NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #319 most downloaded on PyPI
Pure Python MySQL Driver
Last release 17 days ago
17 Sep 2026
Release timing varies
gaps range from 1 weeks to 2.2 years
Nearly every release is documented
notes for 40 of 43 stable releases
1 version withdrawn
withdrawn after publishing
17 years old
49 releases · first in 2009
Full Changelog : v1.2.2...v1.2.3
Full Changelog: v1.2.2...v1.2.3
Release date: 2026-09-17
Restored the ability to import pymysql.converters.escape_bytes_prefixed for
compatibility with aiomysql.
Use pymysql.converters at your own risk.
It's internal functions. No backward compatibility are guaranteed.
Restored the ability to import pymysql.converters.escape_dict for compatibility with aiomysql. This function does not escape dictionaries and is entir
Restored the ability to import pymysql.converters.escape_dict for
compatibility with aiomysql.
This function does not escape dictionaries and is entirely unnecessary.
Unless you use aiomysql, there is no need to upgrade from v1.2.1.
Full Changelog: v1.2.1...v1.2.2
One column per quarter.
Release date: 2026-09-17
Restored the ability to import pymysql.converters.escape_dict for
compatibility with aiomysql.
This function does not escape dictionaries and is entirely unnecessary.
Unless you use aiomysql, there is no need to upgrade from v1.2.1.
Bump codecov/codecov-action from 6 to 7 in the all-dependencies group by @dependabot [bot] in #1250
Full Changelog: v1.2.0...v1.2.1
Release date: 2026-09-17
Fixed a SQL injection vulnerability caused by incorrect escaping of bytes
parameters when using the big5, gbk, sjis, cp932, or gb18030 character sets.
This vulnerability also occurs when strings decoded from bytes using
surrogateescape are passed as query parameters.
See also: https://github.com/PyMySQL/PyMySQL/security/advisories/GHSA-x4f8-9hx9-hpp9
Queries are now encoded using the strict error handler instead of
surrogateescape.
Queries that cannot be encoded using the connection encoding can no longer be sent.
bytes parameters are now always sent as hexadecimal literals, such as
X'636174'. Note that this increases the number of bytes sent.
The binary_prefix parameter of connect() is deprecated. The _binary
prefix is no longer sent.
These changes address the confirmed SQL injection vulnerabilities related to
character encoding.
However, we strongly recommend using UTF-8 (utf8mb4).
Other character sets are not thoroughly tested, and their limited use means
that problems may go unreported. In the 2020s, encodings other than UTF-8
should be considered legacy.
deprecate db and passwd again by @methane in #1240
executemany INSERT regex by @Copilot in #1235decimal.Decimal query parameters (NaN, sNaN, ±Infinity) by @Copilot in #1237db and passwd again by @methane in #1240reconnect in Connection.ping() by @methane in #1241Connection.set_charset() at runtime and document warning behavior by @Copilot in #1243Full Changelog: v1.1.3...v1.2.0
Release date: 2026-05-19
Connection.ping() change the default to not reconnect and deprecate reconnect argument.
Create a new connection if you want to reconnect. (#1241)
Error classes in Cursor class are removed. (#1240)
connect() arguments db and passwd now emit DeprecationWarning.
Use database and password instead. (#1240)
Reorganize TLS connection behavior.
PyMySQL uses TLS by default when server supports it.
Use ssl_disabled=True to prohibit SSL. (#1213)
When ssl_verify_cert=True, ssl_verify_identity=True, an ssl.SSLContext is passed,
or when any other SSL option is configured, the connection requires SSL and raises
OperationalError (CR_SSL_CONNECTION_ERROR) if the server doesn't support it. (#1234)
executemany INSERT regex. (#1235)decimal.Decimal query parameters (NaN, sNaN, ±Infinity). (#1237)Connection.set_charset(charset) now emits DeprecationWarning.callproc: escape procname by @methane in #1225
Full Changelog: v1.1.2...v1.1.3
Release date: 2026-05-01
Fix Cursor.callproc() didn't escape procedure name. (#1206)
There was a possibility of SQL injection when calling a procedure with a string received from an untrusted source as the procedure name.
