Skip to content

Conversation

vpmedia
Copy link

@vpmedia vpmedia commented Oct 12, 2025

Updates

  • Affected products

Comments
The asyncmy package is also affected by this vulnerability, because it's based on pymysql codebase.
See: long2ice/asyncmy#134

@github-actions github-actions bot changed the base branch from main to vpmedia/advisory-improvement-6303 October 12, 2025 06:02
@helixplant
Copy link

Hi @vpmedia,
We cannot add the package associated with long2ice/asyncmy to this advisory because it is not officially associated with PyMySQL/PyMySQL. If the maintainers of long2ice/asyncmy wish to issue alerts regarding their package’s vulnerability to CVE-2024-36039, they can do so by utilizing the security advisory feature within their repository.

For more information please refer to the following: https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/creating-a-repository-security-advisory

@helixplant helixplant closed this Oct 13, 2025
@github-actions github-actions bot deleted the vpmedia-GHSA-v9hf-5j83-6xpp branch October 13, 2025 12:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants