{"record":{"id":"fc88af1183765703","repo":"spring-projects/spring-security","slug":"the-request-was-rejected-because-the-http-method","errorCode":null,"errorMessage":"The request was rejected because the HTTP method \\\"\" + request.getMethod() + \"\\\" was not included within the list of allowed HTTP methods \" + this.allowedHttpMethods","messagePattern":"The request was rejected because the HTTP method \\\\\"\" \\+ request\\.getMethod\\(\\) \\+ \"\\\\\" was not included within the list of allowed HTTP methods \" \\+ this\\.allowedHttpMethods","errorType":"exception","errorClass":"RequestRejectedException","httpStatus":400,"severity":"error","filePath":"web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java","lineNumber":539,"sourceCode":"\t\t\tthrow new RequestRejectedException(\"The request was rejected because the URL was not normalized.\");\n\t\t}\n\t\trejectNonPrintableAsciiCharactersInFieldName(request.getRequestURI(), \"requestURI\");\n\t\treturn new StrictFirewalledRequest(request);\n\t}\n\n\tprivate void rejectNonPrintableAsciiCharactersInFieldName(String toCheck, String propertyName) {\n\t\tif (!containsOnlyPrintableAsciiCharacters(toCheck)) {\n\t\t\tthrow new RequestRejectedException(String\n\t\t\t\t.format(\"The %s was rejected because it can only contain printable ASCII characters.\", propertyName));\n\t\t}\n\t}\n\n\tprivate void rejectForbiddenHttpMethod(HttpServletRequest request) {\n\t\tif (this.allowedHttpMethods == ALLOW_ANY_HTTP_METHOD) {\n\t\t\treturn;\n\t\t}\n\t\tif (!this.allowedHttpMethods.contains(request.getMethod())) {\n\t\t\tthrow new RequestRejectedException(\n\t\t\t\t\t\"The request was rejected because the HTTP method \\\"\" + request.getMethod()\n\t\t\t\t\t\t\t+ \"\\\" was not included within the list of allowed HTTP methods \" + this.allowedHttpMethods);\n\t\t}\n\t}\n\n\tprivate void rejectedBlocklistedUrls(HttpServletRequest request) {\n\t\tfor (String forbidden : this.encodedUrlBlocklist) {\n\t\t\tif (encodedUrlContains(request, forbidden)) {\n\t\t\t\tthrow new RequestRejectedException(\n\t\t\t\t\t\t\"The request was rejected because the URL contained a potentially malicious String \\\"\"\n\t\t\t\t\t\t\t\t+ forbidden + \"\\\"\");\n\t\t\t}\n\t\t}\n\t\tfor (String forbidden : this.decodedUrlBlocklist) {\n\t\t\tif (decodedUrlContains(request, forbidden)) {\n\t\t\t\tthrow new RequestRejectedException(\n\t\t\t\t\t\t\"The request was rejected because the URL contained a potentially malicious String \\\"\"\n\t\t\t\t\t\t\t\t+ forbidden + \"\\\"\");","sourceCodeStart":521,"sourceCodeEnd":557,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java#L521-L557","documentation":"Error \"The request was rejected because the HTTP method \\\"\" + request.getMethod() + \"\\\" was not included within the list of allowed HTTP methods \" + this.allowedHttpMethods\" thrown in spring-projects/spring-security.","triggerScenarios":"Thrown at web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java:539 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Add the HTTP method to StrictHttpFirewall's allowedHttpMethods (e.g. setAllowedHttpMethods or addAllowedHttpMethod) if it is legitimately used by your clients","If the client should never send that method, block it upstream (e.g. at the proxy) or fix the client","Call setUnsafeAllowAnyHttpMethod only for trusted internal networks, understanding it disables this protection"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}