# BUG: panic when packetbeat parsing HTTP host header with non-standard format

**URL:** <https://discuss.elastic.co/t/bug-panic-when-packetbeat-parsing-http-host-header-with-non-standard-format/342258>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [September 4, 2023, 12:00pm UTC](https://discuss.elastic.co/t/bug-panic-when-packetbeat-parsing-http-host-header-with-non-standard-format/342258 "2023-09-04T12:00:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![moonD4rk](https://avatars.discourse-cdn.com/v4/letter/m/9f8e36/32.png) [@moonD4rk](https://discuss.elastic.co/u/moonD4rk)\
**Post date:** [September 4, 2023, 12:00pm UTC](https://discuss.elastic.co/t/bug-panic-when-packetbeat-parsing-http-host-header-with-non-standard-format/342258/1 "2023-09-04T12:00:58Z")

</div>

#### Summary:

Packetbeat(all version) encounters a panic when parsing HTTP requests that have a non-standard `Host` header. The issue occurs in the function `extractHostHeader` and manifests as an "index out of range" panic.

#### Steps to Reproduce:

1. Use Packetbeat to capture HTTP traffic.
2. Make an HTTP request where the `Host` header is of the form `:12345` (just a port number without the hostname).

#### Expected Result:

Packetbeat should handle non-standard `Host` headers gracefully, either by ignoring them or logging an error message.

#### Actual Result:

Packetbeat panics with "index out of range".

```auto
panic: runtime error: index out of range [0] with length 0

goroutine 130 [running]:
***** /protos/http.extractHostHeader({0xc01cf26ea8, 0x3})
        ***** /protos/http/http.go:737 +0x21b
***** /protos/http.(*httpPlugin).newTransaction(0xc0000f4f70, 0xc0073d8c80, 0xc0 073d9180)
        ***** /protos/http/http.go:541 +0xbff
***** /protos/http.(*httpPlugin).correlate(0xc0000f4f70, 0xc02930e9c0)
        ***** /protos/http/http.go:483 +0x111
***** /protos/http.(*httpPlugin).handleHTTP(0xc0000f4f70, 0xc02930e9c0, 0xc0073d 9180, 0x7f1aef56cf18?, 0xa0?)
        ***** /protos/http/http.go:442 +0x3fb
***** /protos/http.(*httpPlugin).messageComplete(...)
        ***** /protos/http/http.go:233

```

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [September 4, 2023, 12:09pm UTC](https://discuss.elastic.co/t/bug-panic-when-packetbeat-parsing-http-host-header-with-non-standard-format/342258/2 "2023-09-04T12:09:24Z")

</div>

Hi @moonD4rk,

Welcome to the community! Thanks for raising this issue. Would you be able to raise a [bug issue on the @elastic/beats Github repo](https://github.com/elastic/beats/issues/new?assignees=&labels=&projects=&template=bug-report.md) for someone to take a look?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2023, 2:10pm UTC](https://discuss.elastic.co/t/bug-panic-when-packetbeat-parsing-http-host-header-with-non-standard-format/342258/3 "2023-10-02T14:10:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
