NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #476 most downloaded on PyPI
A Flask extension simplifying CORS support
Last release 3 months ago
08 Jun 2026
Release timing varies
gaps range from 3 weeks to 2.5 years
Most releases are documented
notes for 33 of 51 stable releases
4 versions withdrawn
withdrawn after publishing
13 years old
58 releases · first in 2013
Add MyPy Typing and modernize options parsing by @corydolphin in #409 (this broke strict type checking when using Blueprints)
Supersedes 6.0.4
Full Changelog: 6.0.3...6.0.5
Add MyPy Typing by @corydolphin in #409
One column per quarter.
Derive package version from git tag via setuptools-scm by @corydolphin in #405
Full Changelog: 6.0.2...6.0.3
Derive package version from git tag via setuptools-scm by @corydolphin in #405
Full Changelog: 6.0.2...6.0.3
Update license pyproject.toml by @wagenrace in #395
Full Changelog: 6.0.1...6.0.2
Invert regex sorting to make it correctly match the intent (sorting by specificity descending) #391 by @joshuamorton in #392
Full Changelog: 6.0.0...6.0.1
Fix regex sorting issue from #391 by @joshuamorton in #392
Full Changelog: 6.0.0...6.0.1.dev
[ CVE-2024-6839 ] Sort Paths by Regex Specificity by @adrianosela in #391
Path specificity ordering has changed to improve specificity. This may break users who expected the previous incorrect ordering.
Full Changelog: 5.0.1...6.0.0
This primarily changes packaging to use uv and a new release pipeline, along with some small documentation improvements
This primarily changes packaging to use uv and a new release pipeline, along with some small documentation improvements
Full Changelog: 5.0.0...5.0.01
…https://osv.dev/vulnerability/PYSEC-2024-71
Full Changelog: https://github.com/corydolphin/flask-cors/compare/4.0.2...5.0.0
Backwards Compatible Fix for CVE-2024-6221 by @adrianosela in https://github.com/corydolphin/flask-cors/pull/363
Full Changelog: https://github.com/corydolphin/flask-cors/compare/4.0.1...4.0.2
Fix Read the Docs builds by @kurtmckee in https://github.com/corydolphin/flask-cors/pull/345
Full Changelog: https://github.com/corydolphin/flask-cors/compare/4.0.0...4.0.1
Remove support for Python versions older than 3.8 by @WAKayser in https://github.com/corydolphin/flask-cors/pull/330
Full Changelog: https://github.com/corydolphin/flask-cors/compare/3.1.01...v4.0.0
Nothing published for this version
Adds support for PPC64 and ARM64 builds for distribution. Thanks @sreekanth370
Escape path before evaluating resource rules (thanks @praetorian-colby-morgan). Prior to this, flask-cors incorrectly evaluated CORS resource matching
Fixes DeprecationWarning: Using or importing the ABCs from 'collections' instead of from 'collections.abc' is deprecated, and in 3.8 it will stop work…
Fixes DeprecationWarning: Using or importing the ABCs from 'collections' instead of from 'collections.abc' is deprecated, and in 3.8 it will stop working
Thank you @juanmaneo and @jdevera!
Fixes : DeprecationWarning: Using or importing the ABCs from 'collections' in Python 3.7. Thank you @juanmaneo and @jdevera for the contribution.
Updated logging.warn to logging.warning (#234) Thanks Vaibhav
Updated logging.warn to logging.warning (#234) Thanks Vaibhav
Manual error in release process. Identical contents at 3.0.5.
Manual error in release process. Identical contents at 3.0.5.
Handle response.headers being None. (Fixes issue #217) Thanks @dusktreader for the improvement!
Handle response.headers being None. (Fixes issue #217) Thanks @dusktreader for the improvement!
Ensure that an Origin of '*' is never sent if supports_credentials is True (fixes Issue #202)
Ensure that an Origin of '*' is never sent if supports_credentials is True (fixes Issue #202)
always_send=True, and '*' is in the allowed origins, and a request is made without an Origin header, no Access-Control-Allow-Origins header will now be returned. This is breaking if you depended on it, but was a bug as it goes against the spec.Fixes Issue #187: regression whereby header (and domain) matching was incorrectly case sensitive. Now it is not, making the behavior identical to 2.X
Fixes Issue #187: regression whereby header (and domain) matching was incorrectly case sensitive. Now it is not, making the behavior identical to 2.X and 1.X.
