{"record":{"id":"afa4e2ca35e615c7","repo":"laravel/framework","slug":"strings-with-null-bytes-cannot-be-escaped-use-the","errorCode":null,"errorMessage":"Strings with null bytes cannot be escaped. Use the binary escape option.","messagePattern":"Strings with null bytes cannot be escaped\\. Use the binary escape option\\.","errorType":"exception","errorClass":"RuntimeException","httpStatus":null,"severity":"error","filePath":"src/Illuminate/Database/Connection.php","lineNumber":1182,"sourceCode":"     * @return string\n     *\n     * @throws \\RuntimeException\n     */\n    public function escape($value, $binary = false)\n    {\n        if ($value === null) {\n            return 'null';\n        } elseif ($binary) {\n            return $this->escapeBinary($value);\n        } elseif (is_int($value) || is_float($value)) {\n            return (string) $value;\n        } elseif (is_bool($value)) {\n            return $this->escapeBool($value);\n        } elseif (is_array($value)) {\n            throw new RuntimeException('The database connection does not support escaping arrays.');\n        } else {\n            if (str_contains($value, \"\\00\")) {\n                throw new RuntimeException('Strings with null bytes cannot be escaped. Use the binary escape option.');\n            }\n\n            if (preg_match('//u', $value) === false) {\n                throw new RuntimeException('Strings with invalid UTF-8 byte sequences cannot be escaped.');\n            }\n\n            return $this->escapeString($value);\n        }\n    }\n\n    /**\n     * Escape a string value for safe SQL embedding.\n     *\n     * @param  string  $value\n     * @return string\n     */\n    protected function escapeString($value)\n    {","sourceCodeStart":1164,"sourceCodeEnd":1200,"githubUrl":"https://github.com/laravel/framework/blob/e0f6eb3518ac29fbbca8529e97d0df7fc9f24481/src/Illuminate/Database/Connection.php#L1164-L1200","documentation":"Thrown by Connection::escape() in the string branch when str_contains($value, \"\\00\") is true. A NUL byte inside a string literal would break SQL parsing and is a classic injection/encoding hazard, so the framework refuses to escape it as a string. Binary data must go through the dedicated escapeBinary() path by passing the $binary flag.","triggerScenarios":"Calling $connection->escape($s) where $s contains a NUL byte (\\0 / chr(0)); reading a blob/binary file into a string and passing it to escape without $binary=true; binding raw bytes into a raw query fragment.","commonSituations":"Storing image/PDF/encrypted bytes in a column; reading from fread()/file_get_contents() of a binary file; serialized/compressed payloads that include NUL bytes.","solutions":["Pass the binary flag: $connection->escape($value, true) so escapeBinary() is used.","Use a parameterized binding (->where('col', '=', $value)) instead of escaping a literal, so PDO handles binary safely.","Sanitize/strip NUL bytes if the value should actually be text: str_replace(\"\\0\", '', $value).","Store binary data in a proper BLOB column and bind it as a stream/LOB."],"exampleFix":"// before\n$conn->escape(file_get_contents('/tmp/asset.bin'));\n\n// after\n$conn->escape(file_get_contents('/tmp/asset.bin'), true);","handlingStrategy":"validation","validationCode":"if (is_string($value) && str_contains($value, \"\\0\")) {\n    $escaped = $connection->escape($value, true); // binary path\n} else {\n    $escaped = $connection->escape($value);\n}","typeGuard":"function isBinaryString(string $value): bool {\n    return str_contains($value, \"\\0\") || mb_check_encoding($value, 'UTF-8') === false;\n}","tryCatchPattern":"try {\n    $sql = $connection->escape($value);\n} catch (\\RuntimeException $e) {\n    if (str_contains($e->getMessage(), 'null bytes')) {\n        $sql = $connection->escape($value, true);\n    } else { throw $e; }\n}","preventionTips":["When handling file/blob output, always pass $binary=true to escape().","Prefer parameter binding over literal escaping for binary data.","Sanitize text inputs to remove NUL bytes when they are unexpected."],"tags":["database","escaping","binary","sql-injection","laravel"],"backgroundTag":null,"analyzedSha":"e0f6eb3518ac29fbbca8529e97d0df7fc9f24481","analyzedAt":"2026-08-11T20:52:37.562Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}