spring-projects/spring-security · error · RequestRejectedException

The request was rejected because the HTTP method \"" +…

Error message

The request was rejected because the HTTP method \"" + request.getMethod() + "\" was not included within the list of allowed HTTP methods " + this.allowedHttpMethods

What it means

Error "The request was rejected because the HTTP method \"" + request.getMethod() + "\" was not included within the list of allowed HTTP methods " + this.allowedHttpMethods" thrown in spring-projects/spring-security.

Solutions

  1. Add the HTTP method to StrictHttpFirewall's allowedHttpMethods (e.g. setAllowedHttpMethods or addAllowedHttpMethod) if it is legitimately used by your clients
  2. If the client should never send that method, block it upstream (e.g. at the proxy) or fix the client
  3. Call setUnsafeAllowAnyHttpMethod only for trusted internal networks, understanding it disables this protection
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java:539 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/fc88af1183765703. Report an issue: GitHub.

Appendix: source

Thrown at web/src/main/java/org/springframework/security/web/firewall/StrictHttpFirewall.java:539

			throw new RequestRejectedException("The request was rejected because the URL was not normalized.");
		}
		rejectNonPrintableAsciiCharactersInFieldName(request.getRequestURI(), "requestURI");
		return new StrictFirewalledRequest(request);
	}

	private void rejectNonPrintableAsciiCharactersInFieldName(String toCheck, String propertyName) {
		if (!containsOnlyPrintableAsciiCharacters(toCheck)) {
			throw new RequestRejectedException(String
				.format("The %s was rejected because it can only contain printable ASCII characters.", propertyName));
		}
	}

	private void rejectForbiddenHttpMethod(HttpServletRequest request) {
		if (this.allowedHttpMethods == ALLOW_ANY_HTTP_METHOD) {
			return;
		}
		if (!this.allowedHttpMethods.contains(request.getMethod())) {
			throw new RequestRejectedException(
					"The request was rejected because the HTTP method \"" + request.getMethod()
							+ "\" was not included within the list of allowed HTTP methods " + this.allowedHttpMethods);
		}
	}

	private void rejectedBlocklistedUrls(HttpServletRequest request) {
		for (String forbidden : this.encodedUrlBlocklist) {
			if (encodedUrlContains(request, forbidden)) {
				throw new RequestRejectedException(
						"The request was rejected because the URL contained a potentially malicious String \""
								+ forbidden + "\"");
			}
		}
		for (String forbidden : this.decodedUrlBlocklist) {
			if (decodedUrlContains(request, forbidden)) {
				throw new RequestRejectedException(
						"The request was rejected because the URL contained a potentially malicious String \""
								+ forbidden + "\"");

View on GitHub (pinned to 96852e8860)