# Haproxy blocking http response with error "invalid response"

**URL:** <https://discourse.haproxy.org/t/haproxy-blocking-http-response-with-error-invalid-response/11653>\
**Category:** Help!\
**Created:** [March 10, 2025, 8:19am UTC](https://discourse.haproxy.org/t/haproxy-blocking-http-response-with-error-invalid-response/11653 "2025-03-10T08:19:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![santoshnadar86](https://avatars.discourse-cdn.com/v4/letter/s/439d5e/32.png) [@santoshnadar86](https://discourse.haproxy.org/u/santoshnadar86)\
**Post date:** [March 10, 2025, 8:19am UTC](https://discourse.haproxy.org/t/haproxy-blocking-http-response-with-error-invalid-response/11653/1 "2025-03-10T08:19:11Z")

</div>

haproxy is blocking http response with error “invalid response”. Haproxy Log gives PH 502 bad gateway.

setting option accept-invalid-http-response does not work

I am not seeing anything wrong with the header though. This was working fine when we were in version 2.4. Issue started after upgrading to version 3.0.3

socat gives the below error output:

backend be\_xxx.xxx.com (#199): invalid response  
frontend FE01 (#2), server 1 (#1), event #66, src xx.xx.xx.228:40675  
buffer starts at 0 (including 0 out), 30143 free,  
len 2625, wraps at 32720, error at position 640  
H1 connection flags 0x80000100, H1 stream flags 0x00014840  
H1 msg state MSG\_CHUNK\_SIZE(26), H1 msg flags 0x00011736  
H1 chunk len 0 bytes, H1 body len 0 bytes :

00000 HTTP/1.1 201 \r\n  
00015 X-Application-Context: api-gateway-service:8081\r\n  
00064 Access-Control-Allow-Origin: [https://xxx.xxx.com](https://xxx.xxx.com)\r\n  
00126 Vary: Origin\r\n  
00140 Access-Control-Allow-Credentials: true\r\n  
00180 Access-Control-Allow-Methods: POST, GET, OPTIONS, DELETE\r\n  
00238 Access-Control-Max-Age: 3600\r\n  
00268 Access-Control-Allow-Headers: Content-Type, Accept, X-Requested-With,  
00338+ Authorization\r\n  
00353 Access-Control-Expose-Headers: Content-Range\r\n  
00399 X-Content-Type-Options: nosniff\r\n  
00432 X-XSS-Protection: 1; mode=block\r\n  
00465 X-Frame-Options: DENY\r\n  
00488 Transfer-Encoding: chunked\r\n  
00516 Date: Mon, 10 Mar 2025 07:30:33 GMT\r\n  
00553 Connection: close\r\n  
00572 Content-Type: application/vnd.Analyttica.TreasureHunt.Token+json\r\n  
00638 \r\n  
00640 {“authorization”:“eyJhbGciOiJIUzUxMiJ9.eyJzdWIiOiJlY3dfdXNlckBhbmFseXR  
00710+ 0aWNhLmNvbSIsImF1ZGllbmNlIjoid2ViIiwiY3JlYXRlZCI6MTc0MTU5MTgzMzY2MiwiZ  
00780+ XhwIjoxNzQyMTk2NjMzLCJ0ZW5hbnQiOiJhbmFseXR0aWNhIn0.ckKypc4CSCYOhb95qRW  
00850+ wjKxUMxpAXUO\_EHXDxk1ARSNb5VOmtqNhGsTQ5NY-FEACEWWy0Z5Hm9VT9Ok2cKbLtA”,"  
00920+ user\_id":3,“joyride\_locked”:true,“welcome\_message\_locked”:false,“tenan  
00990+ t\_name”:“analyttica”,“tc\_accepted”:true,“can\_user\_enroll\_free”:true,“c  
01060+ an\_user\_enroll\_paid”:true,“can\_console\_open”:false,“restricted\_for\_mul  
01130+ tiple\_logins”:false,“signup”:false,“\_links”:{“lock\_joyride”:{“href”:“/  
01200+ users/3/lock/joyride”,“method”:“POST”,“accept”:“application/json”,“typ  
01270+ e”:“application/json”},“notification”:{“href”:“/users/3/notifications”  
01340+ ,“method”:“GET”,“accept”:“application/json”,“type”:“application/json”}  
01410+ ,“accept\_tc”:{“href”:“/users/3/lock/acceptTC”,“method”:“POST”,“accept”  
01480+ :“application/json”,“type”:“application/json”},“preloaded\_datasets”:{"  
01550+ href":“/projects/datasets/preloaded”,“method”:“GET”,“accept”:“applicat  
01620+ ion/vnd.Analyttica.TreasureHunt.PreloadedDatasets+json”,“type”:null},"  
01690+ all\_notification":{“href”:“/users/3/allNotifications”,“method”:“GET”,"  
01760+ accept":“application/json”,“type”:“application/json”},“notification\_ma  
01830+ rk\_all\_read”:{“href”:“/users/3/notifications/markAllRead”,“method”:“PO  
01900+ ST”,“accept”:“application/json”,“type”:“application/json”},“user\_profi  
01970+ le”:{“href”:“/users/3/profile”,“method”:“GET”,“accept”:“application/vn  
02040+ d.Analyttica.TreasureHunt.UserProfile+json”,“type”:null},“lock\_welcome  
02110+ \_note”:{“href”:“/users/3/lock/welcomenote”,“method”:“POST”,“accept”:“a  
02180+ pplication/json”,“type”:“application/json”},“notification\_count”:{“hre  
02250+ f”:“/users/3/notifications/count”,“method”:“GET”,“accept”:“application  
02320+ /json”,“type”:“application/json”},“get\_address”:{“href”:“/users/3/addr  
02390+ ess”,“method”:“GET”,“accept”:“application/json”,“type”:null},“marketpl  
02460+ ace\_courses”:{“href”:“/users/3/marketplace-courses”,“method”:“GET”,“ac  
02530+ cept”:“application/vnd.Analyttica.TreasureHunt.MarketplaceCourseCollec  
02600+ tion+json”,“type”:null}}}

