{"record":{"id":"54f609f9dcd01e72","repo":"actix/actix-web","slug":"invalid-chunk-size-line-invalid-size","errorCode":null,"errorMessage":"Invalid chunk size line: Invalid Size","messagePattern":"Invalid chunk size line: Invalid Size","errorType":"exception","errorClass":"io::Error","httpStatus":null,"severity":"error","filePath":"actix-http/src/h1/chunked.rs","lineNumber":65,"sourceCode":"            BodyLf => ChunkedState::read_body_lf(body),\n            EndCr => ChunkedState::read_end_cr(body),\n            EndLf => ChunkedState::read_end_lf(body),\n            End => Poll::Ready(Ok(ChunkedState::End)),\n        }\n    }\n\n    fn read_size(rdr: &mut BytesMut, size: &mut u64) -> Poll<Result<ChunkedState, io::Error>> {\n        let radix = 16;\n\n        let rem = match byte!(rdr) {\n            b @ b'0'..=b'9' => b - b'0',\n            b @ b'a'..=b'f' => b + 10 - b'a',\n            b @ b'A'..=b'F' => b + 10 - b'A',\n            b'\\t' | b' ' => return Poll::Ready(Ok(ChunkedState::SizeLws)),\n            b';' => return Poll::Ready(Ok(ChunkedState::Extension)),\n            b'\\r' => return Poll::Ready(Ok(ChunkedState::SizeLf)),\n            _ => {\n                return Poll::Ready(Err(io::Error::new(\n                    io::ErrorKind::InvalidInput,\n                    \"Invalid chunk size line: Invalid Size\",\n                )));\n            }\n        };\n\n        match size.checked_mul(radix) {\n            Some(n) => {\n                *size = n;\n                *size += rem as u64;\n\n                Poll::Ready(Ok(ChunkedState::Size))\n            }\n            None => {\n                debug!(\"chunk size would overflow u64\");\n                Poll::Ready(Err(io::Error::new(\n                    io::ErrorKind::InvalidInput,\n                    \"Invalid chunk size line: Size is too big\",","sourceCodeStart":47,"sourceCodeEnd":83,"githubUrl":"https://github.com/actix/actix-web/blob/4d435abc281842f3cbee165b6cde739e001d3a25/actix-http/src/h1/chunked.rs#L47-L83","documentation":"Raised in ChunkedState::read_size (chunked.rs:65) when the first byte of a chunk-size field is not a hex digit and not one of the allowed delimiters (space/tab, ';', or CR). It signals a structurally invalid chunked transfer-encoding body and surfaces upstream as a PayloadError::Io, typically causing a 400 Bad Request when reading the request body.","triggerScenarios":"A chunked request body begins a chunk-size line with a non-hex character, e.g. the body sent \"G\\r\\n...\" or \"x4\\r\\ndata\\r\\n\". The byte! macro reads one byte and the wildcard arm at chunked.rs:64 fires.","commonSituations":"A buggy HTTP client not emitting hex chunk sizes; a request smuggling attempt; a proxy that strips or corrupts the chunked encoding; misconfigured reverse proxy forwarding a de-chunked body but leaving Transfer-Encoding: chunked.","solutions":["Ensure the client emits chunk sizes as lowercase/uppercase hexadecimal followed by CRLF.","If behind a reverse proxy, make proxy and backend agree: either the proxy fully de-chunks and sends Content-Length, or it forwards valid chunked framing.","Handle the resulting PayloadError and respond 400 rather than 500."],"exampleFix":"// before (client body)\n\"G\\r\\nhello\\r\\n0\\r\\n\\r\\n\"\n// after\n\"5\\r\\nhello\\r\\n0\\r\\n\\r\\n\"","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"// Errors surface while reading the body payload\nwhile let Some(res) = payload.next().await {\n    match res {\n        Ok(chunk) => { /* process */ }\n        Err(PayloadError::Io(e)) if e.kind() == io::ErrorKind::InvalidInput =>\n            return HttpResponse::BadRequest().finish(),\n        Err(e) => return Err(e.into()),\n    }\n}","preventionTips":["Use a compliant HTTP client for chunked requests.","Don't hand-roll chunked framing.","Ensure proxies either forward valid chunked bodies or fully de-chunk them."],"tags":["http","chunked-encoding","actix-http","protocol"],"backgroundTag":null,"analyzedSha":"4d435abc281842f3cbee165b6cde739e001d3a25","analyzedAt":"2026-08-09T01:01:40.926Z","contentChangedAt":"2026-08-09T01:01:40.926Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}