{"record":{"id":"000c1413b161d1e3","repo":"actix/actix-web","slug":"invalid-chunk-size-line-size-is-too-big","errorCode":null,"errorMessage":"Invalid chunk size line: Size is too big","messagePattern":"Invalid chunk size line: Size is too big","errorType":"exception","errorClass":"io::Error","httpStatus":null,"severity":"error","filePath":"actix-http/src/h1/chunked.rs","lineNumber":81,"sourceCode":"            b'\\r' => return Poll::Ready(Ok(ChunkedState::SizeLf)),\n            _ => {\n                return Poll::Ready(Err(io::Error::new(\n                    io::ErrorKind::InvalidInput,\n                    \"Invalid chunk size line: Invalid Size\",\n                )));\n            }\n        };\n\n        match size.checked_mul(radix) {\n            Some(n) => {\n                *size = n;\n                *size += rem as u64;\n\n                Poll::Ready(Ok(ChunkedState::Size))\n            }\n            None => {\n                debug!(\"chunk size would overflow u64\");\n                Poll::Ready(Err(io::Error::new(\n                    io::ErrorKind::InvalidInput,\n                    \"Invalid chunk size line: Size is too big\",\n                )))\n            }\n        }\n    }\n\n    fn read_size_lws(rdr: &mut BytesMut) -> Poll<Result<ChunkedState, io::Error>> {\n        match byte!(rdr) {\n            // LWS can follow the chunk size, but no more digits can come\n            b'\\t' | b' ' => Poll::Ready(Ok(ChunkedState::SizeLws)),\n            b';' => Poll::Ready(Ok(ChunkedState::Extension)),\n            b'\\r' => Poll::Ready(Ok(ChunkedState::SizeLf)),\n            _ => Poll::Ready(Err(io::Error::new(\n                io::ErrorKind::InvalidInput,\n                \"Invalid chunk size linear white space\",\n            ))),\n        }","sourceCodeStart":63,"sourceCodeEnd":99,"githubUrl":"https://github.com/actix/actix-web/blob/4d435abc281842f3cbee165b6cde739e001d3a25/actix-http/src/h1/chunked.rs#L63-L99","documentation":"Raised in read_size (chunked.rs:81) when accumulating the hex chunk size would overflow a u64 - i.e. size.checked_mul(16) returns None. This is an intentional guard (logged at debug level, chunked.rs:80) against pathologically large or malicious chunk sizes such as the smuggler payload f0000000000000003 tested in hrs_chunk_size_overflow (chunked.rs:407).","triggerScenarios":"A chunk-size line declares a value whose hexadecimal representation exceeds 64 bits, e.g. \"f0000000000000003\\r\\n\". Each hex digit shifts left by 4 bits; enough digits overflow u64.","commonSituations":"Request-smuggling / desync attack probes; a malformed client; fuzzing the HTTP parser.","solutions":["No legitimate chunk size approaches 2^64; treat this as a malicious or broken client and close the connection.","Ensure upstream proxies normalize/sanitize chunked framing.","Cap request body sizes via PayloadConfig so oversized bodies are rejected earlier."],"exampleFix":"// before (attack)\n\"f0000000000000003\\r\\n...\"\n// after (valid small chunk)\n\"10\\r\\n<16 bytes>\\r\\n0\\r\\n\\r\\n\"","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"match payload.next().await {\n    Some(Err(PayloadError::Io(e))) if e.kind() == io::ErrorKind::InvalidInput =>\n        return HttpResponse::BadRequest().finish(), // oversized chunk size\n    _ => { /* ... */ }\n}","preventionTips":["Treat u64-overflow chunk sizes as hostile.","Set a PayloadConfig max body size.","Rate-limit clients that trip framing errors repeatedly."],"tags":["http","chunked-encoding","actix-http","security"],"backgroundTag":null,"analyzedSha":"4d435abc281842f3cbee165b6cde739e001d3a25","analyzedAt":"2026-08-09T01:01:40.926Z","contentChangedAt":"2026-08-09T01:01:40.926Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}