memray
Memray is a memory profiler for Python
Activity
- Latest release
- 1mo ago
- Total releases
- 36
- Cadence
- ~34 days
- Last 12 months
- 4
Reach
- Stars
- 15.2k
Details
- License
- Apache-2.0
- First release
- Apr 09, 2022
| Version | Released | |
|---|---|---|
1.20.0
minor
| ||
1.19.3
patch
| ||
1.19.2
patch
| ||
1.19.1
patch
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.19.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.18.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.17.2
patch
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.17.1
patch
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.17.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.16.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.15.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.14.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.13.4
patch
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.13.3
patch
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.13.2
patch
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.13.1
patch
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.13.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.12.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.11.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.10.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.9.1
patch
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.9.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.8.1
patch
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.8.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.7.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.6.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.5.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.1
patch
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.1
patch
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.3
patch
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.0
initial
1 CVE
CVE-2026-32722
PYSEC-2026-2203
GHSA-r5pr-887v-m2w9
Mar 18, 2026
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process directly into generated HTML reports without escaping. Because there was no escaping, attacker-controlled command line arguments were inserted as raw HTML into the generated report. This allowed JavaScript execution when a victim opened the generated report in a browser. Version 1.19.2 fixes the issue. Affected versions
1.0.0
1.0.2
1.0.3
1.1.0
1.10.0
1.11.0
1.12.0
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
+ 21 more Show less
1.14.0
1.15.0
1.16.0
1.17.0
1.17.1
1.17.2
1.18.0
1.19.0
1.19.1
1.2.0
1.3.0
1.3.1
1.4.0
1.4.1
1.5.0
1.6.0
1.7.0
1.8.0
1.8.1
1.9.0
1.9.1
Fixed in
1.19.2
References Updated Jul 13, 2026 · Source: OSV.dev |