vercel/next.js · error · Error

Multiple router state headers were sent. This is not allowed

Error message

Multiple router state headers were sent. This is not allowed.

What it means

parseAndValidateFlightRouterState throws when the RSC request's router-state header arrives as an array (i.e. the header was sent multiple times) instead of a single string; exactly one Next-Router-State-Tree value must exist for the state to be parseable.

Source

Thrown at packages/next/src/server/app-render/parse-and-validate-flight-router-state.tsx:21

import { assert } from 'next/dist/compiled/superstruct'

export function parseAndValidateFlightRouterState(
  stateHeader: string | string[]
): FlightRouterState
export function parseAndValidateFlightRouterState(
  stateHeader: undefined
): undefined
export function parseAndValidateFlightRouterState(
  stateHeader: string | string[] | undefined
): FlightRouterState | undefined
export function parseAndValidateFlightRouterState(
  stateHeader: string | string[] | undefined
): FlightRouterState | undefined {
  if (typeof stateHeader === 'undefined') {
    return undefined
  }
  if (Array.isArray(stateHeader)) {
    throw new Error(
      'Multiple router state headers were sent. This is not allowed.'
    )
  }

  // We limit the size of the router state header to ~40kb. This is to prevent
  // a malicious user from sending a very large header and slowing down the
  // resolving of the router state.
  // This is around 2,000 nested or parallel route segment states:
  // '{"children":["",{}]}'.length === 20.
  if (stateHeader.length > 20 * 2000) {
    throw new Error('The router state header was too large.')
  }

  try {
    const state = JSON.parse(decodeURIComponent(stateHeader))
    assert(state, flightRouterStateSchema)
    return state
  } catch {

View on GitHub (pinned to 0eb3775416)

Solutions

  1. Ensure only one `next-router-state-tree` header is sent with the request; remove duplicated header setters in proxies or middleware.
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/next/src/server/app-render/parse-and-validate-flight-router-state.tsx:21 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of vercel/next.js@0eb3775416 (2026-08-19). Data as JSON: /api/errors/4a2bd157aeda016b. Report an issue: GitHub.