Common causes
- Too many or very large cookies stored for the domain
- Analytics, A/B testing or session plugins adding cookies on every visit
- Large authentication tokens (JWT, SSO) stored in cookies or headers
- Nginx large_client_header_buffers left at the default 4 8k
- Apache LimitRequestFieldSize at the default 8190 bytes
- Cookies shared across subdomains via a parent-domain cookie
How to fix it
- Clear cookies for the site. In the browser, open site settings for the domain and delete its cookies. If the page loads again, the cookie size was the problem. This is a quick fix for one user.
- Find the large cookies. Open developer tools > Application > Cookies and sort by size. Note which plugin or script sets the biggest or most numerous cookies.
- Raise Nginx header buffers. Add large_client_header_buffers 4 16k; in the http or server block, run sudo nginx -t, then reload. Raise it moderately; do not set huge values.
- Raise Apache header limits. Set LimitRequestFieldSize 16380 in the server config (not .htaccess) and restart Apache. Also check any proxy in front with its own limit.
- Shrink cookies at the source. Store session data on the server and keep only a session ID in the cookie. Remove unused tracking scripts and set cookies on the exact subdomain instead of the whole domain.
Increase Nginx request header buffers
http {
large_client_header_buffers 4 16k;
} How to stop it happening again
- Keep cookies small and server-side sessions where possible
- Audit third-party scripts that set cookies
- Scope cookies to the subdomain that needs them
- Set expiry dates on cookies so they do not pile up