{"record":{"id":"638506a00a276194","repo":"spring-projects/spring-security","slug":"the-requesturi-cannot-contain-encoded-slash-got","errorCode":null,"errorMessage":"The requestURI cannot contain encoded slash. Got \" + requestURI","messagePattern":"The requestURI cannot contain encoded slash\\. Got \" \\+ requestURI","errorType":"exception","errorClass":"RequestRejectedException","httpStatus":400,"severity":"error","filePath":"web/src/main/java/org/springframework/security/web/firewall/DefaultHttpFirewall.java","lineNumber":61,"sourceCode":" *\n * @author Luke Taylor\n * @see StrictHttpFirewall\n */\npublic class DefaultHttpFirewall implements HttpFirewall {\n\n\tprivate boolean allowUrlEncodedSlash;\n\n\t@Override\n\tpublic FirewalledRequest getFirewalledRequest(HttpServletRequest request) throws RequestRejectedException {\n\t\tFirewalledRequest firewalledRequest = new RequestWrapper(request);\n\t\tif (!isNormalized(firewalledRequest.getServletPath()) || !isNormalized(firewalledRequest.getPathInfo())) {\n\t\t\tthrow new RequestRejectedException(\n\t\t\t\t\t\"Un-normalized paths are not supported: \" + firewalledRequest.getServletPath()\n\t\t\t\t\t\t\t+ ((firewalledRequest.getPathInfo() != null) ? firewalledRequest.getPathInfo() : \"\"));\n\t\t}\n\t\tString requestURI = firewalledRequest.getRequestURI();\n\t\tif (containsInvalidUrlEncodedSlash(requestURI)) {\n\t\t\tthrow new RequestRejectedException(\"The requestURI cannot contain encoded slash. Got \" + requestURI);\n\t\t}\n\t\treturn firewalledRequest;\n\t}\n\n\t@Override\n\tpublic HttpServletResponse getFirewalledResponse(HttpServletResponse response) {\n\t\treturn new FirewalledResponse(response);\n\t}\n\n\t/**\n\t * <p>\n\t * Sets if the application should allow a URL encoded slash character.\n\t * </p>\n\t * <p>\n\t * If true (default is false), a URL encoded slash will be allowed in the URL.\n\t * Allowing encoded slashes can cause security vulnerabilities in some situations\n\t * depending on how the container constructs the HttpServletRequest.\n\t * </p>","sourceCodeStart":43,"sourceCodeEnd":79,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/web/src/main/java/org/springframework/security/web/firewall/DefaultHttpFirewall.java#L43-L79","documentation":"DefaultHttpFirewall rejects a request whose requestURI contains an URL-encoded slash (%2F or lowercase variants) that would decode into a path separator. Because decoding happens later in the container, an encoded slash could smuggle extra path segments past URL-pattern based authorization. It throws RequestRejectedException with the offending URI.","triggerScenarios":"A client sends a requestURI containing %2F or %2f (e.g. /api/resource%2Fsub) and the URI contains no valid, permitted encoded slash — DefaultHttpFirewall strictly rejects encoded slashes unless allowUrlEncodedSlash is set (and even then only for non-blocking cases per release).","commonSituations":"REST APIs where resource identifiers contain slashes and clients pre-encode them; gateway already decoded once then re-encoded (%252F double encoding); frontend routing frameworks generating encoded path segments; upgrading Spring Security changed firewall behavior for paths that previously worked.","solutions":["Have clients use double-encoded slashes (%252F) or restructure identifiers to avoid slashes (use IDs instead of names containing '/')","If encoded slashes are legitimate for your app, call firewall.setAllowUrlEncodedSlash(true) on the DefaultHttpFirewall bean (and matching Tomcat system property org.apache.tomcat.util.buf.UDecoder.ALLOW_ENCODED_SLASH=true / relaxedPathChars as needed)","Decode/normalize at the reverse proxy before forwarding, or map such requests to a different route pattern","Verify which firewall bean FilterChainProxy uses; prefer StrictHttpFirewall and configure setAllowUrlEncodedSlash there with full awareness of the bypass risk"],"exampleFix":"// before\n@Bean\nDefaultHttpFirewall firewall() { return new DefaultHttpFirewall(); }\n// after\n@Bean\nDefaultHttpFirewall firewall() {\n    DefaultHttpFirewall fw = new DefaultHttpFirewall();\n    fw.setAllowUrlEncodedSlash(true); // only if encoded slashes are required and safe here\n    return fw;\n}","handlingStrategy":"try-catch","validationCode":"String uri = request.getRequestURI();\nboolean hasEncodedSlash = uri.toLowerCase().contains(\"%2f\");\nif (hasEncodedSlash && !allowEncodedSlash) {\n    // reject or re-encode client-side before calling the firewall\n}","typeGuard":null,"tryCatchPattern":"try {\n    FirewalledRequest fw = firewall.getFirewalledRequest(request);\n    chain.doFilter(fw, response);\n} catch (RequestRejectedException e) {\n    if (e.getMessage().contains(\"encoded slash\")) {\n        response.sendError(HttpServletResponse.SC_BAD_REQUEST, \"Encoded slashes are not allowed\");\n    } else throw e;\n}","preventionTips":["Design resource IDs without slashes, or document that clients must double-encode (%252F)","Only enable setAllowUrlEncodedSlash(true) after reviewing the path-matching bypass risk","Check Tomcat's ALLOW_ENCODED_SLASH system property agrees with the firewall setting","Monitor logs for RequestRejectedException spikes indicating clients or gateways mis-encoding paths"],"tags":["spring-security","firewall","url-encoding","request-rejected","security"],"backgroundTag":"path-traversal-blocked","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}