CVE-2026-32722

Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bloomberg:memray:*:*:*:*:*:python:*:*

History

17 Jun 2026, 10:36

Type Values Removed Values Added
Summary
  • (es) Memray es un perfilador de memoria para Python. Antes de Memray 1.19.2, Memray renderizaba la línea de comandos del proceso rastreado directamente en los informes HTML generados sin escapar. Debido a que no había escape, los argumentos de línea de comandos controlados por el atacante se insertaban como HTML sin procesar en el informe generado. Esto permitía la ejecución de JavaScript cuando una víctima abría el informe generado en un navegador. La versión 1.19.2 corrige el problema.

19 Mar 2026, 19:21

Type Values Removed Values Added
References () https://github.com/bloomberg/memray/commit/ba6e4e2e9930f9641bed7adfdf43c8e2545ce249 - () https://github.com/bloomberg/memray/commit/ba6e4e2e9930f9641bed7adfdf43c8e2545ce249 - Patch
References () https://github.com/bloomberg/memray/releases/tag/v1.19.2 - () https://github.com/bloomberg/memray/releases/tag/v1.19.2 - Product, Release Notes
References () https://github.com/bloomberg/memray/security/advisories/GHSA-r5pr-887v-m2w9 - () https://github.com/bloomberg/memray/security/advisories/GHSA-r5pr-887v-m2w9 - Exploit, Vendor Advisory
First Time Bloomberg
Bloomberg memray
CPE cpe:2.3:a:bloomberg:memray:*:*:*:*:*:python:*:*

18 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-18 22:16

Updated : 2026-06-17 10:36


NVD link : CVE-2026-32722

Mitre link : CVE-2026-32722

CVE.ORG link : CVE-2026-32722


JSON object : View

Products Affected

bloomberg

  • memray
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')