{"record":{"id":"10e747ff22a420c6","repo":"spring-projects/spring-security","slug":"could-not-parse-accept-header-value-ex-get","errorCode":null,"errorMessage":"Could not parse 'Accept' header [<value>]: <ex.getMessage()>","messagePattern":"Could not parse 'Accept' header \\[<value>\\]: <ex\\.getMessage\\(\\)>","errorType":"http","errorClass":"NotAcceptableStatusException","httpStatus":406,"severity":"warning","filePath":"web/src/main/java/org/springframework/security/web/server/util/matcher/MediaTypeServerWebExchangeMatcher.java","lineNumber":147,"sourceCode":"\t * Set the {@link MediaType} to ignore from the {@link ContentNegotiationStrategy}.\n\t * This is useful if for example, you want to match on\n\t * {@link MediaType#APPLICATION_JSON} but want to ignore {@link MediaType#ALL}.\n\t * @param ignoredMediaTypes the {@link MediaType}'s to ignore from the\n\t * {@link ContentNegotiationStrategy}\n\t */\n\tpublic void setIgnoredMediaTypes(Set<MediaType> ignoredMediaTypes) {\n\t\tthis.ignoredMediaTypes = ignoredMediaTypes;\n\t}\n\n\tprivate List<MediaType> resolveMediaTypes(ServerWebExchange exchange) throws NotAcceptableStatusException {\n\t\ttry {\n\t\t\tList<MediaType> mediaTypes = exchange.getRequest().getHeaders().getAccept();\n\t\t\tMimeTypeUtils.sortBySpecificity(mediaTypes);\n\t\t\treturn mediaTypes;\n\t\t}\n\t\tcatch (InvalidMediaTypeException ex) {\n\t\t\tString value = exchange.getRequest().getHeaders().getFirst(\"Accept\");\n\t\t\tthrow new NotAcceptableStatusException(\n\t\t\t\t\t\"Could not parse 'Accept' header [\" + value + \"]: \" + ex.getMessage());\n\t\t}\n\t}\n\n\t@Override\n\tpublic String toString() {\n\t\treturn \"MediaTypeRequestMatcher [matchingMediaTypes=\" + this.matchingMediaTypes + \", useEquals=\"\n\t\t\t\t+ this.useEquals + \", ignoredMediaTypes=\" + this.ignoredMediaTypes + \"]\";\n\t}\n\n}\n","sourceCodeStart":129,"sourceCodeEnd":159,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/web/src/main/java/org/springframework/security/web/server/util/matcher/MediaTypeServerWebExchangeMatcher.java#L129-L159","documentation":"MediaTypeServerWebExchangeMatcher resolves the request's Accept header to a list of MediaTypes to decide if the exchange matches. If the header contains a syntactically invalid media type, parsing throws InvalidMediaTypeException, which is converted to a 406 NotAcceptableStatusException with the offending header value and parse reason.","triggerScenarios":"An incoming HTTP request whose Accept header cannot be parsed (malformed type/subtype, illegal characters, bad parameters) when the matcher's matches() is invoked during authorization or content negotiation.","commonSituations":"Browsers/proxies sending unusual or corrupted Accept headers; API clients hand-crafting Accept values like 'application/json;' with dangling parameters; automated tools sending Accept: */*;q= with malformed quality syntax.","solutions":["Fix the client to send a well-formed Accept header (e.g. 'application/json')","Catch NotAcceptableStatusException on the server side and return a clean 406 response without internals","Normalize/sanitize the Accept header in an upstream filter or gateway before the matcher runs","If you control the matcher usage, wrap matching and fall back to a default media type"],"exampleFix":"// before\ncurl -H 'Accept: application/json;' http://api/...\n// after\ncurl -H 'Accept: application/json' http://api/...","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n    boolean matches = matcher.matches(exchange).block();\n} catch (NotAcceptableStatusException ex) {\n    // malformed Accept header: treat as not-matching or respond 406\n    return matcherDoesNotMatch();\n}","preventionTips":["Send explicit, simple Accept headers from clients (e.g. application/json)","Avoid hand-building media-type strings with manual parameters/quality values","Sanitize Accept headers at gateway/proxy layer for untrusted traffic"],"tags":["spring-security","http-headers","content-negotiation"],"backgroundTag":"invalid-argument-format","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}