Output of haproxy -vv:

HAProxy version 3.0.3-95a607c 2024/07/11 - [https://haproxy.org/](https://haproxy.org/)  
Status: long-term supported branch - will stop receiving fixes around Q2 2029.  
Known bugs: [http://www.haproxy.org/bugs/bugs-3.0.3.html](http://www.haproxy.org/bugs/bugs-3.0.3.html)  
Running on: Linux 4.18.0-553.32.1.el8\_10.x86\_64 #1 SMP Wed Dec 11 16:33:48 UTC 2024 x86\_64  
Build options :  
TARGET = linux-glibc  
CC = cc  
CFLAGS = -O2 -g -fwrapv  
OPTIONS = USE\_OPENSSL=1 USE\_LUA=1 USE\_SYSTEMD=1 USE\_PCRE=1  
DEBUG =

Feature list : -51DEGREES +ACCEPT4 +BACKTRACE -CLOSEFROM +CPU\_AFFINITY +CRYPT\_H -DEVICEATLAS +DL -ENGINE +EPOLL -EVPORTS +GETADDRINFO -KQUEUE -LIBATOMIC +LIBCRYPT +LINUX\_CAP +LINUX\_SPLICE +LINUX\_TPROXY +LUA +MATH -MEMORY\_PROFILING +NETFILTER +NS -OBSOLETE\_LINKER +OPENSSL -OPENSSL\_AWSLC -OPENSSL\_WOLFSSL -OT +PCRE -PCRE2 -PCRE2\_JIT -PCRE\_JIT +POLL +PRCTL -PROCCTL -PROMEX -PTHREAD\_EMULATION -QUIC -QUIC\_OPENSSL\_COMPAT +RT +SHM\_OPEN +SLZ +SSL -STATIC\_PCRE -STATIC\_PCRE2 +SYSTEMD +TFO +THREAD +THREAD\_DUMP +TPROXY -WURFL -ZLIB

