{"record":{"id":"b4f995461c9eedce","repo":"actix/actix-web","slug":"invalid-chunk-size-lf","errorCode":null,"errorMessage":"Invalid chunk size LF","messagePattern":"Invalid chunk size LF","errorType":"exception","errorClass":"io::Error","httpStatus":null,"severity":"error","filePath":"actix-http/src/h1/chunked.rs","lineNumber":116,"sourceCode":"            ))),\n        }\n    }\n    fn read_extension(rdr: &mut BytesMut) -> Poll<Result<ChunkedState, io::Error>> {\n        match byte!(rdr) {\n            b'\\r' => Poll::Ready(Ok(ChunkedState::SizeLf)),\n            // strictly 0x20 (space) should be disallowed but we don't parse quoted strings here\n            0x00..=0x08 | 0x0a..=0x1f | 0x7f => Poll::Ready(Err(io::Error::new(\n                io::ErrorKind::InvalidInput,\n                \"Invalid character in chunk extension\",\n            ))),\n            _ => Poll::Ready(Ok(ChunkedState::Extension)), // no supported extensions\n        }\n    }\n    fn read_size_lf(rdr: &mut BytesMut, size: u64) -> Poll<Result<ChunkedState, io::Error>> {\n        match byte!(rdr) {\n            b'\\n' if size > 0 => Poll::Ready(Ok(ChunkedState::Body)),\n            b'\\n' if size == 0 => Poll::Ready(Ok(ChunkedState::EndCr)),\n            _ => Poll::Ready(Err(io::Error::new(\n                io::ErrorKind::InvalidInput,\n                \"Invalid chunk size LF\",\n            ))),\n        }\n    }\n\n    fn read_body(\n        rdr: &mut BytesMut,\n        rem: &mut u64,\n        buf: &mut Option<Bytes>,\n    ) -> Poll<Result<ChunkedState, io::Error>> {\n        trace!(\"Chunked read, remaining={:?}\", rem);\n\n        let len = rdr.len() as u64;\n        if len == 0 {\n            Poll::Ready(Ok(ChunkedState::Body))\n        } else {\n            let slice;","sourceCodeStart":98,"sourceCodeEnd":134,"githubUrl":"https://github.com/actix/actix-web/blob/4d435abc281842f3cbee165b6cde739e001d3a25/actix-http/src/h1/chunked.rs#L98-L134","documentation":"Raised in read_size_lf (chunked.rs:116) when the byte expected to be the LF terminating the chunk-size line is not '\\n'. After read_size/read_size_lws/read_extension consume the CR, this state requires a single '\\n'; anything else is a malformed CRLF terminator.","triggerScenarios":"A chunk-size line terminates with CR followed by a non-LF byte, e.g. \"4\\rX\\r\\n\" or a lone CR without LF. The state machine enters SizeLf expecting '\\n' and gets something else.","commonSituations":"Client using bare LF (\\n) line endings inconsistently so the parser sees CR then a digit; corrupt/truncated body; proxy mangling CRLF.","solutions":["Always terminate chunk-size lines with a full CRLF (\\r\\n) as required by RFC 7230.","Use a standards-compliant HTTP client library to serialize chunked requests.","Check intermediary proxies for CRLF normalization bugs."],"exampleFix":"// before\n\"4\\rdata\\r\\n\"\n// after\n\"4\\r\\ndata\\r\\n\"","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"match payload.next().await {\n    Some(Err(PayloadError::Io(e))) if e.kind() == io::ErrorKind::InvalidInput =>\n        return HttpResponse::BadRequest().finish(), // chunk size LF missing\n    _ => { /* ... */ }\n}","preventionTips":["Terminate every chunk-size line with CRLF (\\r\\n).","Use a compliant client library.","Audit proxies for CRLF normalization."],"tags":["http","chunked-encoding","actix-http","protocol"],"backgroundTag":null,"analyzedSha":"4d435abc281842f3cbee165b6cde739e001d3a25","analyzedAt":"2026-08-09T01:01:40.926Z","contentChangedAt":"2026-08-09T01:01:40.926Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}