{"record":{"id":"57daefdab67a0ae0","repo":"actix/actix-web","slug":"invalid-header-value","errorCode":null,"errorMessage":"Invalid header value","messagePattern":"Invalid header value","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"actix-web/src/middleware/default_headers.rs","lineNumber":94,"sourceCode":"    #[doc(hidden)]\n    #[deprecated(\n        since = \"4.0.0\",\n        note = \"Prefer `.add((key, value))`. Will be removed in v5.\"\n    )]\n    pub fn header<K, V>(self, key: K, value: V) -> Self\n    where\n        HeaderName: TryFrom<K>,\n        <HeaderName as TryFrom<K>>::Error: Into<HttpError>,\n        HeaderValue: TryFrom<V>,\n        <HeaderValue as TryFrom<V>>::Error: Into<HttpError>,\n    {\n        self.add((\n            HeaderName::try_from(key)\n                .map_err(Into::into)\n                .expect(\"Invalid header name\"),\n            HeaderValue::try_from(value)\n                .map_err(Into::into)\n                .expect(\"Invalid header value\"),\n        ))\n    }\n\n    /// Adds a default *Content-Type* header if response does not contain one.\n    ///\n    /// Default is `application/octet-stream`.\n    pub fn add_content_type(self) -> Self {\n        #[allow(clippy::declare_interior_mutable_const)]\n        const HV_MIME: HeaderValue = HeaderValue::from_static(\"application/octet-stream\");\n        self.add((CONTENT_TYPE, HV_MIME))\n    }\n}\n\nimpl<S, B> Transform<S, ServiceRequest> for DefaultHeaders\nwhere\n    S: Service<ServiceRequest, Response = ServiceResponse<B>, Error = Error>,\n    S::Future: 'static,\n{","sourceCodeStart":76,"sourceCodeEnd":112,"githubUrl":"https://github.com/actix/actix-web/blob/4d435abc281842f3cbee165b6cde739e001d3a25/actix-web/src/middleware/default_headers.rs#L76-L112","documentation":"This is a runtime panic from the deprecated `DefaultHeaders::header()` method. When the provided value cannot be converted into a valid `HeaderValue` via `HeaderValue::try_from(value)`, the `.expect(\"Invalid header value\")` at line 94 panics. Header values must not contain certain bytes like raw newlines (`\\n`, `\\r`) or other control characters.","triggerScenarios":"Calling the deprecated `.header(key, value)` with a value containing invalid bytes such as `\"\\n\"`, `\"\\r\\n\"`, null bytes, or other non-visible ASCII control characters. For example, `.header(\"X-Test\", \"\\n\")` will panic.","commonSituations":"Embedding user input or multi-line strings into header values without sanitization. Using the deprecated `.header()` method instead of `.add()`.","solutions":["Sanitize or validate header values before passing them: reject or escape control characters","Use `HeaderValue::try_from(value)` and handle the error instead of panicking","Migrate to the `.add((key, value))` API (though it also panics on invalid values; validation is still needed)","Ensure header values are visible ASCII or valid percent-encoded UTF-8 without raw newlines or control chars"],"exampleFix":"// before (deprecated, panics on invalid value)\nlet mw = DefaultHeaders::new().header(\"X-Test\", user_input); // panics if user_input has \\n\n\n// after (validated)\nlet mw = DefaultHeaders::new();\nif let Ok(val) = HeaderValue::try_from(user_input.trim()) {\n    let mw = mw.add((\"X-Test\", val));\n}","handlingStrategy":"validation","validationCode":"// Validate header values before passing to the middleware.\nuse actix_web::http::header::HeaderValue;\n\nfn is_valid_header_value(value: &str) -> bool {\n    HeaderValue::try_from(value).is_ok()\n}\n\n// Sanitize user input before using as header value.\nfn sanitize_header_value(input: &str) -> String {\n    input.chars().filter(|c| !c.is_control()).collect()\n}","typeGuard":"use actix_web::http::header::HeaderValue;\n\nfn is_valid_header_value(value: &str) -> bool {\n    HeaderValue::try_from(value).is_ok()\n}","tryCatchPattern":"// Do not use the deprecated .header() method. Use .add() with validation:\nlet mw = DefaultHeaders::new();\nif let Ok(val) = HeaderValue::try_from(sanitized_value) {\n    let mw = mw.add((\"X-Custom\", val));\n}","preventionTips":["Always sanitize user input before using it as a header value — strip control characters and newlines","Validate with HeaderValue::try_from() before constructing the middleware","Migrate from the deprecated .header() to the .add((key, value)) API","Header values must not contain raw \\r, \\n, or other non-visible control bytes"],"tags":["rust","actix-web","middleware","runtime-panic","headers","deprecated","input-validation"],"backgroundTag":null,"analyzedSha":"4d435abc281842f3cbee165b6cde739e001d3a25","analyzedAt":"2026-08-09T01:01:40.926Z","contentChangedAt":"2026-08-09T01:01:40.926Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}