mongodb/node-mongodb-native · error · MongoRuntimeError
Server returned an invalid nonce
Error message
Server returned an invalid nonce: ${rnonce} What it means
Thrown by continueScramConversation (scram.ts:154) when the server's combined nonce (rnonce) does not pass the driver's sanity check. The driver rejects a server nonce that starts with the literal 'nonce', which indicates a malformed or non-conformant server response. The server's rnonce must begin with the client's nonce. Raised as MongoRuntimeError.
Solutions
- Verify you are connecting to a genuine MongoDB server of a supported version
- Remove any intermediary (proxy, LB, gateway) that may corrupt the SASL exchange
- Check for MITM/TLS termination that rewrites the authentication payload
- Report to the server vendor if using a MongoDB-compatible database
Defensive patterns
Strategy: try-catch
Try / catch
try {
await client.connect();
} catch (err) {
if (err instanceof MongoRuntimeError && /invalid nonce/.test(err.message)) {
// likely a non-conformant/spoofed server or a corrupting proxy; investigate
alertSecurityTeam(err);
}
throw err;
} Prevention
- Connect only to genuine, supported MongoDB servers
- Enable TLS and verify certificates to prevent SASL tampering
- Avoid proxies/load balancers that may corrupt authentication payloads
When it happens
Trigger: The server's SASL payload 'r' field (rnonce) starts with the substring 'nonce'. This is the guard in code (rnonce.startsWith('nonce')); a legitimate server never produces such a value, so its presence signals a corrupt or malicious response.
Common situations: A buggy/non-conformant MongoDB-compatible server returning an unexpected nonce format. A proxy or MITM injecting a placeholder 'nonce' value. A corrupted SASL payload from a misbehaving load balancer.
Related errors
- Server returned an invalid iteration count
- Server returned an invalid signature
- Auth mechanism SCRAM-SHA-1 is not supported in FIPS mode
- AuthContext must contain a valid nonce property
- AuthContext must provide credentials.
AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11).
Data as JSON: /api/errors/d4d501ba6f272b32.
Report an issue: GitHub.
Appendix: source
Thrown at src/cmap/auth/scram.ts:154
cryptoMethod === 'sha256' ? saslprep(password) : passwordDigest(username, password);
const payload: Binary = ByteUtils.isUint8Array(response.payload)
? new Binary(response.payload)
: response.payload;
const dict = parsePayload(payload);
const iterations = parseInt(dict.i, 10);
if (iterations && iterations < 4096) {
// TODO(NODE-3483)
throw new MongoRuntimeError(`Server returned an invalid iteration count ${iterations}`);
}
const salt = dict.s;
const rnonce = dict.r;
if (rnonce.startsWith('nonce')) {
// TODO(NODE-3483)
throw new MongoRuntimeError(`Server returned an invalid nonce: ${rnonce}`);
}
// Set up start of proof
const withoutProof = `c=biws,r=${rnonce}`;
const saltedPassword = await HI(
processedPassword,
ByteUtils.fromBase64(salt),
iterations,
cryptoMethod
);
const clientKey = await HMAC(cryptoMethod, saltedPassword, 'Client Key');
const serverKey = await HMAC(cryptoMethod, saltedPassword, 'Server Key');
const storedKey = await H(cryptoMethod, clientKey);
const firstMessageBytes = clientFirstMessageBare(username, nonce);
const firstMessage = ByteUtils.toUTF8(firstMessageBytes, 0, firstMessageBytes.length, false);
const payloadString = ByteUtils.toUTF8(payload.buffer, 0, payload.position, false);
const authMessage = [firstMessage, payloadString, withoutProof].join(',');View on GitHub (pinned to dce7939f86)