{"record":{"id":"cfd0a9e8426e2006","repo":"laravel/framework","slug":"the-database-connection-does-not-support-escaping","errorCode":null,"errorMessage":"The database connection does not support escaping arrays.","messagePattern":"The database connection does not support escaping arrays\\.","errorType":"exception","errorClass":"RuntimeException","httpStatus":null,"severity":"error","filePath":"src/Illuminate/Database/Connection.php","lineNumber":1179,"sourceCode":"     *\n     * @param  string|float|int|bool|null  $value\n     * @param  bool  $binary\n     * @return string\n     *\n     * @throws \\RuntimeException\n     */\n    public function escape($value, $binary = false)\n    {\n        if ($value === null) {\n            return 'null';\n        } elseif ($binary) {\n            return $this->escapeBinary($value);\n        } elseif (is_int($value) || is_float($value)) {\n            return (string) $value;\n        } elseif (is_bool($value)) {\n            return $this->escapeBool($value);\n        } elseif (is_array($value)) {\n            throw new RuntimeException('The database connection does not support escaping arrays.');\n        } else {\n            if (str_contains($value, \"\\00\")) {\n                throw new RuntimeException('Strings with null bytes cannot be escaped. Use the binary escape option.');\n            }\n\n            if (preg_match('//u', $value) === false) {\n                throw new RuntimeException('Strings with invalid UTF-8 byte sequences cannot be escaped.');\n            }\n\n            return $this->escapeString($value);\n        }\n    }\n\n    /**\n     * Escape a string value for safe SQL embedding.\n     *\n     * @param  string  $value\n     * @return string","sourceCodeStart":1161,"sourceCodeEnd":1197,"githubUrl":"https://github.com/laravel/framework/blob/e0f6eb3518ac29fbbca8529e97d0df7fc9f24481/src/Illuminate/Database/Connection.php#L1161-L1197","documentation":"Thrown by Connection::escape() when the value passed is a PHP array. The base escape() dispatches by type (null, int/float, bool, string, binary) and explicitly rejects arrays, because array-to-SQL literal conversion is driver-specific. Only drivers that override the array branch (e.g. Postgres with array columns) support it.","triggerScenarios":"Calling $connection->escape($arrayValue) or $connection->quote($arrayValue) where $arrayValue is a non-empty array; using a raw where clause that forces an array through escape; binding an array into a statement that the grammar tries to escape literally.","commonSituations":"Trying to inline a list into a raw SQL fragment; misusing escape() instead of whereIn(); Postgres array column code run against MySQL/SQLite where array escaping is not supported.","solutions":["Use a query builder list method (whereIn/whereJsonContains) instead of escaping the array into SQL.","Flatten the array yourself: implode(',', array_map(fn ($v) => $conn->escape($v), $arr)).","If you need literal array syntax, use a driver/connection that overrides escape() for arrays (Postgres).","Cast the array to a scalar (json_encode) before escaping and store it in a JSON/text column."],"exampleFix":"// before\n$sql = \"WHERE id IN ({$conn->escape([1, 2, 3])})\";\n\n// after\n$conn->table('users')->whereIn('id', [1, 2, 3])->get();","handlingStrategy":"validation","validationCode":"if (is_array($value)) {\n    $literal = implode(',', array_map(fn ($v) => $connection->escape($v), $value));\n} else {\n    $literal = $connection->escape($value);\n}","typeGuard":"function isEscapableScalar(mixed $value): bool {\n    return $value === null\n        || is_int($value) || is_float($value)\n        || is_bool($value) || is_string($value);\n}","tryCatchPattern":"try {\n    $sql = $connection->escape($value);\n} catch (\\RuntimeException $e) {\n    if (is_array($value)) {\n        $sql = implode(',', array_map(fn ($v) => $connection->escape($v), $value));\n    } else { throw $e; }\n}","preventionTips":["Never escape an array into SQL; use whereIn()/whereJsonContains() for lists.","Validate that values bound into raw SQL fragments are scalars before escaping.","For Postgres array columns, ensure you are on a PostgresConnection that overrides array escaping."],"tags":["database","escaping","sql-injection","laravel"],"backgroundTag":null,"analyzedSha":"e0f6eb3518ac29fbbca8529e97d0df7fc9f24481","analyzedAt":"2026-08-11T20:52:37.562Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}