{"record":{"id":"6cf422060ac3f4c0","repo":"aio-libs/aiohttp","slug":"server-attempted-redirecting-to-a-location-that-do","errorCode":null,"errorMessage":"Server attempted redirecting to a location that does not look like a URL","messagePattern":"Server attempted redirecting to a location that does not look like a URL","errorType":"exception","errorClass":"InvalidUrlRedirectClientError","httpStatus":null,"severity":"error","filePath":"aiohttp/client.py","lineNumber":824,"sourceCode":"                            hdrs.URI\n                        )\n                        if r_url is None:\n                            # see github.com/aio-libs/aiohttp/issues/2022\n                            break\n                        else:\n                            # reading from correct redirection\n                            # response is forbidden\n                            resp.release()\n\n                        try:\n                            parsed_redirect_url = URL(\n                                r_url, encoded=not self._requote_redirect_url\n                            )\n                        except ValueError as e:\n                            if req._body is not None:\n                                await req._body.close()\n                            resp.close()\n                            raise InvalidUrlRedirectClientError(\n                                r_url,\n                                \"Server attempted redirecting to a location that does not look like a URL\",\n                            ) from e\n\n                        scheme = parsed_redirect_url.scheme\n                        if scheme not in HTTP_AND_EMPTY_SCHEMA_SET:\n                            if req._body is not None:\n                                await req._body.close()\n                            resp.close()\n                            raise NonHttpUrlRedirectClientError(r_url)\n                        elif not scheme:\n                            parsed_redirect_url = url.join(parsed_redirect_url)\n\n                        try:\n                            redirect_origin = parsed_redirect_url.origin()\n                        except ValueError as origin_val_err:\n                            if req._body is not None:\n                                await req._body.close()","sourceCodeStart":806,"sourceCodeEnd":842,"githubUrl":"https://github.com/aio-libs/aiohttp/blob/d041d4d0fd48c3f0832084d33be16cf1c4835f85/aiohttp/client.py#L806-L842","documentation":"Raised as InvalidUrlRedirectClientError when yarl.URL() raises ValueError parsing the server-supplied redirect target (LOCATION/URI header). The redirect target is structurally not a URL and cannot be followed.","triggerScenarios":"Server returns a 3xx with a LOCATION header containing characters/syntax yarl cannot parse (control chars, malformed quoting, illegal percent-encoding). self._requote_redirect_url changes the encoded= flag passed to URL().","commonSituations":"Misconfigured or hostile server returning garbage LOCATION headers. Buggy server-side URL builders. Encoded vs raw redirect URL mismatch when requote_redirect_url is disabled.","solutions":["Set allow_redirects=False and follow redirects manually so you can sanitize the LOCATION header.","Fix or report the server returning the malformed redirect.","If requote_redirect_url is the cause, set ClientSession(requote_redirect_url=False) (or True) to match the server's encoding convention."],"exampleFix":"// before\nawait session.get(url)  # server returns malformed LOCATION -> raises\n// after\nresp = await session.get(url, allow_redirects=False)\nif 300 <= resp.status < 400:\n    next_url = URL(resp.headers['LOCATION'].strip())\n    resp = await session.get(next_url)","handlingStrategy":"try-catch","validationCode":"from aiohttp import URL\nfrom aiohttp.client_exceptions import InvalidURL\n\ndef safe_redirect_target(raw):\n    try:\n        return URL(raw, encoded=False)\n    except ValueError:\n        return None","typeGuard":"from aiohttp import URL\n\ndef is_valid_redirect_target(raw) -> bool:\n    try:\n        URL(raw)\n        return True\n    except ValueError:\n        return False","tryCatchPattern":"from aiohttp.client_exceptions import InvalidUrlRedirectClientError\n\ntry:\n    resp = await session.get(url)\nexcept InvalidUrlRedirectClientError as e:\n    # disable auto-follow and decide manually\n    resp = await session.get(url, allow_redirects=False)","preventionTips":["Validate server-supplied LOCATION values before following.","Use allow_redirects=False for clients that must not auto-trust server URLs.","Log redirect targets at the boundary for quick diagnosis."],"tags":["redirect","url-validation","server-error"],"backgroundTag":null,"analyzedSha":"d041d4d0fd48c3f0832084d33be16cf1c4835f85","analyzedAt":"2026-08-11T20:44:15.550Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}