Fixed a SQL injection vulnerability caused by incorrect escaping of bytes
parameters when using the big5, gbk, sjis, cp932, or gb18030 character sets.
This vulnerability also occurs when strings decoded from bytes using surrogateescape are passed as query parameters.
Queries are now encoded using the strict error handler instead of surrogateescape.
Queries that cannot be encoded using the connection encoding can no longer be sent.
bytes parameters are now always sent as hexadecimal literals, such as X'636174'. Note that this increases the number of bytes sent.
The binary_prefix parameter of connect() is deprecated. The _binary
prefix is no longer sent.
These changes address the confirmed SQL injection vulnerabilities related to
character encoding.
However, we strongly recommend using UTF-8 (utf8mb4).
Other character sets are not thoroughly tested, and their limited use means
that problems may go unreported. In the 2020s, encodings other than UTF-8
should be considered legacy.
Configuration
📅Schedule: (UTC)
Branch creation
At any time (no schedule defined)
Automerge
At any time (no schedule defined)
🚦Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕Ignore: Close this PR and you won't be reminded about this update again.
If you want to rebase/retry this PR, check this box
This PR contains the following updates:
| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [PyMySQL](https://github.com/PyMySQL/PyMySQL) ([changelog](https://github.com/PyMySQL/PyMySQL/blob/main/CHANGELOG.md)) | `==1.2.0` → `==1.2.1` |  |  |
---
### Release Notes
<details>
<summary>PyMySQL/PyMySQL (PyMySQL)</summary>
### [`v1.2.1`](https://github.com/PyMySQL/PyMySQL/blob/HEAD/CHANGELOG.md#v121-security-fix)
[Compare Source](https://github.com/PyMySQL/PyMySQL/compare/v1.2.0...v1.2.1)
Release date: 2026-09-17
Fixed a SQL injection vulnerability caused by incorrect escaping of `bytes`
parameters when using the big5, gbk, sjis, cp932, or gb18030 character sets.
This vulnerability also occurs when strings decoded from `bytes` using
`surrogateescape` are passed as query parameters.
See also: <https://github.com/PyMySQL/PyMySQL/security/advisories/GHSA-x4f8-9hx9-hpp9>
- Queries are now encoded using the `strict` error handler instead of
`surrogateescape`.
Queries that cannot be encoded using the connection encoding can no longer be sent.
- `bytes` parameters are now always sent as hexadecimal literals, such as
`X'636174'`. Note that this increases the number of bytes sent.
- The `binary_prefix` parameter of `connect()` is deprecated. The `_binary`
prefix is no longer sent.
These changes address the confirmed SQL injection vulnerabilities related to
character encoding.
However, we strongly recommend using UTF-8 (`utf8mb4`).
Other character sets are not thoroughly tested, and their limited use means
that problems may go unreported. In the 2020s, encodings other than UTF-8
should be considered legacy.
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Enabled.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC44My4yIiwidXBkYXRlZEluVmVyIjoiNDQuODMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR contains the following updates:
==1.2.0→==1.2.1Release Notes
PyMySQL/PyMySQL (PyMySQL)
v1.2.1Compare Source
Release date: 2026-09-17
Fixed a SQL injection vulnerability caused by incorrect escaping of
bytesparameters when using the big5, gbk, sjis, cp932, or gb18030 character sets.
This vulnerability also occurs when strings decoded from
bytesusingsurrogateescapeare passed as query parameters.See also: https://github.com/PyMySQL/PyMySQL/security/advisories/GHSA-x4f8-9hx9-hpp9
Queries are now encoded using the
stricterror handler instead ofsurrogateescape.Queries that cannot be encoded using the connection encoding can no longer be sent.
bytesparameters are now always sent as hexadecimal literals, such asX'636174'. Note that this increases the number of bytes sent.The
binary_prefixparameter ofconnect()is deprecated. The_binaryprefix is no longer sent.
These changes address the confirmed SQL injection vulnerabilities related to
character encoding.
However, we strongly recommend using UTF-8 (
utf8mb4).Other character sets are not thoroughly tested, and their limited use means
that problems may go unreported. In the 2020s, encodings other than UTF-8
should be considered legacy.
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.