NOTICE: This change may cause backward compatibility issues. If you specified a procedure name like "dbname.funcname", the previous version called CALL dbname.funcname, but from this version, it will call CALL `dbname.funcname` so you cannot specify procedure name with database name anymore.
Prevent UnboundLocalError on MySQLResult initialization during SystemExit by @palm002 in #1174
connection._rfile in Connection._force_close by @cfbolz in #1184Full Changelog: v1.1.1...v1.1.2
Release date: 2025-08-24
SocketIO soon when Connection is closed for PyPy. https://github.com/PyMySQL/PyMySQL/issues/1183getpass.getuser() raises OSEError. https://github.com/PyMySQL/PyMySQL/pull/1190Connection.kill() uses KILL query instead of COM_KILLcommand to support MySQL 8.4. https://github.com/PyMySQL/PyMySQL/pull/1197Warning This release fixes a vulnerability ( CVE-2024-36039 ). All users are recommended to update to this version.
Warning
This release fixes a vulnerability (CVE-2024-36039).
All users are recommended to update to this version.
If you can not update soon, check the input value from untrusted source has an expected type.
Only dict input from untrusted source can be an attack vector.
Cursor.execute(). It didn't produce valid SQLFull Changelog: v1.1.0...v1.1.1
Release date: 2024-05-21
[!WARNING] This release fixes a vulnerability (CVE-2024-36039). All users are recommended to update to this version.
If you can not update soon, check the input value from untrusted source has an expected type. Only dict input from untrusted source can be an attack vector.
Cursor.execute(). It didn't produce valid SQL
and might cause SQL injection. (CVE-2024-36039)Deprecate Cursor.Error access by @methane in #1117
Cursor.warning_count by @Nothing4You in #1056_ with - by @methane in #1114collation option and set_character_set() to Connection by @methane in #1119Full Changelog: v1.0.3...v1.1.0
Release date: 2023-06-26
Cursor.warning_count to check for warnings without additional query (#1056)Cursor.fetchall() returns empty list instead of tuple (#1115). Note that Cursor.fetchmany() still return empty tuple after reading all rows for compatibility with Django.Connection.set_character_set(charset, collation=None). This method is compatible with mysqlclient. (#1119)Connection.set_charset(charset) (#1119)charset="utf8mb3" option (#1127)Bump mariadb version by @grooverdan in #1123
Deprecate Cursor.Error access by @methane in #1117
Cursor.warning_count by @Nothing4You in #1056_ with - by @methane in #1114collation option and set_character_set() to Connection by @methane in #1119Full Changelog: v1.0.3...v1.1.0rc1
Remove deprecated socket.error from Connection.connect exception handler by @Nothing4You in #1062
test_nextset by @wd0517 in #1057Full Changelog: v1.0.2...v1.0.3
Release date: 2023-03-28
_last_executed because of duplication with _executed by @rajat315315 in https://github.com/PyMySQL/PyMySQL/pull/948Remove deprecated socket.error from Connection.connect exception handler by @Nothing4You in #1062
test_nextset by @wd0517 in #1057Full Changelog: v1.0.2...v1.0.3rc1
Fix user, password, host, database are still positional arguments. All arguments of connect() are now keyword-only.
Release date: 2021-01-09
user, password, host, database are still positional arguments.
All arguments of connect() are now keyword-only. (#941)Stop emitting DeprecationWarning for use of db and passwd. Note that they are still deprecated.
Release date: 2021-01-08
db and passwd.
Note that they are still deprecated. (#939)python_requires=">=3.6" to setup.py. (#936)connect() kwargs db and passwd are now deprecated; Use database and password instead.
