github RasaHQ/rasa-sdk 3.18.2

latest releases: 3.19.2, 3.17.3
4 hours ago

Rasa_Sdk 3.18.2 (2026-10-08)

Bugfixes

  • #1423: Security patch — upgrade strongly recommended: the action server no longer depends on the unmaintained sanic-cors package, which was last released in 2022 and carries CVE-2026-37737. sanic-cors matched configured origins with an unanchored regular expression, so an allowlist entry such as --cors 'https://.*\.example\.com' also accepted attacker-controlled origins like https://app.example.com.attacker.test, letting them read cross-origin responses from the action server. CORS is now handled in-tree and origins are matched with full anchoring.

    Three smaller corrections come with this:

    • Wildcard origins now work as globs. --cors 'https://*.example.com' matches https://app.example.com and nothing outside example.com. Previously such a value was compiled as a regular expression and silently matched no origin at all.
    • Preflight responses no longer carry an Access-Control-Max-Age header. It was previously sent as the literal, invalid string None.
    • A request that repeats the Origin header no longer receives CORS headers. The two values used to be joined and echoed back as a single, meaningless origin.

    Exact (non-wildcard) origins and the --cors flag are otherwise unchanged. If you configured an origin as a regular expression and relied on it matching by prefix, anchor it explicitly or switch to the * glob form.

Don't miss a new rasa-sdk release

NewReleases is sending notifications on new releases.