{"record":{"id":"4e1c01c0aedf063b","repo":"mongodb/node-mongodb-native","slug":"malformed-json-body-in-get-request","errorCode":null,"errorMessage":"Malformed JSON body in GET request.","messagePattern":"Malformed JSON body in GET request\\.","errorType":"exception","errorClass":"MongoCryptAzureKMSRequestError","httpStatus":null,"severity":"error","filePath":"src/client-side-encryption/providers/azure.ts","lineNumber":75,"sourceCode":"    return fetchAzureKMSToken();\n  }\n}\n\n/** @internal */\nexport const tokenCache = new AzureCredentialCache();\n\n/** @internal */\nasync function parseResponse(response: {\n  body: string;\n  status?: number;\n}): Promise<AzureTokenCacheEntry> {\n  const { status, body: rawBody } = response;\n\n  const body: { expires_in?: number; access_token?: string } = (() => {\n    try {\n      return JSON.parse(rawBody);\n    } catch {\n      throw new MongoCryptAzureKMSRequestError('Malformed JSON body in GET request.');\n    }\n  })();\n\n  if (status !== 200) {\n    throw new MongoCryptAzureKMSRequestError('Unable to complete request.', body);\n  }\n\n  if (!body.access_token) {\n    throw new MongoCryptAzureKMSRequestError(\n      'Malformed response body - missing field `access_token`.'\n    );\n  }\n\n  if (!body.expires_in) {\n    throw new MongoCryptAzureKMSRequestError(\n      'Malformed response body - missing field `expires_in`.'\n    );\n  }","sourceCodeStart":57,"sourceCodeEnd":93,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/client-side-encryption/providers/azure.ts#L57-L93","documentation":"Raised by the Azure KMS credential provider when the HTTP response body from the Azure Instance Metadata Service (IMDS, http://169.254.169.254/...) cannot be parsed as JSON. It is a MongoCryptAzureKMSRequestError thrown in parseResponse after JSON.parse throws. This provider is used by CSFLE/Queryable Encryption to fetch an access token for Azure-managed keys.","triggerScenarios":"Running CSFLE with an azure KMS provider on a host that cannot reach the Azure IMDS endpoint and returns an HTML/text error page (e.g. a proxy block page); the IMDS endpoint returning a non-JSON 5xx body; network middleware rewriting the response.","commonSituations":"Running the driver outside an Azure VM/container (no IMDS available, returns connection error or HTML); corporate proxy injecting an authentication/redirect HTML page; Azure IMDS temporarily returning a plain-text error; wrong Azure endpoint configured via test options.","solutions":["Run on an Azure resource with a managed identity enabled (VM, App Service, etc.) so IMDS at 169.254.169.254 returns valid JSON.","Ensure no HTTP proxy intercepts and rewrites the IMDS response; allowlist 169.254.169.254 if a proxy is mandatory.","If running locally/off-Azure, supply Azure credentials explicitly via the kmsProviders Azure tenantId/clientId/clientSecret instead of relying on IMDS.","Verify the IMDS endpoint by curling it directly: curl 'http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https%3A%2F%2Fvault.azure.net' -H 'Metadata: true'."],"exampleFix":"// before: relying on IMDS auto-discovery off-Azure\nconst client = new MongoClient(uri, {\n  autoEncryption: { kmsProviders: { azure: {} } } // IMDS path, fails off-Azure\n});\n// after: explicit Azure service principal credentials\nconst client = new MongoClient(uri, {\n  autoEncryption: {\n    kmsProviders: {\n      azure: {\n        tenantId: process.env.AZURE_TENANT_ID,\n        clientId: process.env.AZURE_CLIENT_ID,\n        clientSecret: process.env.AZURE_CLIENT_SECRET\n      }\n    }\n  }\n});","handlingStrategy":"fallback","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  const client = new MongoClient(uri, { autoEncryption: { kmsProviders: { azure: {} } } });\n  await client.connect();\n} catch (e) {\n  if (e instanceof MongoCryptAzureKMSRequestError && /Malformed JSON/.test(e.message)) {\n    // fall back to explicit Azure service principal credentials\n  }\n  throw e;\n}","preventionTips":["In production prefer explicit azure kmsProvider credentials (tenantId/clientId/clientSecret) over IMDS auto-discovery.","Allowlist 169.254.169.254 on any egress proxy when relying on managed identity."],"tags":["csfle","azure","kms","network","client-side-encryption"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}