affaan-m/ECC · warning · anyhow::Error

HTTP request headers too large

Error message

HTTP request headers too large

What it means

While accumulating request bytes the HTTP reader enforces a 64 KiB cap on the header section. If no `\r\n\r\n` terminator is found before the buffer exceeds 64 * 1024 bytes, it bails with this error. This protects the server from unbounded memory growth from malicious or broken clients.

Solutions

  1. Reduce request header size on the client — trim cookies or split authentication headers.
  2. Clear accumulated cookies for the host in the browser/client and retry.
  3. If large headers are a legitimate requirement, raise the 64 * 1024 limit in the server's read loop.
  4. Verify the client is speaking HTTP/1.1 with proper `\r\n` line endings.

Example fix

// before (server)
if buffer.len() > 64 * 1024 {
    anyhow::bail!("HTTP request headers too large");
}

// after (allow 256 KiB)
const MAX_HEADER_BYTES: usize = 256 * 1024;
if buffer.len() > MAX_HEADER_BYTES {
    anyhow::bail!("HTTP request headers too large");
}
Defensive patterns

Strategy: validation

Validate before calling

// Client-side check before sending
const MAX_HEADER_BYTES: usize = 64 * 1024;
if request_header_bytes.len() > MAX_HEADER_BYTES {
    // trim cookies/headers or reject before sending
}

Try / catch

match send_request(req) {
    Err(e) if e.to_string().contains("headers too large") => {
        // reduce headers (clear cookies) and retry once
    }
    other => other?,
}

Prevention

When it happens

Trigger: A client sends HTTP headers totaling more than 64 KiB (e.g. a huge `Cookie` or `Authorization` header), or sends garbage bytes that never contain the `\r\n\r\n` delimiter.

Common situations: Cookie bloat after many sessions/tokens accumulate in one request; a client appending many large custom headers; a non-HTTP client (raw TCP) streaming data to the port; fuzzing or a request smuggling probe.

Understand the failure class

Background: payload too large / request exceeds maximum size: why libraries cap bytes and how to fix oversize payloads — this error's family across 50 libraries.

Related errors


AI-assisted analysis of affaan-m/ECC@8321021c54 (2026-09-16). Data as JSON: /api/errors/a0df3f60901d8941. Report an issue: GitHub.

Appendix: source

Thrown at ecc2/src/main.rs:4205

    }
}

fn read_http_request(
    stream: &mut TcpStream,
) -> Result<(String, String, BTreeMap<String, String>, Vec<u8>)> {
    let mut buffer = Vec::new();
    let mut temp = [0_u8; 1024];
    let header_end = loop {
        let read = stream.read(&mut temp)?;
        if read == 0 {
            anyhow::bail!("Unexpected EOF while reading HTTP request");
        }
        buffer.extend_from_slice(&temp[..read]);
        if let Some(index) = buffer.windows(4).position(|window| window == b"\r\n\r\n") {
            break index + 4;
        }
        if buffer.len() > 64 * 1024 {
            anyhow::bail!("HTTP request headers too large");
        }
    };

    let header_text = String::from_utf8(buffer[..header_end].to_vec())
        .context("HTTP request headers were not valid UTF-8")?;
    let mut lines = header_text.split("\r\n");
    let request_line = lines
        .next()
        .filter(|line| !line.trim().is_empty())
        .ok_or_else(|| anyhow::anyhow!("Missing HTTP request line"))?;
    let mut request_parts = request_line.split_whitespace();
    let method = request_parts
        .next()
        .ok_or_else(|| anyhow::anyhow!("Missing HTTP method"))?
        .to_string();
    let path = request_parts
        .next()
        .ok_or_else(|| anyhow::anyhow!("Missing HTTP path"))?

View on GitHub (pinned to 8321021c54)