{"record":{"id":"941357ec9225796e","repo":"spring-projects/spring-security","slug":"the-request-was-rejected-because-the-parameter-nam-941357","errorCode":null,"errorMessage":"The request was rejected because the parameter name \"<name>\" is not allowed.","messagePattern":"The request was rejected because the parameter name \"<name>\" is not allowed\\.","errorType":"exception","errorClass":"ServerExchangeRejectedException","httpStatus":400,"severity":"error","filePath":"web/src/main/java/org/springframework/security/web/server/firewall/StrictServerWebExchangeFirewall.java","lineNumber":649,"sourceCode":"\t}\n\n\tprivate void validateAllowedHeaderName(String headerNames) {\n\t\tif (!StrictServerWebExchangeFirewall.this.allowedHeaderNames.test(headerNames)) {\n\t\t\tthrow new ServerExchangeRejectedException(\n\t\t\t\t\t\"The request was rejected because the header name \\\"\" + headerNames + \"\\\" is not allowed.\");\n\t\t}\n\t}\n\n\tprivate void validateAllowedHeaderValue(Object key, @Nullable String value) {\n\t\tif (!StrictServerWebExchangeFirewall.this.allowedHeaderValues.test(value)) {\n\t\t\tthrow new ServerExchangeRejectedException(\"The request was rejected because the header: \\\"\" + key\n\t\t\t\t\t+ \" \\\" has a value \\\"\" + value + \"\\\" that is not allowed.\");\n\t\t}\n\t}\n\n\tprivate void validateAllowedParameterName(String name) {\n\t\tif (!StrictServerWebExchangeFirewall.this.allowedParameterNames.test(name)) {\n\t\t\tthrow new ServerExchangeRejectedException(\n\t\t\t\t\t\"The request was rejected because the parameter name \\\"\" + name + \"\\\" is not allowed.\");\n\t\t}\n\t}\n\n\tprivate void validateAllowedParameterValue(String name, String value) {\n\t\tif (!StrictServerWebExchangeFirewall.this.allowedParameterValues.test(value)) {\n\t\t\tthrow new ServerExchangeRejectedException(\"The request was rejected because the parameter: \\\"\" + name\n\t\t\t\t\t+ \" \\\" has a value \\\"\" + value + \"\\\" that is not allowed.\");\n\t\t}\n\t}\n\n\tprivate static boolean encodedUrlContains(ServerHttpRequest request, String value) {\n\t\tif (valueContains(request.getPath().value(), value)) {\n\t\t\treturn true;\n\t\t}\n\t\treturn valueContains(request.getURI().getRawPath(), value);\n\t}\n","sourceCodeStart":631,"sourceCodeEnd":667,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/web/src/main/java/org/springframework/security/web/server/firewall/StrictServerWebExchangeFirewall.java#L631-L667","documentation":"The firewall validates every request parameter name against the allowedParameterNames predicate. A parameter whose name fails is rejected with ServerExchangeRejectedException. This blocks parameter-pollution and malicious parameter-name injection (e.g. names with control characters).","triggerScenarios":"A request (query string or form body) contains a parameter name that fails allowedParameterNames — e.g. names with special/control characters, or a custom predicate that doesn't include the parameter the client sends.","commonSituations":"APIs adding new query parameters after a restrictive setAllowedParameterNames predicate was configured; clients sending parameters with URL-encoded or malformed names; form fields auto-generated from user input; Spring Security upgrades changing default parameter validation.","solutions":["Rename the parameter on the client to a valid name (alphanumerics, '-', '_', '.').","If the parameter is legitimate, update the firewall: firewall.setAllowedParameterNames(name -> name.matches(\"[a-zA-Z0-9_.-]+\")).","Check logs to identify the exact rejected name and which client/endpoint sends it.","Sanitize dynamically generated form/query parameter names at the source."],"exampleFix":"// before: dynamic param name from user input\nString url = \"/api?\" + userInput + \"=1\";\n// after\nString safeName = userInput.replaceAll(\"[^a-zA-Z0-9_.-]\", \"\");\nString url = \"/api?\" + safeName + \"=1\";","handlingStrategy":"validation","validationCode":"boolean isSafeParameterName(String name) {\n    return name != null && name.matches(\"[a-zA-Z0-9_.-]+\") && !name.isEmpty();\n}","typeGuard":null,"tryCatchPattern":"try {\n    exchange = firewall.getFirewalledExchange(exchange);\n} catch (ServerExchangeRejectedException e) {\n    log.warn(\"Rejected parameter name: {}\", e.getMessage());\n    return ResponseEntity.badRequest().build();\n}","preventionTips":["Use fixed, code-reviewed parameter names in clients and forms.","Sanitize any dynamically generated parameter names.","When restricting parameter names with setAllowedParameterNames, include all params your API actually uses.","Add integration tests that hit every endpoint's parameters through the firewall."],"tags":["security","spring-security","request-parameters","firewall"],"backgroundTag":"invalid-argument-format","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}