"System.Web.HttpException (0x80004005): The URL-encoded form data is not valid." error after MS11-100

Date posted: 2012-01-03
Last updated: 2026-10-03

After installing security update MS11-100, ASP.NET forms with more than 1000 fields fail. Increase aspnet:MaxHttpCollectionKeys to fix it.

After applying MS11-100, an out-of-band security update for ASP.NET to mitigate an ASP.NET Denial of Service vulnerability, you may experience the error System.Web.HttpException (0x80004005): The URL-encoded form data is not valid. coming from .NET web applications. Here is why, and how to fix it.

Since MS11-100, ASP.NET rejects requests with more than 1000 form keys, files or JSON members, which shows up as an HTTP 500 error and event ID 1309. Raise the limit per application with the aspnet:MaxHttpCollectionKeys appSetting in web.config.

I originally wrote this post in January 2012, right after Microsoft released security bulletin MS11-100. The update itself is old news, but the 1000 keys limit it introduced is still part of ASP.NET on the .NET Framework, so you can still run into this error with large forms.

What causes the error?

A requirement is having a large form with many form fields: more than 1000. Microsoft's knowledge base article KB 2661403 summarizes it:

Microsoft security update MS11-100 limits the maximum number of form keys, files, and JSON members to 1000 in an HTTP request.

Because of this change, ASP.NET applications reject requests that contain more of these elements. HTTP clients sending such requests get an error message in the browser, usually with an HTTP 500 status code. On the server, the Application event log shows a Warning entry with a specific ASP.NET version as its Source, and Event ID 1309. The good news: the limit can be configured per application.

Increase MaxHttpCollectionKeys in web.config

To resolve this error you can increase MaxHttpCollectionKeys on a per application basis in your web.config file, as follows:

<appSettings>
  <add key="aspnet:MaxHttpCollectionKeys" value="some number here"/>
</appSettings>

Replace "some number here" with a value larger than the number of form fields your application needs. Don't raise it more than necessary: the limit exists to protect your server against a Denial of Service attack.

References:

More ASP.NET tuning: ASP.NET performance: what to keep in mind.

I write these posts in my spare time, based on real problems from my day job as a sysadmin. If this one saved you some debugging time, a small donation is much appreciated. Thanks! 🙏

Leave a Comment