go-sql-driver/mysql · error

invalid DSN: interpolateParams can not be used with unsafe…

Error message

invalid DSN: interpolateParams can not be used with unsafe collations

What it means

Error "invalid DSN: interpolateParams can not be used with unsafe collations" thrown in go-sql-driver/mysql.

Solutions

  1. Remove interpolateParams=true from the DSN when using a collation whose charset is not safely escapable (e.g. certain multi-byte collations like big5, cp932, gb2312, gbk, sjis).
  2. Switch the connection collation to a safe one such as utf8mb4_general_ci, or keep interpolateParams=false so the server-side prepared statement protocol is used.

Example fix

dsn := "user:pass@tcp(127.0.0.1:3306)/mydb?collation=utf8mb4_general_ci&interpolateParams=true"

When it happens

Trigger: DSN parsing validates the collation when interpolateParams=true and rejects collations that are unsafe for client-side parameter interpolation.

Common situations: Happens when combining interpolateParams=true with a multibyte collation prone to encoding-based SQL injection (e.g. big5, gbk, sjis, cp932). Either disable interpolateParams or switch to a safe collation such as utf8mb4.


AI-assisted analysis of go-sql-driver/mysql@03d76c7e07 (2026-08-07). Data as JSON: /api/errors/e4bf52c1a1a60255. Report an issue: GitHub.

Appendix: source

Thrown at dsn.go:32

	"crypto/rsa"
	"crypto/tls"
	"errors"
	"fmt"
	"maps"
	"math/big"
	"net"
	"net/url"
	"sort"
	"strconv"
	"strings"
	"time"
)

var (
	errInvalidDSNUnescaped       = errors.New("invalid DSN: did you forget to escape a param value?")
	errInvalidDSNAddr            = errors.New("invalid DSN: network address not terminated (missing closing brace)")
	errInvalidDSNNoSlash         = errors.New("invalid DSN: missing the slash separating the database name")
	errInvalidDSNUnsafeCollation = errors.New("invalid DSN: interpolateParams can not be used with unsafe collations")
)

// Config is a configuration parsed from a DSN string.
// If a new Config is created instead of being parsed from a DSN string,
// the NewConfig function should be used, which sets default values.
type Config struct {
	// non boolean fields

	User                 string            // Username
	Passwd               string            // Password (requires User)
	Net                  string            // Network (e.g. "tcp", "tcp6", "unix". default: "tcp")
	Addr                 string            // Address (default: "127.0.0.1:3306" for "tcp" and "/tmp/mysql.sock" for "unix")
	DBName               string            // Database name
	Params               map[string]string // Connection parameters
	ConnectionAttributes string            // Connection Attributes, comma-delimited string of user-defined "key:value" pairs
	Collation            string            // Connection collation. When set, this will be set in SET NAMES <charset> COLLATE <collation> query
	Loc                  *time.Location    // Location for time.Time values
	MaxAllowedPacket     int               // Max packet size allowed

View on GitHub (pinned to 03d76c7e07)