{"record":{"id":"c34393c76400e707","repo":"spring-projects/spring-security","slug":"the-request-was-rejected-because-the-header","errorCode":null,"errorMessage":"The request was rejected because the header: \\\"\" + name + \" \\\" has a value \\\"\" + value + \"\\\" that is not allowed.","messagePattern":"The request was rejected because the header: \\\\\"\" \\+ name \\+ \" \\\\\" has a value \\\\\"\" \\+ value \\+ \"\\\\\" that is not allowed\\.","errorType":"exception","errorClass":"RequestRejectedException","httpStatus":400,"severity":"error","filePath":"web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java","lineNumber":843,"sourceCode":"\t\t\tString[] values = super.getParameterValues(name);\n\t\t\tif (values != null) {\n\t\t\t\tfor (String value : values) {\n\t\t\t\t\tvalidateAllowedParameterValue(name, value);\n\t\t\t\t}\n\t\t\t}\n\t\t\treturn values;\n\t\t}\n\n\t\tprivate void validateAllowedHeaderName(String headerNames) {\n\t\t\tif (!StrictHttpFirewall.this.allowedHeaderNames.test(headerNames)) {\n\t\t\t\tthrow new RequestRejectedException(\n\t\t\t\t\t\t\"The request was rejected because the header name \\\"\" + headerNames + \"\\\" is not allowed.\");\n\t\t\t}\n\t\t}\n\n\t\tprivate void validateAllowedHeaderValue(String name, String value) {\n\t\t\tif (!StrictHttpFirewall.this.allowedHeaderValues.test(value)) {\n\t\t\t\tthrow new RequestRejectedException(\"The request was rejected because the header: \\\"\" + name\n\t\t\t\t\t\t+ \" \\\" has a value \\\"\" + value + \"\\\" that is not allowed.\");\n\t\t\t}\n\t\t}\n\n\t\tprivate void validateAllowedParameterName(String name) {\n\t\t\tif (!StrictHttpFirewall.this.allowedParameterNames.test(name)) {\n\t\t\t\tthrow new RequestRejectedException(\n\t\t\t\t\t\t\"The request was rejected because the parameter name \\\"\" + name + \"\\\" is not allowed.\");\n\t\t\t}\n\t\t}\n\n\t\tprivate void validateAllowedParameterValue(String name, String value) {\n\t\t\tif (!StrictHttpFirewall.this.allowedParameterValues.test(value)) {\n\t\t\t\tthrow new RequestRejectedException(\"The request was rejected because the parameter: \\\"\" + name\n\t\t\t\t\t\t+ \" \\\" has a value \\\"\" + value + \"\\\" that is not allowed.\");\n\t\t\t}\n\t\t}\n","sourceCodeStart":825,"sourceCodeEnd":861,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java#L825-L861","documentation":"StrictHttpFirewall validates every header value against an allowedHeaderValues predicate (by default, printable ASCII with no CR/LF). If a header value fails the test, the firewalled request throws RequestRejectedException before it reaches any filter. This protects against header-injection and response-splitting attacks.","triggerScenarios":"A client (or upstream proxy) sends a request whose header value contains characters outside the allowed set — typically CRLF, non-ASCII/UTF-8 characters, or control characters in headers like Referer, User-Agent, or custom headers.","commonSituations":"Users with non-Latin characters in a Referer or custom header; misbehaving proxies or API clients appending stray newlines; scanners sending malformed headers; custom clients building headers from untrusted input.","solutions":["Find which header/value is rejected from the exception message and fix the client to send only printable ASCII header values.","Relax validation by configuring StrictHttpFirewall via setAllowedHeaderValues(Predicate<String>) and registering it as a HttpFirewall bean in your SecurityFilterChain.","If the value is safe in your context, allow specific patterns (e.g. non-ASCII) with a predicate like Pattern.compile(\"[\\\\p{IsAssigned}&&[^\\\\p{Cntrl}\\\\s]]|^$\").asMatchPredicate().","Prefer fixing the sender over loosening the firewall — loosening reduces protection against header injection."],"exampleFix":"// before\nHttpFirewall defaultFirewall = new DefaultHttpFirewall();\n// after\nStrictHttpFirewall firewall = new StrictHttpFirewall();\nfirewall.setAllowedHeaderValues(header -> header.matches(\"[\\\\p{IsAssigned}&&[^\\\\p{Cntrl}\\\\s]]|^$\"));\nhttp.firewall(firewall);","handlingStrategy":"validation","validationCode":"// Java client-side guard before sending\nif (!value.chars().allMatch(c -> c >= 0x20 && c != 0x7F)) {\n    throw new IllegalArgumentException(\"Header value contains invalid characters: \" + name);\n}","typeGuard":null,"tryCatchPattern":"// Server-side handling\ntry {\n    return chain.filter(exchange);\n} catch (RequestRejectedException e) {\n    log.warn(\"Rejected request: {}\", e.getMessage());\n    response.setStatusCode(HttpStatus.BAD_REQUEST);\n    return response.setComplete();\n}","preventionTips":["Only send printable ASCII in HTTP header values","Strip CR/LF from user-derived header data","Monitor RequestRejectededException logs to spot misbehaving clients early","Never build headers from unvalidated user input"],"tags":["spring-security","http-firewall","request-rejected","header-injection"],"backgroundTag":"invalid-argument-value","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}