Connection errors
ERR_HTTP2_PROTOCOL_ERROR
The browser and server had a problem speaking HTTP/2.
Quick answer
HTTP/2 is a modern way browsers and servers exchange data. This error means the server sent something that broke the HTTP/2 rules, or something on the way, like security software, changed the traffic.
When to wait: If caused by a server change, waiting helps only once the owner fixes it.
If you are visiting the website
- Reload once A single broken reply can cause this error. Reload the page once before trying anything else.
- Try a private window Open the site in a private (incognito) window. If it works there, an extension or saved site data may be the cause.
- Update and restart your browser Older browser versions can handle HTTP/2 differently. Install the latest version and restart the browser.
- Windows
- Chrome: More (three dots) > Help > About Google Chrome, then click Relaunch. Edge: Settings and more > Help and feedback > About Microsoft Edge.
- macOS
- Chrome: More (three dots) > Help > About Google Chrome, then click Relaunch. Edge: Settings and more > Help and feedback > About Microsoft Edge.
- Linux
- Update Chrome through your system's package manager or software center, then restart it.
- Android
- Open the Google Play Store, search for Chrome and tap Update if it is offered.
- iPhone and iPad (iOS)
- Open the App Store, tap your profile picture and update Chrome if it is listed.
- Start fresh connections HTTP/2 keeps one connection open for many requests. Throwing it away makes the browser build a clean new one.
- Windows
- Chrome: chrome://net-internals/#sockets > Flush socket pools. Edge: edge://net-internals/#sockets.
- macOS
- Chrome: chrome://net-internals/#sockets > Flush socket pools. Edge: edge://net-internals/#sockets.
- ChromeOS
- Open chrome://net-internals/#sockets and click Flush socket pools.
- Pause HTTPS scanning briefly Antivirus or firewall tools that read encrypted traffic (often called HTTPS scanning or web shield) sit between you and the server and can break HTTP/2. Pause only that feature for one test, then switch it back on. If it was the cause, update the security software or add an exception for the site.
- Test without VPN or proxy VPNs and company proxies can also inspect or rewrite traffic. Disconnect the VPN for one test, or ask your IT team whether a proxy is in use.
- Try another network Switch from Wi-Fi to mobile data, or the other way round. If the site works there, something on your network is involved.
If you run the website
- Check server and proxy error logs Look at your web server, reverse proxy and application logs for the time of the error. Stream resets, upstream errors and oversized requests usually show up there.
- Compare HTTP/1.1 and HTTP/2 Run curl --http1.1 -v https://example.com/path and curl --http2 -v https://example.com/path. If only the HTTP/2 request fails, the fault is in the HTTP/2 layer (server, proxy or CDN), not in your app logic.
- Remove forbidden connection headers HTTP/2 does not allow HTTP/1.1 connection headers such as Connection, Keep-Alive, Transfer-Encoding and Upgrade, and header names must be lowercase. An app or proxy that forwards them unchanged can break the stream.
- Check header, cookie and body sizes Very large headers or cookies can exceed limits in your server, proxy or CDN. Also make sure a Content-Length header matches the body actually sent, because a mismatch makes the reply invalid.
- Test the CDN-to-origin hop With Cloudflare, a broken HTTP/2 setup on your server can be ruled out by turning off HTTP/2 to Origin in the Speed settings for a short test. Turn it back on once you have fixed the origin.
- Review recent server changes Upgrades of the web server, compression modules or proxy software often precede this error. Roll back with your tested procedure if the timing matches.
Is it the website or me?
If the error appears on one website only and on every network, the website or its CDN is the likely source. If it appears on many websites, look at your device first: security software, a proxy or an outdated browser.
For developers: what happens technically
HTTP/2 (defined in RFC 9113) sends requests and replies as binary frames over one connection. When a peer breaks the framing rules, sends forbidden headers or a body that does not match its length, the stream or the whole connection is reset.
Chromium then reports net error -337, shown as ERR_HTTP2_PROTOCOL_ERROR.
How it differs from ERR_QUIC_PROTOCOL_ERROR
HTTP/2 runs over ordinary TCP connections, while HTTP/3 runs over QUIC. Both errors mean the protocol conversation broke.
HTTP/2 problems usually sit in the server, proxy or security software. QUIC problems are often caused by networks that block or disturb its traffic.
Common questions
Is this a security warning?
No. It is a transport error: the page did not arrive in a valid form. It is not the same as a certificate warning.
Why does only one page, video or download fail?
HTTP/2 can reset a single request while the rest of the page loads. One large or broken reply can fail while other content works.
Should I turn off my antivirus?
Only pause its HTTPS scanning for a single test, then turn it back on. If that fixes it, update the software or add an exception instead of leaving protection off.
I own the site. Where do I start?
Compare an HTTP/1.1 and an HTTP/2 request with curl, then read the logs of every proxy in the chain. Recent server or CDN changes are the next suspect.
Likely causes
- Common A server, proxy or CDN misconfiguration. (Website side)
- Sometimes Security software or a proxy that inspects your traffic. (Your side)
What to avoid
- Do not turn off your antivirus permanently.
- Do not change hidden browser settings or flags you do not understand; test with another network or a paused VPN instead.
Is the website down? Check it now
One measurement point. Results explain what we saw, not a worldwide verdict.
Related messages
Sources
- Chromium source: net/base/net_error_list.h
- RFC 9113: HTTP/2
- Google Chrome Help: Get help with common error messages in Chrome
- Cloudflare Docs: Error 520 (HTTP/2 to origin)
- curl man page
Last reviewed: