{"record":{"id":"8ce7bd4b42da2193","repo":"go-sql-driver/mysql","slug":"no-pem-data-found-data-s","errorCode":null,"errorMessage":"no pem data found, data: %s","messagePattern":"no pem data found, data: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"auth.go","lineNumber":432,"sourceCode":"\t\t\t\t\t\t}\n\t\t\t\t\t\tdata[4] = cachingSha2PasswordRequestPublicKey\n\t\t\t\t\t\terr = mc.writePacket(data)\n\t\t\t\t\t\tif err != nil {\n\t\t\t\t\t\t\treturn err\n\t\t\t\t\t\t}\n\n\t\t\t\t\t\tif data, err = mc.readPacket(); err != nil {\n\t\t\t\t\t\t\treturn err\n\t\t\t\t\t\t}\n\n\t\t\t\t\t\tif data[0] != iAuthMoreData {\n\t\t\t\t\t\t\treturn fmt.Errorf(\"unexpected resp from server for caching_sha2_password, perform full authentication\")\n\t\t\t\t\t\t}\n\n\t\t\t\t\t\t// parse public key\n\t\t\t\t\t\tblock, rest := pem.Decode(data[1:])\n\t\t\t\t\t\tif block == nil {\n\t\t\t\t\t\t\treturn fmt.Errorf(\"no pem data found, data: %s\", rest)\n\t\t\t\t\t\t}\n\t\t\t\t\t\tpkix, err := x509.ParsePKIXPublicKey(block.Bytes)\n\t\t\t\t\t\tif err != nil {\n\t\t\t\t\t\t\treturn err\n\t\t\t\t\t\t}\n\t\t\t\t\t\tpubKey = pkix.(*rsa.PublicKey)\n\t\t\t\t\t}\n\n\t\t\t\t\t// send encrypted password\n\t\t\t\t\terr = mc.sendEncryptedPassword(oldAuthData, pubKey)\n\t\t\t\t\tif err != nil {\n\t\t\t\t\t\treturn err\n\t\t\t\t\t}\n\t\t\t\t}\n\t\t\t\treturn mc.resultUnchanged().readResultOK()\n\n\t\t\tdefault:\n\t\t\t\treturn ErrMalformPkt","sourceCodeStart":414,"sourceCodeEnd":450,"githubUrl":"https://github.com/go-sql-driver/mysql/blob/03d76c7e07908e255ce62d126d07ede3f2365d86/auth.go#L414-L450","documentation":"Returned at auth.go:432 during caching_sha2_password full auth: after the client requests the server public key, pem.Decode of the response (data[1:]) returns a nil block, meaning the bytes were not valid PEM-encoded key material.","triggerScenarios":"caching_sha2_password over plaintext TCP where the server's public-key response is malformed or not PEM — a non-conformant server/proxy, truncated packet, or handshake tampering. Sibling of error 37 for the caching_sha2 path.","commonSituations":"Proxies/load balancers that strip or alter the public-key payload; buggy MySQL fork; packet truncation from MTU/MSS issues; connecting to something pretending to be MySQL.","solutions":["Use TLS or unix socket so the cleartext path is taken and no key exchange occurs.","Pin the server's public key via serverPubKey so the driver never parses a server-supplied key.","Bypass or reconfigure any middleware that rewrites the auth payload.","Verify the endpoint is a real MySQL 8+ server emitting a conformant RSA public key."],"exampleFix":"// before: server key not parseable as PEM\ndsn := \"user:pass@tcp(mysql8:3306)/db\"\n// -> \"no pem data found, data: ...\"\n\n// after: avoid dynamic key fetch entirely\ndsn := \"user:pass@tcp(mysql8:3306)/db?tls=true\"","handlingStrategy":"fallback","validationCode":"// Pin the public key so the client never has to parse a server-supplied one.\nmysql.RegisterServerPubKey(\"mysql8\", serverKeyPEM)\ndsn := \"user:pass@tcp(host:3306)/db?tls=true\" // or ?serverPubKey=mysql8","typeGuard":"func isNoPemData(err error) bool {\n    return err != nil && strings.Contains(err.Error(), \"no pem data found\")\n}","tryCatchPattern":"if isNoPemData(err) {\n    // take the TLS/cleartext path or pin the key; avoid parsing server key.\n}","preventionTips":["Prefer TLS for caching_sha2_password over plaintext TCP.","Pin serverPubKey to eliminate reliance on dynamic PEM parsing.","Ensure no intermediary rewrites the public-key frame."],"tags":["authentication","caching-sha2","pem","handshake"],"backgroundTag":null,"analyzedSha":"03d76c7e07908e255ce62d126d07ede3f2365d86","analyzedAt":"2026-08-07T10:39:17.340Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}