024 bytes, it bails with this error. This protects the server from unbounded memory growth from malicious or broken clients.
Solutions
- Reduce request header size on the client — trim cookies or split authentication headers.
- Clear accumulated cookies for the host in the browser/client and retry.
- If large headers are a legitimate requirement, raise the 64 * 1024 limit in the server's read loop.
- Verify the client is speaking HTTP/1.1 with proper `\r\n` line endings.
Example fix
// before (server)
if buffer.len() > 64 * 1024 {
anyhow::bail!("HTTP request headers too large");
}
// after (allow 256 KiB)
const MAX_HEADER_BYTES: usize = 256 * 1024;
if buffer.len() > MAX_HEADER_BYTES {
anyhow::bail!("HTTP request headers too large");
} Defensive patterns
Strategy: validation
Validate before calling
// Client-side check before sending
const MAX_HEADER_BYTES: usize = 64 * 1024;
if request_header_bytes.len() > MAX_HEADER_BYTES {
// trim cookies/headers or reject before sending
} Try / catch
match send_request(req) {
Err(e) if e.to_string().contains("headers too large") => {
// reduce headers (clear cookies) and retry once
}
other => other?,
} Prevention
- Keep cookies and custom headers small; periodically clear stale cookies.
- Never send raw non-HTTP bytes to the HTTP port.
- If you legitimately need big headers, raise the server limit consciously and document it.
When it happens
Trigger: A client sends HTTP headers totaling more than 64 KiB (e.g. a huge `Cookie` or `Authorization` header), or sends garbage bytes that never contain the `\r\n\r\n` delimiter.
Common situations: Cookie bloat after many sessions/tokens accumulate in one request; a client appending many large custom headers; a non-HTTP client (raw TCP) streaming data to the port; fuzzing or a request smuggling probe.
Understand the failure class
Background: payload too large / request exceeds maximum size: why libraries cap bytes and how to fix oversize payloads — this error's family across 50 libraries.
Related errors
- Unexpected EOF while reading HTTP request
- Unexpected EOF while reading HTTP request body
- -32001
- agent profile inheritance cycle
- an active harness configuration already exists
AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16).
Data as JSON: /api/errors/a0df3f60901d8941.
Report an issue: GitHub.
Appendix: source
Thrown at ecc2/src/main.rs:4205
}
}
fn read_http_request(
stream: &mut TcpStream,
) -> Result<(String, String, BTreeMap<String, String>, Vec<u8>)> {
let mut buffer = Vec::new();
let mut temp = [0_u8; 1024];
let header_end = loop {
let read = stream.read(&mut temp)?;
if read == 0 {
anyhow::bail!("Unexpected EOF while reading HTTP request");
}
buffer.extend_from_slice(&temp[..read]);
if let Some(index) = buffer.windows(4).position(|window| window == b"\r\n\r\n") {
break index + 4;
}
if buffer.len() > 64 * 1024 {
anyhow::bail!("HTTP request headers too large");
}
};
let header_text = String::from_utf8(buffer[..header_end].to_vec())
.context("HTTP request headers were not valid UTF-8")?;
let mut lines = header_text.split("\r\n");
let request_line = lines
.next()
.filter(|line| !line.trim().is_empty())
.ok_or_else(|| anyhow::anyhow!("Missing HTTP request line"))?;
let mut request_parts = request_line.split_whitespace();
let method = request_parts
.next()
.ok_or_else(|| anyhow::anyhow!("Missing HTTP method"))?
.to_string();
let path = request_parts
.next()
.ok_or_else(|| anyhow::anyhow!("Missing HTTP path"))?View on GitHub (pinned to 8321021c54)