{"record":{"id":"bfb05b779c1626fb","repo":"mongodb/node-mongodb-native","slug":"namespace-cannot-contain-a-null-character","errorCode":null,"errorMessage":"Namespace cannot contain a null character","messagePattern":"Namespace cannot contain a null character","errorType":"exception","errorClass":"MongoRuntimeError","httpStatus":null,"severity":"error","filePath":"src/cmap/commands.ts","lineNumber":103,"sourceCode":"  /** moreToCome is an OP_MSG only concept */\n  moreToCome = false;\n  databaseName: string;\n  query: Document;\n\n  constructor(databaseName: string, query: Document, options: OpQueryOptions) {\n    // Basic options needed to be passed in\n    // TODO(NODE-3483): Replace with MongoCommandError\n    const ns = `${databaseName}.$cmd`;\n    if (typeof databaseName !== 'string') {\n      throw new MongoRuntimeError('Database name must be a string for a query');\n    }\n    // TODO(NODE-3483): Replace with MongoCommandError\n    if (query == null) throw new MongoRuntimeError('A query document must be specified for query');\n\n    // Validate that we are not passing 0x00 in the collection name\n    if (ns.indexOf('\\x00') !== -1) {\n      // TODO(NODE-3483): Use MongoNamespace static method\n      throw new MongoRuntimeError('Namespace cannot contain a null character');\n    }\n\n    // Basic optionsa\n    this.databaseName = databaseName;\n    this.query = query;\n    this.ns = ns;\n\n    // Additional options\n    this.numberToSkip = options.numberToSkip || 0;\n    this.numberToReturn = options.numberToReturn || 0;\n    this.returnFieldSelector = options.returnFieldSelector || undefined;\n    this.requestId = options.requestId ?? OpQueryRequest.getRequestId();\n\n    // special case for pre-3.2 find commands, delete ASAP\n    this.pre32Limit = options.pre32Limit;\n\n    // Serialization option\n    this.serializeFunctions =","sourceCodeStart":85,"sourceCodeEnd":121,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/commands.ts#L85-L121","documentation":"Thrown as a MongoRuntimeError in the OpQueryRequest constructor when the constructed namespace (databaseName + '.$cmd') contains a NUL byte (\\x00). In the MongoDB wire protocol the collection name is a C-string terminated by NUL, so an embedded NUL would silently truncate the namespace and route the command to the wrong collection. This guard rejects such input early.","triggerScenarios":"The database name passed to OpQueryRequest contains a literal \\x00 character. Because the driver normally derives databaseName from the user's db/collection strings, this means a NUL byte appeared in a database or collection name in the user's code.","commonSituations":"Reading a database/collection name from untrusted input that includes a NUL byte; binary data accidentally concatenated into a namespace; a logging or injection test that injects control characters.","solutions":["Sanitize database and collection names to reject control characters (especially \\x00) before use","Trace where the NUL byte entered the namespace string (e.g. a buffer read without trimming)","Validate user-supplied collection/db names against /^[A-Za-z0-9_.-]+$/"],"exampleFix":"// before\nconst db = client.db(nameFromFile); // nameFromFile may contain a NUL byte\n\n// after\nif (/\\x00/.test(nameFromFile)) throw new Error('Invalid db name');\nconst db = client.db(nameFromFile);","handlingStrategy":"validation","validationCode":"function assertSafeNamespace(name: string) {\n  if (name.indexOf('\\x00') !== -1) throw new Error(`Namespace contains NUL: ${JSON.stringify(name)}`);\n}\nassertSafeNamespace(dbName);\nassertSafeNamespace(collectionName);","typeGuard":"function isNulFreeNamespace(name: string): boolean {\n  return !name.includes('\\x00');\n}","tryCatchPattern":null,"preventionTips":["Validate database/collection names against /^[A-Za-z0-9_.-]+$/ before use","Sanitize untrusted input that flows into namespace strings","Reject any control character (\\\\x00-\\\\x1f) in db/collection names"],"tags":["wire-protocol","namespace","validation","security"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}