jackc/pgx · error

invalid SCRAM iteration count received from server

Error message

invalid SCRAM iteration count received from server: %w

What it means

The SCRAM server-first-message contained an iteration count (i=) that is not a positive integer. Either it failed to parse or parsed to a value <= 0. This is a malformed server response and authentication aborts.

Solutions

  1. Verify the server's scram_iterations setting is valid
  2. Confirm the server is functioning correctly (not corrupted by proxies)
  3. Try connecting with psql to see if the same failure occurs
  4. Contact the server administrator if the problem persists
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at pgconn/auth_scram.go:285 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/302bcee46b88f96a. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/auth_scram.go:285

	}
	saltStr := buf[:idx]
	buf = buf[idx+1:]

	if !bytes.HasPrefix(buf, []byte("i=")) {
		return errors.New("invalid SCRAM server-first-message received from server: did not include i=")
	}
	buf = buf[2:]
	iterationsStr := buf

	var err error
	sc.salt, err = base64.StdEncoding.DecodeString(string(saltStr))
	if err != nil {
		return fmt.Errorf("invalid SCRAM salt received from server: %w", err)
	}

	sc.iterations, err = strconv.Atoi(string(iterationsStr))
	if err != nil || sc.iterations <= 0 {
		return fmt.Errorf("invalid SCRAM iteration count received from server: %w", err)
	}
	// Bound server-supplied iteration count to prevent a malicious server from forcing the client
	// to spend unbounded CPU in PBKDF2. PostgreSQL's scram_iterations defaults to 4096; this ceiling
	// is ~2500x that.
	const maxScramIterations = 10_000_000
	if sc.iterations > maxScramIterations {
		return fmt.Errorf("SCRAM iteration count from server too high: %d (max %d)", sc.iterations, maxScramIterations)
	}

	if !bytes.HasPrefix(sc.clientAndServerNonce, sc.clientNonce) {
		return errors.New("invalid SCRAM nonce: did not start with client nonce")
	}

	if len(sc.clientAndServerNonce) <= len(sc.clientNonce) {
		return errors.New("invalid SCRAM nonce: did not include server nonce")
	}

	return nil

View on GitHub (pinned to ec1a0befd2)