Skip to content

Exception thrown when streaming certain XML values via XmlReader #4756

Description

@sharpjs

Describe the bug

When streaming with CommandBehavior.SequentialAccess, if an xml value is a fragment beginning with any character other than <, then SqlDataReader.GetXmlReader(…) returns a reader doomed to throw an exception.

System.Xml.XmlException
  HResult=0x80131940
  Message='.', hexadecimal value 0x00, is an invalid character. Line 1, position 2.
  Source=System.Private.Xml
  StackTrace:
   at System.Xml.XmlTextReaderImpl.Throw(Exception e)
   at System.Xml.XmlTextReaderImpl.Throw(String res, String[] args)
   at System.Xml.XmlTextReaderImpl.ParseText(Int32& startPos, Int32& endPos, Int32& outOrChars)
   at System.Xml.XmlTextReaderImpl.ParseText()
   at System.Xml.XmlTextReaderImpl.ParseDocumentContent()
   at Program.<Main>$(String[] args) in D:\Code\Self\XmlReaderEncodingBug\XmlReaderEncodingBug\Program.cs:line 14

This issue is fixed by #4757.

To reproduce

using Microsoft.Data.SqlClient;
using System.Data;

using var connection = new SqlConnection("Server=.;Integrated Security=true;Encrypt=false");
connection.Open();

using var command = connection.CreateCommand();
command.CommandText = "SELECT CONVERT(xml, 'a<b/>');";

using var results = command.ExecuteReader(CommandBehavior.SequentialAccess);
results.Read(); // => true

using var xml = results.GetXmlReader(0);
xml.Read(); // throws

Expected behavior

Program exits cleanly.

Further technical details

Microsoft.Data.SqlClient version: 7.1.0
.NET target: .NET 10.0
SQL Server version: SQL Server 2025
Operating system: Windows 11 25H2

Activity

  1. added theissue type on Sep 26, 2026
  2. github-actions commented on Sep 26, 2026

    @github-actions

    🔍 Triage Summary

    Check Result
    Issue type Bug
    Environment All required environment details provided for investigation
    Area No exact match in the standard area label list (this affects XML value streaming via SqlDataReader.GetXmlReader/SqlStream encoding detection, not pooling/AKV/JSON/SNI/bulk copy/vector/async); closest general fit would be Area\Netcore, though the root cause is in shared encoding-detection logic likely affecting both netfx and netcore code paths
    Duplicates None found (exact match); related but distinct: #1877 (O(N^2) perf reading XML with SequentialAccess), #1903 (NullReferenceException streaming XML async, closed), #3035 (ARM test flakiness in XmlReader test)
    Regression Not indicated — no prior-working-version boundary mentioned

    Analysis

    This bug affects SqlDataReader.GetXmlReader() when streaming an xml value under CommandBehavior.SequentialAccess. SQL Server streams xml values as BOM-less UTF-16LE, but some code paths that construct the resulting XmlReader (unlike others that wrap with a BOM-synthesizing SqlStream) don't specify an explicit encoding, so .NET's XML encoding-detection logic can misidentify BOM-less UTF-16LE content as UTF-8 whenever the first character isn't <. This produces a corrupted read and an XmlException on the very first Read() call. The report includes a clear, minimal repro, full stack trace, and complete environment details. Severity: P2 (correctness bug with a clear, narrow root cause and workaround already identified, but no data loss/security impact and a fix is already proposed).

    Next Steps

    Note: This triage summary is auto-generated by an AI agent. The analysis and suggestions above have not been verified by a human maintainer. Please treat as preliminary guidance only.

    Generated by SqlClient Issue Auto-Triage for #4756 · copilot · auto · 35.8 AIC · ⌖ 12.7 AIC · ⊞ 11.8K · ◷

  3. sharpjs commented on Sep 26, 2026

    @sharpjs
    ContributorAuthor

    Suggested label: Repro Available ✔️

  4. added this to the 8.0.0-preview1 milestone on Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Repro Available ✔️Issues that are reproducible with repro provided.

    Type

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions