Rasa_Sdk 3.18.2 (2026-10-08)
Bugfixes
-
#1423: Security patch — upgrade strongly recommended: the action server no longer depends on the unmaintained
sanic-corspackage, which was last released in 2022 and carries CVE-2026-37737.sanic-corsmatched configured origins with an unanchored regular expression, so an allowlist entry such as--cors 'https://.*\.example\.com'also accepted attacker-controlled origins likehttps://app.example.com.attacker.test, letting them read cross-origin responses from the action server. CORS is now handled in-tree and origins are matched with full anchoring.Three smaller corrections come with this:
- Wildcard origins now work as globs.
--cors 'https://*.example.com'matcheshttps://app.example.comand nothing outsideexample.com. Previously such a value was compiled as a regular expression and silently matched no origin at all. - Preflight responses no longer carry an
Access-Control-Max-Ageheader. It was previously sent as the literal, invalid stringNone. - A request that repeats the
Originheader no longer receives CORS headers. The two values used to be joined and echoed back as a single, meaningless origin.
Exact (non-wildcard) origins and the
--corsflag are otherwise unchanged. If you configured an origin as a regular expression and relied on it matching by prefix, anchor it explicitly or switch to the*glob form. - Wildcard origins now work as globs.