{"record":{"id":"8672be54f9c41042","repo":"hashicorp/terraform","slug":"failed-to-decode-content-md5-s-s","errorCode":null,"errorMessage":"Failed to decode Content-MD5 '%s': %s","messagePattern":"Failed to decode Content-MD5 '(.+?)': (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/http/client.go","lineNumber":191,"sourceCode":"\tif _, err := io.Copy(buf, resp.Body); err != nil {\n\t\treturn nil, diags.Append(fmt.Errorf(\"Failed to read remote state: %s\", err))\n\t}\n\n\t// Create the payload\n\tpayload := &remote.Payload{\n\t\tData: buf.Bytes(),\n\t}\n\n\t// If there was no data, then return nil\n\tif len(payload.Data) == 0 {\n\t\treturn nil, diags\n\t}\n\n\t// Check for the MD5\n\tif raw := resp.Header.Get(\"Content-MD5\"); raw != \"\" {\n\t\tmd5, err := base64.StdEncoding.DecodeString(raw)\n\t\tif err != nil {\n\t\t\treturn nil, diags.Append(fmt.Errorf(\n\t\t\t\t\"Failed to decode Content-MD5 '%s': %s\", raw, err))\n\t\t}\n\n\t\tpayload.MD5 = md5\n\t} else {\n\t\t// Generate the MD5\n\t\thash := md5.Sum(payload.Data)\n\t\tpayload.MD5 = hash[:]\n\t}\n\n\treturn payload, diags\n}\n\nfunc (c *httpClient) Put(data []byte) tfdiags.Diagnostics {\n\tvar diags tfdiags.Diagnostics\n\n\t// Copy the target URL\n\tbase := *c.URL","sourceCodeStart":173,"sourceCodeEnd":209,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/http/client.go#L173-L209","documentation":"Thrown when the Content-MD5 response header is present but cannot be base64-decoded (client.go:184-191). The backend reads Content-MD5 to set payload.MD5 for integrity verification; if the header is malformed, base64.StdEncoding.DecodeString fails. The two %s fields are the raw header value and the decode error.","triggerScenarios":"The state server returns a Content-MD5 header that is not valid base64 (wrong encoding, padding stripped, hex instead of base64, or corrupted). This is a server/intermediary bug, not a client config issue.","commonSituations":"A custom state server emits a hex-encoded or double-encoded MD5; a CDN/proxy rewrites or corrupts the header; the server mistakenly returns the raw 16-byte digest instead of base64.","solutions":["Inspect the actual Content-MD5 header value the server returns and fix its encoding to base64.","If you control the server, ensure Content-MD5 is base64.StdEncoding of the raw MD5 digest (RFC 2616).","If an intermediary corrupts the header, bypass or reconfigure it.","As a workaround, remove the Content-MD5 header at the server so the client falls back to computing MD5 itself (client.go:193-196)."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"// If you control a custom client, fall back to computing MD5 locally when the header is malformed:\n// payload, diags := httpClient.Get()\n// for _, d := range diags {\n//   if strings.Contains(d.Description().Summary, \"Failed to decode Content-MD5\") {\n//     // server bug: request operator fix the header encoding\n//   }\n// }","preventionTips":["If you operate the state server, always emit Content-MD5 as base64(raw MD5) per RFC 2616.","Do not let proxies rewrite/corrupt Content-MD5.","Omit the header rather than emit a malformed one — the client computes MD5 itself."],"tags":["http-backend","md5","integrity","header"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}