jackc/pgx · error

unused argument

Error message

unused argument: %d

What it means

After sanitization, at least one supplied argument was never referenced by any placeholder in the SQL. Sanitize requires every argument to be used, so extra arguments are rejected.

Solutions

  1. Remove the unused argument (index reported in the message)
  2. Add the corresponding placeholder to the SQL
  3. Check for placeholder numbering gaps that skip an argument
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at internal/sanitize/sanitize.go:103 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/546461faa3d01776. Report an issue: GitHub.

Appendix: source

Thrown at internal/sanitize/sanitize.go:103

					AppendFormat(buf.AvailableBuffer(), "'2006-01-02 15:04:05.999999999Z07:00:00'")
			default:
				return "", fmt.Errorf("invalid arg type: %T", arg)
			}
			argUse[argIdx] = true

			buf.Write(p)

			// Prevent SQL injection via Line Comment Creation
			// https://github.com/jackc/pgx/security/advisories/GHSA-m7wr-2xf7-cm9p
			buf.WriteByte(' ')
		default:
			return "", fmt.Errorf("invalid Part type: %T", part)
		}
	}

	for i, used := range argUse {
		if !used {
			return "", fmt.Errorf("unused argument: %d", i)
		}
	}
	return buf.String(), nil
}

func NewQuery(sql string) (*Query, error) {
	query := &Query{}
	query.init(sql)

	return query, nil
}

var sqlLexerPool = &pool[*sqlLexer]{
	new: func() *sqlLexer {
		return &sqlLexer{}
	},
	reset: func(sl *sqlLexer) bool {
		*sl = sqlLexer{}

View on GitHub (pinned to ec1a0befd2)