Release date: 2021-01-07
Backward incompatible changes:
connect() uses keyword-only arguments. User must use keyword argument.connect() kwargs db and passwd are now deprecated; Use database and password instead.escape_dict, escape_sequence, and escape_string from pymysql
module. They are still in pymysql.converters.Other changes:
__exit__ closes the connection. (#886)Fix missing import of ProgrammingError.
Release date: 2020-09-10
This version is the last version supporting Python 2.7.
Release date: 2020-07-18
This version is the last version supporting Python 2.7.
Connection. It will be added
with different meaning.Deprecate context manager API of Connection object.
Release date: 2018-12-18
sys.argv[0] for connection attribute "program_name".Disabled unintentinally enabled debug log
Release date: 2018-07-04
Fixed caching_sha2_password and sha256_password raise TypeError on PY2 (#700, #702)
Release date: 2018-07-03
Remove deprecated no_delay option
Release date: 2018-06-27
no_delay option (#694)Reduce cursor.callproc() roundtrip time.
Release date: 2018-05-07
Reduce cursor.callproc() roundtrip time. (#636)
Fixed cursor.query() is hunged after multi statement failed. (#647)
WRONG_DB_NAME and WRONG_COLUMN_NAME is ProgrammingError for now. (#629)
Many test suite improvements, especially adding MySQL 8.0 and using Docker. Thanks to Daniel Black.
Dropped support for old Python and MySQL which is not tested long time.
Nothing published for this version
Fixed Connection.close() failed when failed to send COM_CLOSE packet.
Release date: 2017-04-06
SECURITY FIX: Raise RuntimeError when received LOAD_LOCAL packet while loacal_infile=False. (Thanks to Bryan Helmig)
Release date: 2017-02-14
SECURITY FIX: Raise RuntimeError when received LOAD_LOCAL packet while
loacal_infile=False. (Thanks to Bryan Helmig)
Raise SERVER_LOST error for MariaDB's shutdown packet (#540)
Change default connect_timeout to 10.
Add bind_address option (#529)
Fix PyMySQL stop reading rows when first column is empty string (#513) Reverts DEPRECATE_EOF introduced in 0.7.7.
Release date: 2016-09-03
Revert error message change in 0.7.7. (SQLAlchemy parses error message, #507)
Release date: 2016-09-01
Experimental support for DEPRECATE_EOF protocol.
Release date: 2016-08-30
Fix SELECT JSON type cause UnicodeError
Release date: 2016-07-29
Fix exception raised while importing when getpwuid() fails
Release date: 2016-06-28
Fix AttributeError may happen while Connection.__del__
Release date: 2016-05-26
Add read_timeout and write_timeout option.
Release date: 2016-05-19
conv option.str(), for MySQLdb compatibility.Cursor.executemany()Cursor.executemany()Fix misuse of max_allowed_packet parameter. (#426, #407 and #397)
Release date: 2016-02-24
max_allowed_packet parameter. (#426, #407 and #397)Cursor.executemany(). (#427, thanks to
@WorldException)Fix escaping unicode fails on Python 2
Release date: 2016-01-14
Nothing published for this version
no_delay option is deprecated and True by default
Release date: 2015-09-30
Fix can't encode blob that is not utf-8 on PY3. (regression of 0.6.4, Thanks to @wiggzz)
Skipped
Skipped
Support "LOAD LOCAL INFILE". Thanks @wraziens
init_command now support multi statement.Connection.escape() method now accepts second argument compatible to
MySQL-Python.Nothing published for this version
Fixed multiple result sets with SSCursor.
Fixed old password on Python 3.
Nothing published for this version
Added cursor._last_executed for MySQLdb compatibility
Added Thing2Literal for Django/MySQLdb compatibility
Nothing published for this version
Cleaned up charset functionality
Implemented most of the extended DBAPI 2.0 spec including callproc()
Changed connection parameter name 'password' to 'passwd' to make it more plugin replaceable for the other mysql clients.
Your coding agent can read these notes before it upgrades. Set up the MCP server →