spring-projects/spring-security · error · RequestRejectedException

The request was rejected because the header: \"" + name + "…

Error message

The request was rejected because the header: \"" + name + " \" has a value \"" + value + "\" that is not allowed.

What it means

StrictHttpFirewall validates every header value against an allowedHeaderValues predicate (by default, printable ASCII with no CR/LF). If a header value fails the test, the firewalled request throws RequestRejectedException before it reaches any filter. This protects against header-injection and response-splitting attacks.

Solutions

  1. Find which header/value is rejected from the exception message and fix the client to send only printable ASCII header values.
  2. Relax validation by configuring StrictHttpFirewall via setAllowedHeaderValues(Predicate<String>) and registering it as a HttpFirewall bean in your SecurityFilterChain.
  3. If the value is safe in your context, allow specific patterns (e.g. non-ASCII) with a predicate like Pattern.compile("[\\p{IsAssigned}&&[^\\p{Cntrl}\\s]]|^$").asMatchPredicate().
  4. Prefer fixing the sender over loosening the firewall — loosening reduces protection against header injection.

Example fix

// before
HttpFirewall defaultFirewall = new DefaultHttpFirewall();
// after
StrictHttpFirewall firewall = new StrictHttpFirewall();
firewall.setAllowedHeaderValues(header -> header.matches("[\\p{IsAssigned}&&[^\\p{Cntrl}\\s]]|^$"));
http.firewall(firewall);
Defensive patterns

Strategy: validation

Validate before calling

// Java client-side guard before sending
if (!value.chars().allMatch(c -> c >= 0x20 && c != 0x7F)) {
    throw new IllegalArgumentException("Header value contains invalid characters: " + name);
}

Try / catch

// Server-side handling
try {
    return chain.filter(exchange);
} catch (RequestRejectedException e) {
    log.warn("Rejected request: {}", e.getMessage());
    response.setStatusCode(HttpStatus.BAD_REQUEST);
    return response.setComplete();
}

Prevention

When it happens

Trigger: A client (or upstream proxy) sends a request whose header value contains characters outside the allowed set — typically CRLF, non-ASCII/UTF-8 characters, or control characters in headers like Referer, User-Agent, or custom headers.

Common situations: Users with non-Latin characters in a Referer or custom header; misbehaving proxies or API clients appending stray newlines; scanners sending malformed headers; custom clients building headers from untrusted input.

Understand the failure class

Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/c34393c76400e707. Report an issue: GitHub.

Appendix: source

Thrown at web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java:843

			String[] values = super.getParameterValues(name);
			if (values != null) {
				for (String value : values) {
					validateAllowedParameterValue(name, value);
				}
			}
			return values;
		}

		private void validateAllowedHeaderName(String headerNames) {
			if (!StrictHttpFirewall.this.allowedHeaderNames.test(headerNames)) {
				throw new RequestRejectedException(
						"The request was rejected because the header name \"" + headerNames + "\" is not allowed.");
			}
		}

		private void validateAllowedHeaderValue(String name, String value) {
			if (!StrictHttpFirewall.this.allowedHeaderValues.test(value)) {
				throw new RequestRejectedException("The request was rejected because the header: \"" + name
						+ " \" has a value \"" + value + "\" that is not allowed.");
			}
		}

		private void validateAllowedParameterName(String name) {
			if (!StrictHttpFirewall.this.allowedParameterNames.test(name)) {
				throw new RequestRejectedException(
						"The request was rejected because the parameter name \"" + name + "\" is not allowed.");
			}
		}

		private void validateAllowedParameterValue(String name, String value) {
			if (!StrictHttpFirewall.this.allowedParameterValues.test(value)) {
				throw new RequestRejectedException("The request was rejected because the parameter: \"" + name
						+ " \" has a value \"" + value + "\" that is not allowed.");
			}
		}

View on GitHub (pinned to 96852e8860)