Skip to content

3.17.3

Choose a tag to compare

@rasabot rasabot released this 09 Oct 09:26
· 78 commits to main since this release
2165ff1

Rasa_Sdk 3.17.3 (2026-10-08)

Bugfixes

  • #1423: Security patch — upgrade strongly recommended: the action server no longer depends on the unmaintained sanic-cors package, which was last released in 2022 and carries CVE-2026-37737. sanic-cors matched configured origins with an unanchored regular expression, so an allowlist entry such as --cors 'https://.*\.example\.com' also accepted attacker-controlled origins like https://app.example.com.attacker.test, letting them read cross-origin responses from the action server. CORS is now handled in-tree and origins are matched with full anchoring.

    Three smaller corrections come with this:

    • Wildcard origins now work as globs. --cors 'https://*.example.com' matches https://app.example.com and nothing outside example.com. Previously such a value was compiled as a regular expression and silently matched no origin at all.
    • Preflight responses no longer carry an Access-Control-Max-Age header. It was previously sent as the literal, invalid string None.
    • A request that repeats the Origin header no longer receives CORS headers. The two values used to be joined and echoed back as a single, meaningless origin.

    Exact (non-wildcard) origins and the --cors flag are otherwise unchanged. If you configured an origin as a regular expression and relied on it matching by prefix, anchor it explicitly or switch to the * glob form.