Default settings :  
bufsize = 16384, maxrewrite = 1024, maxpollevents = 200

Built with multi-threading support (MAX\_TGROUPS=16, MAX\_THREADS=256, default=2).  
Built with OpenSSL version : OpenSSL 1.1.1k FIPS 25 Mar 2021  
Running on OpenSSL version : OpenSSL 1.1.1k FIPS 25 Mar 2021  
OpenSSL library supports TLS extensions : yes  
OpenSSL library supports SNI : yes  
OpenSSL library supports : TLSv1.0 TLSv1.1 TLSv1.2 TLSv1.3  
Built with Lua version : Lua 5.3.5  
Built with network namespace support.  
Built with libslz for stateless compression.  
Compression algorithms supported : identity(“identity”), deflate(“deflate”), raw-deflate(“deflate”), gzip(“gzip”)  
Built with transparent proxy support using: IP\_TRANSPARENT IPV6\_TRANSPARENT IP\_FREEBIND  
Built with PCRE version : 8.42 2018-03-20  
Running on PCRE version : 8.42 2018-03-20  
PCRE library supports JIT : no (USE\_PCRE\_JIT not set)  
Encrypted password support via crypt(3): yes  
Built with gcc compiler version 8.5.0 20210514 (Red Hat 8.5.0-20)

Available polling systems :  
epoll : pref=300, test result OK  
poll : pref=200, test result OK  
select : pref=150, test result OK  
Total: 3 (3 usable), will use epoll.

Available multiplexer protocols :  
(protocols marked as cannot be specified using ‘proto’ keyword)  
h2 : mode=HTTP side=FE|BE mux=H2 flags=HTX|HOL\_RISK|NO\_UPG  
 : mode=HTTP side=FE|BE mux=H1 flags=HTX  
h1 : mode=HTTP side=FE|BE mux=H1 flags=HTX|NO\_UPG  
fcgi : mode=HTTP side=BE mux=FCGI flags=HTX|HOL\_RISK|NO\_UPG  
 : mode=TCP side=FE|BE mux=PASS flags=  
none : mode=TCP side=FE|BE mux=PASS flags=NO\_UPG

Available services : none

Available filters :  
[BWLIM] bwlim-in  
[BWLIM] bwlim-out  
[CACHE] cache  
[COMP] compression  
[FCGI] fcgi-app  
[SPOE] spoe  
[TRACE] trace

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [March 10, 2025, 8:36am UTC](https://discourse.haproxy.org/t/haproxy-blocking-http-response-with-error-invalid-response/11653/2 "2025-03-10T08:36:14Z")

</div>

The response is invalid.

It is indicating chunked transfer encoding in the header, but the payload is not actually chunked.

The response is not parsable, the application needs to be fixed.

---

<div class="post-metadata">

**Author:** ![santoshnadar86](https://avatars.discourse-cdn.com/v4/letter/s/439d5e/32.png) [@santoshnadar86](https://discourse.haproxy.org/u/santoshnadar86)\
**Post date:** [March 10, 2025, 8:49am UTC](https://discourse.haproxy.org/t/haproxy-blocking-http-response-with-error-invalid-response/11653/3 "2025-03-10T08:49:31Z")

</div>

Oh, let me work with the developer of the application. Thanks!  
Will keep this post updated.

---

<div class="post-metadata">

**Author:** ![santoshnadar86](https://avatars.discourse-cdn.com/v4/letter/s/439d5e/32.png) [@santoshnadar86](https://discourse.haproxy.org/u/santoshnadar86)\
**Post date:** [March 25, 2026, 1:27pm UTC](https://discourse.haproxy.org/t/haproxy-blocking-http-response-with-error-invalid-response/11653/4 "2026-03-25T13:27:25Z")

</div>

Hello Lukas,

I know it has been quite some time now for this post.  
The developers of the application has informed me that they did not find anything wrong in their code/application.

They asked me a question that why is it working in haproxy version 2.4 and anything above gives the 502 error (even version 2.8 throws the error)

It would be a great help if you can suggest a workaround for this issue.

---

<div class="post-metadata">

**Author:** ![lukastribus](https://avatars.discourse-cdn.com/v4/letter/l/7ea924/32.png) [@lukastribus](https://discourse.haproxy.org/u/lukastribus)\
**Post date:** [March 25, 2026, 1:58pm UTC](https://discourse.haproxy.org/t/haproxy-blocking-http-response-with-error-invalid-response/11653/5 "2026-03-25T13:58:53Z")

</div>

What is wrong with the response has been indicated in this thread, which is that your backend server is emitting a `Transfer-Encoding:chunked` header, when the payload is not actually chunked. This is what your developers need to fix.

Haproxy 2.4 works because it does not fully parse the response, so it just goes through as is, and then the browsers have to figure out what to do with this invalid response.

Later haproxy versions fully parse the HTTP response, because that is required for new features like H2 and H3 support and also because this invalid behavior can lead to request smuggling vulnerabilities.
