{"record":{"id":"3930f263f933aa66","repo":"mongodb/node-mongodb-native","slug":"unidentifiable-error-in-mongocrypt-received-an-e","errorCode":null,"errorMessage":"unidentifiable error in MongoCrypt - received an error status from `libmongocrypt` but received no error message.","messagePattern":"unidentifiable error in MongoCrypt - received an error status from `libmongocrypt` but received no error message\\.","errorType":"exception","errorClass":"MongoCryptError","httpStatus":null,"severity":"critical","filePath":"src/client-side-encryption/state_machine.ts","lineNumber":291,"sourceCode":"            throw new MongoCryptError(message);\n          }\n          result = finalizedContext;\n          break;\n        }\n\n        default:\n          throw new MongoCryptError(`Unknown state: ${getState()}`);\n      }\n    }\n\n    if (getState() === MONGOCRYPT_CTX_ERROR || result == null) {\n      const message = getStatus().message;\n      if (!message) {\n        debug(\n          `unidentifiable error in MongoCrypt - received an error status from \\`libmongocrypt\\` but received no error message.`\n        );\n      }\n      throw new MongoCryptError(\n        message ??\n          'unidentifiable error in MongoCrypt - received an error status from `libmongocrypt` but received no error message.'\n      );\n    }\n\n    return result;\n  }\n\n  /**\n   * Handles the request to the KMS service. Exposed for testing purposes. Do not directly invoke.\n   * @param kmsContext - A C++ KMS context returned from the bindings\n   * @returns A promise that resolves when the KMS reply has be fully parsed\n   */\n  async kmsRequest(\n    request: MongoCryptKMSRequest,\n    options?: { timeoutContext?: TimeoutContext } & Abortable\n  ): Promise<void> {\n    const parsedUrl = request.endpoint.split(':');","sourceCodeStart":273,"sourceCodeEnd":309,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/client-side-encryption/state_machine.ts#L273-L309","documentation":"The CSFLE state machine exited with MONGOCRYPT_CTX_ERROR but context.status.message was empty — libmongocrypt reported an error status without a human-readable message. The driver substitutes this descriptive string so the rejection is not a bare empty message. It almost always points to a lower-level libmongocrypt/KMS problem the driver cannot introspect.","triggerScenarios":"libmongocrypt hits an internal error (e.g. malformed BSON passed to a context, unsupported algorithm, KMS TLS failure) and sets ERROR without populating the message; corrupted/empty payload fed to decrypt; missing or malformed data key material.","commonSituations":"Feeding a non-Binary / wrong-subtype value to decrypt; passing malformed BSON to an expression encryption; KMS TLS handshake failure before libmongocrypt can describe it; version skew between libmongocrypt and the driver's expected message contract.","solutions":["Enable CSFLE debug logging (setAutoEncryptionExtraOptions / logger) to capture libmongocrypt's raw diagnostics, which often contain the real cause.","Verify the value being encrypted/decrypted is a valid BSON-serializable / Binary(6) value respectively.","Check that the data key document in the key vault is well-formed (not truncated, correct _id, correct keyMaterial).","Align libmongocrypt/crypt_shared and driver versions if the input is known-good."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  await clientEncryption.encrypt(value, opts);\n} catch (e) {\n  if (e instanceof MongoCryptError && /unidentifiable error/.test(e.message)) {\n    // enable CSFLE debug logging and retry to capture libmongocrypt diagnostics\n  }\n  throw e;\n}","preventionTips":["Enable CSFLE logging (AutoEncryption logger) in non-prod to capture libmongocrypt messages.","Validate input is a BSON-serializable value (encrypt) or a Binary subtype 6 (decrypt) before calling."],"tags":["csfle","client-side-encryption","internal","libmongocrypt","debugging"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}