Common causes
- Nginx client_max_body_size is left at its 1m default or set too low
- Apache LimitRequestBody is set lower than the upload (Apache 2.4.54+ defaults to 1 GB)
- PHP upload_max_filesize or post_max_size is smaller than the file
- The limit is set in one Nginx server block but the request is handled by another
- A reverse proxy, load balancer, CDN or Kubernetes ingress in front of the server has its own body limit
- A WAF or ModSecurity rule (SecRequestBodyLimit) rejects large bodies
How to fix it
- Identify which layer returns 413. Look at the error page footer (nginx, Apache, Cloudflare) and the error log. Nginx logs "client intended to send too large body" with the exact byte count.
- Raise the Nginx limit. Add client_max_body_size 64M; to the http, server or location block that handles the upload, then run sudo nginx -t && sudo systemctl reload nginx.
- Raise the Apache limit. If LimitRequestBody is set in the vhost or .htaccess, raise it (the value is in bytes, for example LimitRequestBody 67108864 for 64 MB), then reload Apache.
- Match the PHP limits. Set upload_max_filesize = 64M and post_max_size = 64M (post_max_size should be equal or larger) in php.ini or .user.ini, then restart PHP-FPM. Check the values with php -i | grep -E 'upload_max|post_max'.
- Check proxies and ingress. For the Kubernetes NGINX ingress use the annotation nginx.ingress.kubernetes.io/proxy-body-size. Cloudflare limits upload size per plan (100 MB on Free and Pro), so very large files need direct upload or chunking.
- Use chunked uploads for big files. For files of hundreds of megabytes, upload in chunks or directly to object storage with presigned URLs instead of raising every limit.
Nginx + php.ini
# /etc/nginx/nginx.conf (http block) or the site server block
client_max_body_size 64M;
# php.ini or .user.ini
upload_max_filesize = 64M
post_max_size = 64M How to stop it happening again
- Set upload limits in Nginx, PHP and any proxy to the same documented value
- Validate file size in the browser before uploading to give a clear message
- Use chunked or direct-to-storage uploads for large media
- Keep limits as low as your use case allows to reduce abuse