jackc/pgx · error

insufficient arguments

Error message

insufficient arguments

What it means

The SQL references a positional parameter (e.g. $3) but fewer arguments than that were passed to Sanitize. The highest referenced index exceeds the supplied argument count.

Solutions

  1. Pass an argument for every placeholder referenced in the SQL
  2. Lower the placeholder number to match the arguments supplied
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at internal/sanitize/sanitize.go:62 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/9dad5dcd0933a117. Report an issue: GitHub.

Appendix: source

Thrown at internal/sanitize/sanitize.go:62

func (q *Query) Sanitize(args ...any) (string, error) {
	argUse := make([]bool, len(args))
	buf := bufPool.get()
	defer bufPool.put(buf)

	for _, part := range q.Parts {
		switch part := part.(type) {
		case string:
			buf.WriteString(part)
		case int:
			argIdx := part - 1
			var p []byte
			if argIdx < 0 {
				return "", fmt.Errorf("first sql argument must be > 0")
			}

			if argIdx >= len(args) {
				return "", fmt.Errorf("insufficient arguments")
			}

			// Prevent SQL injection via Line Comment Creation
			// https://github.com/jackc/pgx/security/advisories/GHSA-m7wr-2xf7-cm9p
			buf.WriteByte(' ')

			arg := args[argIdx]
			switch arg := arg.(type) {
			case nil:
				p = null
			case int64:
				p = strconv.AppendInt(buf.AvailableBuffer(), arg, 10)
			case float64:
				p = strconv.AppendFloat(buf.AvailableBuffer(), arg, 'f', -1, 64)
			case bool:
				p = strconv.AppendBool(buf.AvailableBuffer(), arg)
			case []byte:
				p = QuoteBytes(buf.AvailableBuffer(), arg)

View on GitHub (pinned to ec1a0befd2)