{"record":{"id":"aa7dd04132555019","repo":"spring-projects/spring-security","slug":"the-request-was-rejected-because-the-url-contained-aa7dd0","errorCode":null,"errorMessage":"The request was rejected because the URL contained a potentially malicious String \"<forbidden>\"","messagePattern":"The request was rejected because the URL contained a potentially malicious String \"<forbidden>\"","errorType":"exception","errorClass":"ServerExchangeRejectedException","httpStatus":400,"severity":"error","filePath":"web/src/main/java/org/springframework/security/web/server/firewall/StrictServerWebExchangeFirewall.java","lineNumber":586,"sourceCode":"\t\t\t\t.format(\"The %s was rejected because it can only contain printable ASCII characters.\", propertyName));\n\t\t}\n\t}\n\n\tprivate void rejectForbiddenHttpMethod(ServerHttpRequest request) {\n\t\tif (this.allowedHttpMethods == ALLOW_ANY_HTTP_METHOD) {\n\t\t\treturn;\n\t\t}\n\t\tif (!this.allowedHttpMethods.contains(request.getMethod())) {\n\t\t\tthrow new ServerExchangeRejectedException(\n\t\t\t\t\t\"The request was rejected because the HTTP method \\\"\" + request.getMethod()\n\t\t\t\t\t\t\t+ \"\\\" was not included within the list of allowed HTTP methods \" + this.allowedHttpMethods);\n\t\t}\n\t}\n\n\tprivate void rejectedBlocklistedUrls(ServerHttpRequest request) {\n\t\tfor (String forbidden : this.encodedUrlBlocklist) {\n\t\t\tif (encodedUrlContains(request, forbidden)) {\n\t\t\t\tthrow new ServerExchangeRejectedException(\n\t\t\t\t\t\t\"The request was rejected because the URL contained a potentially malicious String \\\"\"\n\t\t\t\t\t\t\t\t+ forbidden + \"\\\"\");\n\t\t\t}\n\t\t}\n\t\tfor (String forbidden : this.decodedUrlBlocklist) {\n\t\t\tif (decodedUrlContains(request, forbidden)) {\n\t\t\t\tthrow new ServerExchangeRejectedException(\n\t\t\t\t\t\t\"The request was rejected because the URL contained a potentially malicious String \\\"\"\n\t\t\t\t\t\t\t\t+ forbidden + \"\\\"\");\n\t\t\t}\n\t\t}\n\t}\n\n\tprivate void rejectedUntrustedHosts(ServerHttpRequest request) {\n\t\tString hostName = request.getURI().getHost();\n\t\tif (hostName != null && !this.allowedHostnames.test(hostName)) {\n\t\t\tthrow new ServerExchangeRejectedException(\n\t\t\t\t\t\"The request was rejected because the domain \" + hostName + \" is untrusted.\");","sourceCodeStart":568,"sourceCodeEnd":604,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/web/src/main/java/org/springframework/security/web/server/firewall/StrictServerWebExchangeFirewall.java#L568-L604","documentation":"StrictServerWebExchangeFirewall maintains encoded and decoded URL blocklists containing path-traversal patterns (e.g. %2e%2e, .., //, %2f). rejectedBlocklistedUrls iterates these lists and throws ServerExchangeRejectedException as soon as the request's encoded or decoded URL contains any forbidden string. This blocks traversal and URL-obfuscation payloads before filters run.","triggerScenarios":"A request URL (raw/encoded or decoded) contains a blocklisted substring such as \"..\", \"%2e\", \"%2f\", \"//\", or \";\" — typically traversal or injection probes — detected while firewalling the exchange.","commonSituations":"Security scanners and bots probing for traversal vulnerabilities; legitimate URLs that incidentally contain blocked substrings (e.g. \"..\" inside a filename or search term); misconfigured proxies double-encoding path segments; custom blocklist entries added too broadly.","solutions":["Identify the blocked string from the exception message and fix the client/URL to avoid it (e.g. encode or rename the resource).","If a legitimate resource collides with a blocklist entry (e.g. filenames containing '..'), rename the resource or path instead of removing blocklist entries.","Check proxy configuration for double-encoding that produces encoded traversal sequences in the forwarded URL.","Only remove entries from the blocklist (removeFromUrlBlocklist) with a documented reason — they exist to block known attack payloads."],"exampleFix":"// before\n// GET /files/report..final.pdf  -> matches blocklist \"..\"\n// after\n// GET /files/report-final.pdf\n// or encode a search term:\nconst url = `/api/search?q=${encodeURIComponent(userInput)}`;","handlingStrategy":"validation","validationCode":"// Client-side guard before sending\nString[] blocked = {\"..\", \"%2e\", \"%2f\", \"//\", \";\"};\nfor (String b : blocked) {\n    if (url.toLowerCase().contains(b)) {\n        throw new IllegalArgumentException(\"URL contains blocked sequence: \" + b);\n    }\n}","typeGuard":null,"tryCatchPattern":"@ExceptionHandler(ServerExchangeRejectedException.class)\nMono<Void> handle(ServerWebExchange exchange, ServerExchangeRejectedException e) {\n    log.warn(\"Blocklisted URL rejected: {}\", e.getMessage());\n    exchange.getResponse().setStatusCode(HttpStatus.BAD_REQUEST);\n    return exchange.getResponse().setComplete();\n}","preventionTips":["Never place user input directly into path segments — encode it","Avoid filenames and IDs containing '..' or ';'","Ensure proxies do not double-encode forwarded URLs","Keep blocklist entries intact; fix URLs rather than weakening the blocklist"],"tags":["spring-security","webflux","firewall","path-traversal","blocklist"],"backgroundTag":"path-traversal-blocked","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}