{"record":{"id":"792c57f9a91e4e3a","repo":"actix/actix-web","slug":"invalid-chunk-size-linear-white-space","errorCode":null,"errorMessage":"Invalid chunk size linear white space","messagePattern":"Invalid chunk size linear white space","errorType":"exception","errorClass":"io::Error","httpStatus":null,"severity":"error","filePath":"actix-http/src/h1/chunked.rs","lineNumber":95,"sourceCode":"                Poll::Ready(Ok(ChunkedState::Size))\n            }\n            None => {\n                debug!(\"chunk size would overflow u64\");\n                Poll::Ready(Err(io::Error::new(\n                    io::ErrorKind::InvalidInput,\n                    \"Invalid chunk size line: Size is too big\",\n                )))\n            }\n        }\n    }\n\n    fn read_size_lws(rdr: &mut BytesMut) -> Poll<Result<ChunkedState, io::Error>> {\n        match byte!(rdr) {\n            // LWS can follow the chunk size, but no more digits can come\n            b'\\t' | b' ' => Poll::Ready(Ok(ChunkedState::SizeLws)),\n            b';' => Poll::Ready(Ok(ChunkedState::Extension)),\n            b'\\r' => Poll::Ready(Ok(ChunkedState::SizeLf)),\n            _ => Poll::Ready(Err(io::Error::new(\n                io::ErrorKind::InvalidInput,\n                \"Invalid chunk size linear white space\",\n            ))),\n        }\n    }\n    fn read_extension(rdr: &mut BytesMut) -> Poll<Result<ChunkedState, io::Error>> {\n        match byte!(rdr) {\n            b'\\r' => Poll::Ready(Ok(ChunkedState::SizeLf)),\n            // strictly 0x20 (space) should be disallowed but we don't parse quoted strings here\n            0x00..=0x08 | 0x0a..=0x1f | 0x7f => Poll::Ready(Err(io::Error::new(\n                io::ErrorKind::InvalidInput,\n                \"Invalid character in chunk extension\",\n            ))),\n            _ => Poll::Ready(Ok(ChunkedState::Extension)), // no supported extensions\n        }\n    }\n    fn read_size_lf(rdr: &mut BytesMut, size: u64) -> Poll<Result<ChunkedState, io::Error>> {\n        match byte!(rdr) {","sourceCodeStart":77,"sourceCodeEnd":113,"githubUrl":"https://github.com/actix/actix-web/blob/4d435abc281842f3cbee165b6cde739e001d3a25/actix-http/src/h1/chunked.rs#L77-L113","documentation":"Raised in read_size_lws (chunked.rs:95) when, after consuming linear whitespace (space/tab) following the chunk size, the next byte is not another LWS, a ';' (extension), or CR. RFC 7230 allows optional LWS after the size but nothing else, so any other character is a framing error surfacing as PayloadError::Io / 400.","triggerScenarios":"A chunk-size line like \"4 X\\r\\n\" where a non-LWS character follows the whitespace, or stray bytes after the size digits. The SizeLws state only accepts \\t, ' ', ';', '\\r'.","commonSituations":"Client inserting stray characters after the chunk size; corrupt body from a proxy; malformed custom HTTP serializer.","solutions":["Ensure chunk-size lines are strictly <hex-size> [ \";ext\" ] CRLF with only optional spaces/tabs before the extension or CRLF.","Use a mature HTTP client library rather than hand-serializing chunked bodies.","Verify any intermediary proxy preserves chunk framing byte-for-byte."],"exampleFix":"// before\n\"4 x\\r\\ndata\\r\\n\"\n// after\n\"4\\r\\ndata\\r\\n\"  // or \"4;ext\\r\\ndata\\r\\n\"","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"match payload.next().await {\n    Some(Err(PayloadError::Io(e))) if e.kind() == io::ErrorKind::InvalidInput =>\n        return HttpResponse::BadRequest().finish(), // bad LWS after chunk size\n    _ => { /* ... */ }\n}","preventionTips":["Format chunk-size lines as <hex>[;ext]CRLF only.","Use a vetted HTTP client.","Check proxy framing behavior."],"tags":["http","chunked-encoding","actix-http","protocol"],"backgroundTag":null,"analyzedSha":"4d435abc281842f3cbee165b6cde739e001d3a25","analyzedAt":"2026-08-09T01:01:40.926Z","contentChangedAt":"2026-08-09T01:01:40.926Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}