A vulnerability described as critical has been identified in laughingman7743 PyAthena up to 3.35.3. This affects the function
DefaultParameterFormatter.format of the component Parameter Formatter. The manipulation results in sql injection.
This vulnerability is cataloged as CVE-2026-65321. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.