{"record":{"id":"e7dc29c1627cea94","repo":"aio-libs/aiohttp","slug":"too-many-trailers-received","errorCode":null,"errorMessage":"Too many trailers received","messagePattern":"Too many trailers received","errorType":"http","errorClass":"BadHttpMessage","httpStatus":400,"severity":"error","filePath":"aiohttp/http_parser.py","lineNumber":1098,"sourceCode":"                                \"Bad trailer line ending, expected CRLF\"\n                            )\n                            set_exception(self.payload, exc)\n                            raise exc\n                        self._chunk_tail = chunk\n                        return PayloadState.PAYLOAD_NEEDS_INPUT, b\"\"\n\n                    line = chunk[:pos]\n                    chunk = chunk[pos + len(SEP) :]\n                    if SEP == b\"\\n\":  # For lax response parsing\n                        line = line.rstrip(b\"\\r\")\n\n                    if len(line) > self._max_field_size:\n                        raise LineTooLong(line[:100] + b\"...\", self._max_field_size)\n\n                    self._trailer_lines.append(line)\n\n                    if len(self._trailer_lines) > self._max_trailers:\n                        raise BadHttpMessage(\"Too many trailers received\")\n\n                    # \\r\\n\\r\\n found, end of stream\n                    if self._trailer_lines[-1] == b\"\":\n                        # Headers and trailers are defined the same way,\n                        # so we reuse the HeadersParser here.\n                        try:\n                            trailers, raw_trailers = self._headers_parser.parse_headers(\n                                self._trailer_lines\n                            )\n                        finally:\n                            self._trailer_lines.clear()\n                        self.payload.feed_eof()\n                        return PayloadState.PAYLOAD_COMPLETE, chunk\n\n        # Read all bytes until eof\n        elif self._type == ParseState.PARSE_UNTIL_EOF:\n            self._more_data_available = self.payload.feed_data(chunk)\n            while self._more_data_available:","sourceCodeStart":1080,"sourceCodeEnd":1116,"githubUrl":"https://github.com/aio-libs/aiohttp/blob/d041d4d0fd48c3f0832084d33be16cf1c4835f85/aiohttp/http_parser.py#L1080-L1116","documentation":"Raised as BadHttpMessage (HTTP 400) when the number of trailer lines in a chunked body exceeds _max_trailers (default 128, derived from max_headers). After each trailer line is appended, the parser checks 'if len(self._trailer_lines) > self._max_trailers' and raises. This bounds the count of trailer headers to prevent resource exhaustion.","triggerScenarios":"A chunked body whose trailer section contains more than max_trailers (default 128) lines before the terminating empty line. Fires inside PARSE_TRAILERS as lines accumulate.","commonSituations":"An attacker flooding the trailer section with many headers (resource-exhaustion); a misbehaving intermediary appending per-hop trailer headers; a server/client streaming many trailer headers by mistake; legitimate high trailer counts exceeding the default 128.","solutions":["Limit the number of trailer headers you send (<=128 by default).","If more trailers are genuinely needed, raise max_headers on the parser (ClientSession(..., max_headers=N) or RequestHandler kwargs).","Strip unnecessary trailers at proxies before forwarding.","Treat unbounded trailer counts from untrusted clients as malicious."],"exampleFix":"# before\r\nsession = aiohttp.ClientSession()\r\n\r\n# after (raise trailer/header cap if needed)\r\nsession = aiohttp.ClientSession(max_headers=256)","handlingStrategy":"validation","validationCode":"def trailer_count_ok(trailers: list, max_trailers: int = 128) -> bool:\n    return len(trailers) <= max_trailers","typeGuard":null,"tryCatchPattern":"from aiohttp.http_exceptions import BadHttpMessage\n\ntry:\n    parser.feed_data(raw)\nexcept BadHttpMessage as e:\n    respond_400(str(e))  # 'Too many trailers received'","preventionTips":["Limit trailer count to <= max_headers (default 128).","Raise max_headers on the parser if more trailers are required.","Strip unnecessary trailers at proxies.","Treat excessive trailers from untrusted clients as an attack."],"tags":["http-parser","trailers","chunked","limits","resource-exhaustion"],"backgroundTag":null,"analyzedSha":"d041d4d0fd48c3f0832084d33be16cf1c4835f85","analyzedAt":"2026-08-11T20:44:15.550Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}