{"record":{"id":"cd665111a857f624","repo":"spring-projects/spring-security","slug":"the-s-was-rejected-because-it-can-only-contain-pr-cd6651","errorCode":null,"errorMessage":"The %s was rejected because it can only contain printable ASCII characters.","messagePattern":"The (.+?) was rejected because it can only contain printable ASCII characters\\.","errorType":"exception","errorClass":"ServerExchangeRejectedException","httpStatus":400,"severity":"error","filePath":"web/src/main/java/org/springframework/security/web/server/firewall/StrictServerWebExchangeFirewall.java","lineNumber":567,"sourceCode":"\t */\n\tpublic void setAllowedHostnames(Predicate<String> allowedHostnames) {\n\t\tAssert.notNull(allowedHostnames, \"allowedHostnames cannot be null\");\n\t\tthis.allowedHostnames = allowedHostnames;\n\t}\n\n\tprivate void urlBlocklistsAddAll(Collection<String> values) {\n\t\tthis.encodedUrlBlocklist.addAll(values);\n\t\tthis.decodedUrlBlocklist.addAll(values);\n\t}\n\n\tprivate void urlBlocklistsRemoveAll(Collection<String> values) {\n\t\tthis.encodedUrlBlocklist.removeAll(values);\n\t\tthis.decodedUrlBlocklist.removeAll(values);\n\t}\n\n\tprivate void rejectNonPrintableAsciiCharactersInFieldName(String toCheck, String propertyName) {\n\t\tif (!containsOnlyPrintableAsciiCharacters(toCheck)) {\n\t\t\tthrow new ServerExchangeRejectedException(String\n\t\t\t\t.format(\"The %s was rejected because it can only contain printable ASCII characters.\", propertyName));\n\t\t}\n\t}\n\n\tprivate void rejectForbiddenHttpMethod(ServerHttpRequest request) {\n\t\tif (this.allowedHttpMethods == ALLOW_ANY_HTTP_METHOD) {\n\t\t\treturn;\n\t\t}\n\t\tif (!this.allowedHttpMethods.contains(request.getMethod())) {\n\t\t\tthrow new ServerExchangeRejectedException(\n\t\t\t\t\t\"The request was rejected because the HTTP method \\\"\" + request.getMethod()\n\t\t\t\t\t\t\t+ \"\\\" was not included within the list of allowed HTTP methods \" + this.allowedHttpMethods);\n\t\t}\n\t}\n\n\tprivate void rejectedBlocklistedUrls(ServerHttpRequest request) {\n\t\tfor (String forbidden : this.encodedUrlBlocklist) {\n\t\t\tif (encodedUrlContains(request, forbidden)) {","sourceCodeStart":549,"sourceCodeEnd":585,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/web/src/main/java/org/springframework/security/web/server/firewall/StrictServerWebExchangeFirewall.java#L549-L585","documentation":"StrictServerWebExchangeFirewall rejects requests whose field values (URL path or query string, via rejectNonPrintableAsciiCharactersInFieldName) contain characters outside the printable ASCII range. The check calls containsOnlyPrintableAsciiCharacters and throws ServerExchangeRejectedException naming the offending property. This prevents control characters and non-ASCII bytes from sneaking into request fields.","triggerScenarios":"A request URL or query parameter contains non-printable ASCII (control characters) or non-ASCII (e.g. UTF-8 multibyte) characters that were not percent-encoded, and the firewall validates the field during getFirewalledExchange.","commonSituations":"Users typing Unicode into URL parameters that a client fails to encode; scanners sending %00/\\x00 payloads; legacy clients putting raw bytes in the query string; logging tools revealing unexpected characters in access logs.","solutions":["Percent-encode non-ASCII characters client-side (URLEncoder / encodeURIComponent) before building the URL.","Identify the offending field from the exception message and sanitize the source of that input.","Validate/sanitize input at an upstream gateway to strip control characters before the request reaches Spring.","Avoid disabling the check (it is internal); if legitimate Unicode is needed, ensure it is properly encoded so the raw field stays printable ASCII."],"exampleFix":"// before\nconst url = `/api/search?q=${term}`; // term may contain raw Unicode/control chars\n// after\nconst url = `/api/search?q=${encodeURIComponent(term)}`;","handlingStrategy":"validation","validationCode":"// JavaScript client-side guard\nif (!/^[\\x20-\\x7E]*$/.test(param)) {\n    param = encodeURIComponent(param);\n}","typeGuard":null,"tryCatchPattern":"@ExceptionHandler(ServerExchangeRejectedException.class)\nMono<Void> handle(ServerWebExchange exchange, ServerExchangeRejectedException e) {\n    log.warn(\"Rejected non-ASCII field: {}\", e.getMessage());\n    exchange.getResponse().setStatusCode(HttpStatus.BAD_REQUEST);\n    return exchange.getResponse().setComplete();\n}","preventionTips":["Percent-encode all non-ASCII data in URLs","Strip control characters from user input before building URLs","Reject or sanitize input at the API gateway too","Avoid raw bytes in query strings from legacy clients"],"tags":["spring-security","webflux","firewall","ascii-validation","request-rejected"],"backgroundTag":"invalid-argument-value","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}