Skip to content

XmlTextReader.Read throws ArgumentNullException #1409

Description

@Metalnem

DataContractSerializer.ReadObject sometimes throws ArgumentNullException. Here's the full program that reproduces this:

using System.IO;
using System.Runtime.Serialization;
using System.Text;

namespace CoreFX.Fuzz
{
  public class Program
  {
    [DataContract]
    private class Obj { }

    public static void Main(string[] args)
    {
      var xml = @"<Program.Obj xmlns=""http://schemas.datacontract.org/2004/07/CoreFX.Fuzz""><s:";
      var bytes = Encoding.UTF8.GetBytes(xml);
      var stream = new MemoryStream(bytes);
      var serializer = new DataContractSerializer(typeof(Obj));

      serializer.ReadObject(stream);
    }
  }
}

The stack trace:

Exception has occurred: CLR/System.ArgumentNullException
An unhandled exception of type 'System.ArgumentNullException' occurred in System.Private.Xml.dll: 'The empty string '' is not a valid local name.'
   at System.Xml.XmlConvert.VerifyNCName(String name, ExceptionType exceptionType)
   at System.Xml.XmlConvert.VerifyNCName(String name)
   at System.Xml.XmlUTF8TextReader.VerifyNCName(String s)
   at System.Xml.XmlUTF8TextReader.ReadQualifiedName(PrefixHandle prefix, StringHandle localName)
   at System.Xml.XmlUTF8TextReader.ReadStartElement()
   at System.Xml.XmlUTF8TextReader.Read()
   at System.Runtime.Serialization.XmlReaderDelegator.Read()
   at System.Runtime.Serialization.ClassDataContract.ReadXmlValue(XmlReaderDelegator xmlReader, XmlObjectSerializerReadContext context)
   at System.Runtime.Serialization.XmlObjectSerializerReadContext.ReadDataContractValue(DataContract dataContract, XmlReaderDelegator reader)
   at System.Runtime.Serialization.XmlObjectSerializerReadContext.InternalDeserialize(XmlReaderDelegator reader, String name, String ns, DataContract& dataContract)
   at System.Runtime.Serialization.XmlObjectSerializerReadContext.InternalDeserialize(XmlReaderDelegator xmlReader, Type declaredType, DataContract dataContract, String name, String ns)
   at System.Runtime.Serialization.DataContractSerializer.InternalReadObject(XmlReaderDelegator xmlReader, Boolean verifyObjectName, DataContractResolver dataContractResolver)
   at System.Runtime.Serialization.XmlObjectSerializer.ReadObjectHandleExceptions(XmlReaderDelegator reader, Boolean verifyObjectName, DataContractResolver dataContractResolver)
   at System.Runtime.Serialization.XmlObjectSerializer.ReadObject(XmlDictionaryReader reader)
   at System.Runtime.Serialization.XmlObjectSerializer.ReadObject(Stream stream)

The environment:

.NET Core SDK (reflecting any global.json):
 Version:   2.2.103
 Commit:    8edbc2570a

Runtime Environment:
 OS Name:     Mac OS X
 OS Version:  10.14
 OS Platform: Darwin
 RID:         osx.10.14-x64
 Base Path:   /usr/local/share/dotnet/sdk/2.2.103/

Found via SharpFuzz.

Activity

  1. danmoseley commented on Feb 9, 2019

    @danmoseley
    Contributor

    Questionable choice of exception for XML to throw on malformed XML.

  2. danmoseley commented on Mar 4, 2019

    @danmoseley
    Contributor

    This type is actually internal to DCS.

  3. Lxiamail commented on Apr 3, 2019

    @Lxiamail
    Contributor

    We should throw a different exception other than ArgumentNullException. However, due to the issue is not reported by real world scenario, this is lower priority issue.

  4. added this to the Future milestone on Jan 7, 2020
  5. added and removed
    untriagedNew issue has not been triaged by the area owner
    on Jan 7, 2020
  6. StephenBonikowsky commented on Feb 28, 2020

    @StephenBonikowsky
    Contributor

    Simple fix, low priority scenario.
    @imcarolwang Could you add this as something for your team to try fixing.

  7. removed this from the Future milestone on Mar 5, 2020
  8. added this to the Future milestone on Jul 1, 2020
  9. HongGit commented on Jul 1, 2020

    @HongGit
    Contributor

    @imcarolwang is this still on your radar?

  10. 7 remaining items

  11. changed the title [-]DataContractSerializer.ReadObject throws ArgumentNullException[/-] [+]XmlTextReader.Read throws ArgumentNullException[/+] on Oct 9, 2021
  12. removed
    untriagedNew issue has not been triaged by the area owner
    on Oct 11, 2021
  13. krwq commented on Oct 12, 2021

    @krwq
    Member

    @Metalnem do you feel like sending PR with a tiny test? I can help with that if needed

  14. added a commit that references this issue on Dec 9, 2021
  15. StephenMolloy commented on Jul 6, 2023

    @StephenMolloy
    Contributor

    @imcarolwang - If this still repros, System.Xml.XmlUTF8TextReader.VerifyNCName should be null-checking before going forward and throwing an XmlException instead.

  16. imcarolwang commented on Jul 7, 2023

    @imcarolwang
    Contributor

    @StephenMolloy, I haven't been able to reproduce this issue, on my repro environment, the stack trace seems missing some details than reported in issue, the exception is System.Runtime.Serialization.SerializationException, not ArgumentNullException, like I pasted before even on net6.0, do I miss something in repro the bug? I tried to run the code on both Windows and Ubuntu OS, I am not sure if it has difference than on Mac OS ...

    Update: I just realized I made a silly mistake when reproducing the issue—it was because I used mismatched namespace in the demo code. The issue is still reproducible on both .NET Framework and .NET platforms.

  17. StephenMolloy commented on Aug 8, 2025

    @StephenMolloy
    Contributor

    Looks like this is still reproducible. But I will say this... it also reproduces on 4.8. And of course the Xml being processed here is malformed. I misspoke earlier about VerifyNCName. It's doing the same thing it has always done since 4.8. I suppose the question is whether a frame further up the stack should be wrapping the ArgumentNullException in something higher-level like SerializationException.

  18. added
    in-prThere is an active PR which will close this issue when it is merged
    on Aug 11, 2025
  19. StephenMolloy commented on Jun 1, 2026

    @StephenMolloy
    Contributor

    I think I was working with the wrong mental context in my last comment when I said I misspoke about VerifyNCName. I actually believe that is where the fix should probably be. I don't know why my last comment made it sound like "nothing has changed there, so that can't be the cause" when the sentence right before literally states that this odd exception type has been the case going all the way back to .Net 4.8.

    The proposed fix works for the repro, but it is probably at the wrong layer. Catching ArgumentException around the entire XmlObjectSerializer.ReadObjectHandleExceptions scope changes behavior for more than this XML reader bug, including DataContractJsonSerializer and user/deserialization code that throws ArgumentException. I’d prefer fixing the narrow source in System.Private.DataContractSerialization\src\System\Xml\XmlUTF8TextReader.cs (VerifyNCName) so the malformed XML becomes an XmlException, which the existing DCS wrapper already converts to SerializationException.

  20. added a commit that references this issue on Jun 2, 2026
    41642df
  21. locked and limited conversation to collaborators on Jul 3, 2026
  22. added a commit that references this issue on Jul 15, 2026
    610b311
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area-System.Xmlbugin-prThere is an active PR which will close this issue when it is merged

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions