2026-04-23 [Release 1.26.423]
Bug Fixes
- Escape single quotes and backslashes in scalar string native params (#258, #259) —
convertParamValue()now escapes\→\\and'→\'for scalarStringparams inselectWithParams()/writeWithParams(). Previously strings likehello\causedCANNOT_PARSE_ESCAPE_SEQUENCEin ClickHouse (@sander-hash, @tom-on-the-internet)
Testing
- 5 new native-params tests — scalar strings with trailing backslash, embedded backslash, single quote, injection attempt, and
writeWithParamswith backslash
Merged PRs
- #259 — Added escape for scalar string (@sander-hash)
Closed Issues
- #258 — Scalar string params are not escaped, causing
CANNOT_PARSE_ESCAPE_SEQUENCE