{"record":{"id":"4ec4bc46b03cdcec","repo":"spring-projects/spring-security","slug":"the-request-was-rejected-because-the-parameter","errorCode":null,"errorMessage":"The request was rejected because the parameter: \\\"\" + name + \" \\\" has a value \\\"\" + value + \"\\\" that is not allowed.","messagePattern":"The request was rejected because the parameter: \\\\\"\" \\+ name \\+ \" \\\\\" has a value \\\\\"\" \\+ value \\+ \"\\\\\" that is not allowed\\.","errorType":"exception","errorClass":"RequestRejectedException","httpStatus":400,"severity":"error","filePath":"web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java","lineNumber":857,"sourceCode":"\t\t}\n\n\t\tprivate void validateAllowedHeaderValue(String name, String value) {\n\t\t\tif (!StrictHttpFirewall.this.allowedHeaderValues.test(value)) {\n\t\t\t\tthrow new RequestRejectedException(\"The request was rejected because the header: \\\"\" + name\n\t\t\t\t\t\t+ \" \\\" has a value \\\"\" + value + \"\\\" that is not allowed.\");\n\t\t\t}\n\t\t}\n\n\t\tprivate void validateAllowedParameterName(String name) {\n\t\t\tif (!StrictHttpFirewall.this.allowedParameterNames.test(name)) {\n\t\t\t\tthrow new RequestRejectedException(\n\t\t\t\t\t\t\"The request was rejected because the parameter name \\\"\" + name + \"\\\" is not allowed.\");\n\t\t\t}\n\t\t}\n\n\t\tprivate void validateAllowedParameterValue(String name, String value) {\n\t\t\tif (!StrictHttpFirewall.this.allowedParameterValues.test(value)) {\n\t\t\t\tthrow new RequestRejectedException(\"The request was rejected because the parameter: \\\"\" + name\n\t\t\t\t\t\t+ \" \\\" has a value \\\"\" + value + \"\\\" that is not allowed.\");\n\t\t\t}\n\t\t}\n\n\t\t@Override\n\t\tpublic void reset() {\n\t\t}\n\n\t};\n\n}\n","sourceCodeStart":839,"sourceCodeEnd":869,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java#L839-L869","documentation":"StrictHttpFirewall validates every request parameter value against allowedParameterValues. When a value fails the predicate, the request is rejected with RequestRejectedException before entering the filter chain. By default this blocks only non-printable ASCII, guarding against parameter-based injection payloads.","triggerScenarios":"A query or form parameter value contains characters rejected by the allowedParameterValues predicate — typically control characters or other content excluded by a custom predicate.","commonSituations":"Users pasting odd characters into forms; clients URL-encoding control bytes; teams adding a custom value predicate that is stricter than expected; payloads with binary data sent as parameter values.","solutions":["Inspect the offending parameter name/value in the exception and fix the client or form to send clean values.","Adjust the predicate via StrictHttpFirewall.setAllowedParameterValues(Predicate<String>) to allow legitimate characters your app needs.","Validate/sanitize user input at the source so control characters never reach the request.","Avoid blanket-disabling the check; scope any relaxation narrowly to the specific parameters that need it."],"exampleFix":"// before\nfirewall.setAllowedParameterValues(value -> value.matches(\"[\\\\a-zA-Z0-9]*\"));\n// after\nfirewall.setAllowedParameterValues(value -> value.chars().allMatch(c -> c >= 0x20 && c < 0x7F));","handlingStrategy":"validation","validationCode":"// Java client-side guard\nif (!value.chars().allMatch(c -> c >= 0x20 && c < 0x7F)) {\n    value = URLEncoder.encode(value, StandardCharsets.UTF_8);\n}","typeGuard":null,"tryCatchPattern":"try {\n    return chain.filter(exchange);\n} catch (RequestRejectedException e) {\n    log.warn(\"Rejected parameter value: {}\", e.getMessage());\n    response.setStatusCode(HttpStatus.BAD_REQUEST);\n    return response.setComplete();\n}","preventionTips":["URL-encode all user-provided parameter values","Sanitize form input for control characters","Test forms with unicode/control-character inputs","Keep custom allowedParameterValues predicates documented and reviewed"],"tags":["spring-security","http-firewall","request-rejected","parameter-value"],"backgroundTag":"invalid-argument-value","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}