{"record":{"id":"0b4243f0bbaa065a","repo":"laravel/framework","slug":"strings-with-invalid-utf-8-byte-sequences-cannot-b","errorCode":null,"errorMessage":"Strings with invalid UTF-8 byte sequences cannot be escaped.","messagePattern":"Strings with invalid UTF-8 byte sequences cannot be escaped\\.","errorType":"exception","errorClass":"RuntimeException","httpStatus":null,"severity":"error","filePath":"src/Illuminate/Database/Connection.php","lineNumber":1186,"sourceCode":"    public function escape($value, $binary = false)\n    {\n        if ($value === null) {\n            return 'null';\n        } elseif ($binary) {\n            return $this->escapeBinary($value);\n        } elseif (is_int($value) || is_float($value)) {\n            return (string) $value;\n        } elseif (is_bool($value)) {\n            return $this->escapeBool($value);\n        } elseif (is_array($value)) {\n            throw new RuntimeException('The database connection does not support escaping arrays.');\n        } else {\n            if (str_contains($value, \"\\00\")) {\n                throw new RuntimeException('Strings with null bytes cannot be escaped. Use the binary escape option.');\n            }\n\n            if (preg_match('//u', $value) === false) {\n                throw new RuntimeException('Strings with invalid UTF-8 byte sequences cannot be escaped.');\n            }\n\n            return $this->escapeString($value);\n        }\n    }\n\n    /**\n     * Escape a string value for safe SQL embedding.\n     *\n     * @param  string  $value\n     * @return string\n     */\n    protected function escapeString($value)\n    {\n        return $this->getReadPdo()->quote($value);\n    }\n\n    /**","sourceCodeStart":1168,"sourceCodeEnd":1204,"githubUrl":"https://github.com/laravel/framework/blob/e0f6eb3518ac29fbbca8529e97d0df7fc9f24481/src/Illuminate/Database/Connection.php#L1168-L1204","documentation":"Thrown by Connection::escape() when preg_match('//u', $value) === false, i.e. the string is not valid UTF-8. The framework escapes string literals assuming UTF-8 (the default client encoding for the supported drivers); non-UTF-8 bytes cannot be safely embedded and would corrupt the literal, so it rejects them.","triggerScenarios":"Calling $connection->escape($s) where $s is a non-UTF-8 string (latin1/Windows-1252/raw bytes); concatenating output from a non-UTF-8 source (legacy API, gzip decode of binary, iconv without //IGNORE); binary data misrouted to the string branch.","commonSituations":"Importing legacy data with latin1 encoding; consuming an external feed that lies about charset; binary payloads that should have used the $binary flag.","solutions":["If the bytes are genuinely binary, escape with $binary=true: $connection->escape($value, true).","Re-encode the string to UTF-8 before escaping: mb_convert_encoding($value, 'UTF-8', 'UTF-8') (or from the source encoding).","Validate/repair encoding up front (mb_check_encoding) and drop or replace invalid sequences.","Bind the value as a parameter so PDO handles encoding rather than escaping it inline."],"exampleFix":"// before\n$conn->escape($latin1String);\n\n// after\n$conn->escape(mb_convert_encoding($latin1String, 'UTF-8', 'Windows-1252'));","handlingStrategy":"validation","validationCode":"if (is_string($value) && mb_check_encoding($value, 'UTF-8') === false) {\n    $value = mb_convert_encoding($value, 'UTF-8', 'UTF-8'); // drop invalid seqs\n}\n$escaped = $connection->escape($value);","typeGuard":"function isValidUtf8(string $value): bool {\n    return mb_check_encoding($value, 'UTF-8');\n}","tryCatchPattern":"try {\n    $sql = $connection->escape($value);\n} catch (\\RuntimeException $e) {\n    if (str_contains($e->getMessage(), 'UTF-8')) {\n        $sql = $connection->escape($value, true); // treat as binary\n    } else { throw $e; }\n}","preventionTips":["Validate input encoding at trust boundaries with mb_check_encoding().","Re-encode legacy data to UTF-8 before passing it to escape().","For genuine binary payloads, use the $binary=true flag."],"tags":["database","escaping","encoding","utf-8","laravel"],"backgroundTag":null,"analyzedSha":"e0f6eb3518ac29fbbca8529e97d0df7fc9f24481","analyzedAt":"2026-08-11T20:52:37.562Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}