spring-projects/spring-security · error · RequestRejectedException
The request was rejected because the header: \"" + name + "…
Error message
The request was rejected because the header: \"" + name + " \" has a value \"" + value + "\" that is not allowed.
What it means
StrictHttpFirewall validates every header value against an allowedHeaderValues predicate (by default, printable ASCII with no CR/LF). If a header value fails the test, the firewalled request throws RequestRejectedException before it reaches any filter. This protects against header-injection and response-splitting attacks.
Solutions
- Find which header/value is rejected from the exception message and fix the client to send only printable ASCII header values.
- Relax validation by configuring StrictHttpFirewall via setAllowedHeaderValues(Predicate<String>) and registering it as a HttpFirewall bean in your SecurityFilterChain.
- If the value is safe in your context, allow specific patterns (e.g. non-ASCII) with a predicate like Pattern.compile("[\\p{IsAssigned}&&[^\\p{Cntrl}\\s]]|^$").asMatchPredicate().
- Prefer fixing the sender over loosening the firewall — loosening reduces protection against header injection.
Example fix
// before
HttpFirewall defaultFirewall = new DefaultHttpFirewall();
// after
StrictHttpFirewall firewall = new StrictHttpFirewall();
firewall.setAllowedHeaderValues(header -> header.matches("[\\p{IsAssigned}&&[^\\p{Cntrl}\\s]]|^$"));
http.firewall(firewall); Defensive patterns
Strategy: validation
Validate before calling
// Java client-side guard before sending
if (!value.chars().allMatch(c -> c >= 0x20 && c != 0x7F)) {
throw new IllegalArgumentException("Header value contains invalid characters: " + name);
} Try / catch
// Server-side handling
try {
return chain.filter(exchange);
} catch (RequestRejectedException e) {
log.warn("Rejected request: {}", e.getMessage());
response.setStatusCode(HttpStatus.BAD_REQUEST);
return response.setComplete();
} Prevention
- Only send printable ASCII in HTTP header values
- Strip CR/LF from user-derived header data
- Monitor RequestRejectededException logs to spot misbehaving clients early
- Never build headers from unvalidated user input
When it happens
Trigger: A client (or upstream proxy) sends a request whose header value contains characters outside the allowed set — typically CRLF, non-ASCII/UTF-8 characters, or control characters in headers like Referer, User-Agent, or custom headers.
Common situations: Users with non-Latin characters in a Referer or custom header; misbehaving proxies or API clients appending stray newlines; scanners sending malformed headers; custom clients building headers from untrusted input.
Understand the failure class
Background: "Must be a positive integer", "Invalid value", "Unsupported": the invalid-argument-value error family, when a library rejects the value you pass — this error's family across 35 libraries.
Related errors
- The request was rejected because the parameter: \"" + name…
- The request was rejected because the parameter name \"" +…
- The request was rejected because the HTTP method
- The requestURI cannot contain encoded slash. Got " +…
- The was rejected because it can only contain printable…
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/c34393c76400e707.
Report an issue: GitHub.
Appendix: source
Thrown at web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java:843
String[] values = super.getParameterValues(name);
if (values != null) {
for (String value : values) {
validateAllowedParameterValue(name, value);
}
}
return values;
}
private void validateAllowedHeaderName(String headerNames) {
if (!StrictHttpFirewall.this.allowedHeaderNames.test(headerNames)) {
throw new RequestRejectedException(
"The request was rejected because the header name \"" + headerNames + "\" is not allowed.");
}
}
private void validateAllowedHeaderValue(String name, String value) {
if (!StrictHttpFirewall.this.allowedHeaderValues.test(value)) {
throw new RequestRejectedException("The request was rejected because the header: \"" + name
+ " \" has a value \"" + value + "\" that is not allowed.");
}
}
private void validateAllowedParameterName(String name) {
if (!StrictHttpFirewall.this.allowedParameterNames.test(name)) {
throw new RequestRejectedException(
"The request was rejected because the parameter name \"" + name + "\" is not allowed.");
}
}
private void validateAllowedParameterValue(String name, String value) {
if (!StrictHttpFirewall.this.allowedParameterValues.test(value)) {
throw new RequestRejectedException("The request was rejected because the parameter: \"" + name
+ " \" has a value \"" + value + "\" that is not allowed.");
}
}
View on GitHub (pinned to 96852e8860)