|  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #68802 PDO::FETCH_SERIALIZE does not unserialize object
Submitted: 2015-01-12 01:00 UTC Modified: 2017-10-24 08:31 UTC
Avg. Score:5.0 ± 0.0
Reproduced:1 of 2 (50.0%)
Same Version:1 (100.0%)
Same OS:1 (100.0%)
From: zerkms at zerkms dot ru Assigned:
Status: Open Package: PDO related
PHP Version: Irrelevant OS:
Private report: No CVE-ID: None
View Add Comment Developer Edit
Anyone can comment on a bug. Have a simpler test case? Does it work for you on a different platform? Let us know!
Just going to say 'Me too!'? Don't clutter the database with that please — but make sure to vote on the bug!
Your email address:
Solve the problem:
28 - 12 = ?
Subscribe to this entry?

 [2015-01-12 01:00 UTC] zerkms at zerkms dot ru
PDO::FETCH_SERIALIZE flag must enable automatic deserialization of an object, while it does it in some wrong way.

If you additionally see the `passed data` line you will notice that the argument passed there contains extra data (the class name) that should not be there.

It causes the whole unserialization process to be broken.

The correspondning test is also invalid since it does not check that we can assemble the original object back.

Test script:
class foo implements Serializable {
    private $data;
    public function __construct() {
        $this->data = "My private data";
    public function serialize() {
        return serialize($this->data);
    public function unserialize($data) {
        var_dump('passed data: ', $data);
        $this->data = unserialize($data);
    public function getData() {
        return $this->data;
$foo = new foo;

$stmt = $pdo->prepare('SELECT \'C:3:"foo":23:{s:15:"My private data";}\'');
$stmt->setFetchMode(PDO::FETCH_CLASS|PDO::FETCH_SERIALIZE, 'foo');
$data = $stmt->fetch();

Expected result:
  object(foo)#5 (1) {
    string(15) "My private data"

Actual result:
object(foo)#4 (1) {
  object(foo)#5 (1) {
    string(15) "My private data"


Add a Patch

Pull Requests

Add a Pull Request


AllCommentsChangesGit/SVN commitsRelated reports
 [2017-10-24 08:31 UTC]
-Package: PDO Core +Package: PDO related
PHP Copyright © 2001-2020 The PHP Group
All rights reserved.
Last updated: Mon Feb 17 22:01:25 2020 UTC