{"record":{"id":"a0df3f60901d8941","repo":"affaan-m/ECC","slug":"http-request-headers-too-large","errorCode":null,"errorMessage":"HTTP request headers too large","messagePattern":"HTTP request headers too large","errorType":"http","errorClass":"anyhow::Error","httpStatus":413,"severity":"warning","filePath":"ecc2/src/main.rs","lineNumber":4205,"sourceCode":"    }\n}\n\nfn read_http_request(\n    stream: &mut TcpStream,\n) -> Result<(String, String, BTreeMap<String, String>, Vec<u8>)> {\n    let mut buffer = Vec::new();\n    let mut temp = [0_u8; 1024];\n    let header_end = loop {\n        let read = stream.read(&mut temp)?;\n        if read == 0 {\n            anyhow::bail!(\"Unexpected EOF while reading HTTP request\");\n        }\n        buffer.extend_from_slice(&temp[..read]);\n        if let Some(index) = buffer.windows(4).position(|window| window == b\"\\r\\n\\r\\n\") {\n            break index + 4;\n        }\n        if buffer.len() > 64 * 1024 {\n            anyhow::bail!(\"HTTP request headers too large\");\n        }\n    };\n\n    let header_text = String::from_utf8(buffer[..header_end].to_vec())\n        .context(\"HTTP request headers were not valid UTF-8\")?;\n    let mut lines = header_text.split(\"\\r\\n\");\n    let request_line = lines\n        .next()\n        .filter(|line| !line.trim().is_empty())\n        .ok_or_else(|| anyhow::anyhow!(\"Missing HTTP request line\"))?;\n    let mut request_parts = request_line.split_whitespace();\n    let method = request_parts\n        .next()\n        .ok_or_else(|| anyhow::anyhow!(\"Missing HTTP method\"))?\n        .to_string();\n    let path = request_parts\n        .next()\n        .ok_or_else(|| anyhow::anyhow!(\"Missing HTTP path\"))?","sourceCodeStart":4187,"sourceCodeEnd":4223,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/ecc2/src/main.rs#L4187-L4223","documentation":"While accumulating request bytes the HTTP reader enforces a 64 KiB cap on the header section. If no `\\r\\n\\r\\n` terminator is found before the buffer exceeds 64 * 1024 bytes, it bails with this error. This protects the server from unbounded memory growth from malicious or broken clients.","triggerScenarios":"A client sends HTTP headers totaling more than 64 KiB (e.g. a huge `Cookie` or `Authorization` header), or sends garbage bytes that never contain the `\\r\\n\\r\\n` delimiter.","commonSituations":"Cookie bloat after many sessions/tokens accumulate in one request; a client appending many large custom headers; a non-HTTP client (raw TCP) streaming data to the port; fuzzing or a request smuggling probe.","solutions":["Reduce request header size on the client — trim cookies or split authentication headers.","Clear accumulated cookies for the host in the browser/client and retry.","If large headers are a legitimate requirement, raise the 64 * 1024 limit in the server's read loop.","Verify the client is speaking HTTP/1.1 with proper `\\r\\n` line endings."],"exampleFix":"// before (server)\nif buffer.len() > 64 * 1024 {\n    anyhow::bail!(\"HTTP request headers too large\");\n}\n\n// after (allow 256 KiB)\nconst MAX_HEADER_BYTES: usize = 256 * 1024;\nif buffer.len() > MAX_HEADER_BYTES {\n    anyhow::bail!(\"HTTP request headers too large\");\n}","handlingStrategy":"validation","validationCode":"// Client-side check before sending\nconst MAX_HEADER_BYTES: usize = 64 * 1024;\nif request_header_bytes.len() > MAX_HEADER_BYTES {\n    // trim cookies/headers or reject before sending\n}","typeGuard":null,"tryCatchPattern":"match send_request(req) {\n    Err(e) if e.to_string().contains(\"headers too large\") => {\n        // reduce headers (clear cookies) and retry once\n    }\n    other => other?,\n}","preventionTips":["Keep cookies and custom headers small; periodically clear stale cookies.","Never send raw non-HTTP bytes to the HTTP port.","If you legitimately need big headers, raise the server limit consciously and document it."],"tags":["http","limits","rust"],"backgroundTag":"payload-too-large","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}