{"record":{"id":"e4bf52c1a1a60255","repo":"go-sql-driver/mysql","slug":"invalid-dsn-interpolateparams-can-not-be-used-wit","errorCode":null,"errorMessage":"invalid DSN: interpolateParams can not be used with unsafe collations","messagePattern":"invalid DSN: interpolateParams can not be used with unsafe collations","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"dsn.go","lineNumber":32,"sourceCode":"\t\"crypto/rsa\"\n\t\"crypto/tls\"\n\t\"errors\"\n\t\"fmt\"\n\t\"maps\"\n\t\"math/big\"\n\t\"net\"\n\t\"net/url\"\n\t\"sort\"\n\t\"strconv\"\n\t\"strings\"\n\t\"time\"\n)\n\nvar (\n\terrInvalidDSNUnescaped       = errors.New(\"invalid DSN: did you forget to escape a param value?\")\n\terrInvalidDSNAddr            = errors.New(\"invalid DSN: network address not terminated (missing closing brace)\")\n\terrInvalidDSNNoSlash         = errors.New(\"invalid DSN: missing the slash separating the database name\")\n\terrInvalidDSNUnsafeCollation = errors.New(\"invalid DSN: interpolateParams can not be used with unsafe collations\")\n)\n\n// Config is a configuration parsed from a DSN string.\n// If a new Config is created instead of being parsed from a DSN string,\n// the NewConfig function should be used, which sets default values.\ntype Config struct {\n\t// non boolean fields\n\n\tUser                 string            // Username\n\tPasswd               string            // Password (requires User)\n\tNet                  string            // Network (e.g. \"tcp\", \"tcp6\", \"unix\". default: \"tcp\")\n\tAddr                 string            // Address (default: \"127.0.0.1:3306\" for \"tcp\" and \"/tmp/mysql.sock\" for \"unix\")\n\tDBName               string            // Database name\n\tParams               map[string]string // Connection parameters\n\tConnectionAttributes string            // Connection Attributes, comma-delimited string of user-defined \"key:value\" pairs\n\tCollation            string            // Connection collation. When set, this will be set in SET NAMES <charset> COLLATE <collation> query\n\tLoc                  *time.Location    // Location for time.Time values\n\tMaxAllowedPacket     int               // Max packet size allowed","sourceCodeStart":14,"sourceCodeEnd":50,"githubUrl":"https://github.com/go-sql-driver/mysql/blob/03d76c7e07908e255ce62d126d07ede3f2365d86/dsn.go#L14-L50","documentation":"Error \"invalid DSN: interpolateParams can not be used with unsafe collations\" thrown in go-sql-driver/mysql.","triggerScenarios":"DSN parsing validates the collation when interpolateParams=true and rejects collations that are unsafe for client-side parameter interpolation.","commonSituations":"Happens when combining interpolateParams=true with a multibyte collation prone to encoding-based SQL injection (e.g. big5, gbk, sjis, cp932). Either disable interpolateParams or switch to a safe collation such as utf8mb4.","solutions":["Remove interpolateParams=true from the DSN when using a collation whose charset is not safely escapable (e.g. certain multi-byte collations like big5, cp932, gb2312, gbk, sjis).","Switch the connection collation to a safe one such as utf8mb4_general_ci, or keep interpolateParams=false so the server-side prepared statement protocol is used."],"exampleFix":"dsn := \"user:pass@tcp(127.0.0.1:3306)/mydb?collation=utf8mb4_general_ci&interpolateParams=true\"","handlingStrategy":null,"validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"03d76c7e07908e255ce62d126d07ede3f2365d86","analyzedAt":"2026-08-07T10:39:17.340Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}