Fixes Issue #183: regression whereby regular expressions for origins with an "?" are not properly matched.
Fixes Issue #183: regression whereby regular expressions for origins with an "?" are not properly matched.
Thanks @di for the report!
This release is largely a number of small bug fixes and improvements, along with a default change in behavior, which is technically a breaking change.
This release is largely a number of small bug fixes and improvements, along with a default change in behavior, which is technically a breaking change.
Breaking Change We added an always_send option, enabled by default, which makes Flask-CORS inject headers even if the request did not have an 'Origin' header. Because this makes debugging far easier, and has very little downside, it has also been set as the default, making it technically a breaking change. If this actually broke something for you, please let me know, and I'll help you work around it. (#156) c7a1ecdad375a796155da6aca6a1f750337175f3
Other improvements:
Fixes Vary:Origin header sending behavior when regex origins are used.
Fixes Vary:Origin header sending behavior when regex origins are used.
Fixes package installation. Requirements.txt was not included in Manifest.
Fixes package installation. Requirements.txt was not included in Manifest.
Stop dynamically referecing logger. Disable internal logging by default and reduce logging verbosity
Stop dynamically referecing logger. Disable internal logging by default and reduce logging verbosity
Adds support for Flask Blueprints.
Adds support for Flask Blueprints.
You may now pass a Flask Blueprint to the CORS extension, and it will work as expected.
Thanks @Bob131for the feature request! https://github.com/corydolphin/flask-cors/issues/128
Fixes Issue #124 where only the first of multiple headers with the same name would be passed through.
Fixes Issue #124 where only the first of multiple headers with the same name would be passed through.
New defaults allow all origins, all headers.
BREAKING CHANGES
New Defaults
Breaking Changes
Update default options and parameters in a backwards incompatible way.
Would love to get some feedback to make sure there are no unexpected regressions. This should be backwards compatible for most people.
Update default options and parameters in a backwards incompatible way.
By default, all headers are now allowed, and only requests with an Origin header have CORS headers returned. If an Origin header is not present, no CORS headers are returned.
Removed the following options: always_send, headers.
Extension and decorator are now in separate modules sharing a core module. Test have been moved into the respective tests.extension and tests.decorator modules. More work to decompose these tests is needed.
Adds logging to Flask-Cors so it is easy to see what is going on and why
Release Version 1.10.3
Big thanks to @michalbachowski and @digitizdat!
This release fixes the behavior of Access-Control-Allow-Headers and Access-Control-Expose-Headers, which was previously swapped since 1.9.0.
This release fixes the behavior of Access-Control-Allow-Headers and Access-Control-Expose-Headers, which was previously swapped since 1.9.0.
To further fix the confusion, the headers parameter was renamed to more explicitly be allow_headers.
Thanks @maximium for the bug report and implementation!
This is a bug fix release, fixing: Incorrect handling of resources and intercept_exceptions App Config options https://github.com/wcdolphin/flask-cors
This is a bug fix release, fixing: Incorrect handling of resources and intercept_exceptions App Config options https://github.com/wcdolphin/flask-cors/issues/84 Issue with functools.partial in 1.10.0 using Python 2.7.9 https://github.com/wcdolphin/flask-cors/issues/83
Shoutout to @diiq and @joonathan for reporting these issues!
Adds support for returning CORS headers with uncaught exceptions in production so 500s will have expected CORS headers set. This will allow clients to
Improves API consistency, allowing a CORS resource of '*'
Thanks to @wking's work in PR https://github.com/wcdolphin/flask-cors/pull/71 python setup.py test will now work.
Thanks to @wking's work in PR https://github.com/wcdolphin/flask-cors/pull/71 python setup.py test will now work.
Adds support for regular expressions in the list of origins.
Adds support for regular expressions in the list of origins.
This allows subdomain wildcarding and should be fully backwards compatible.
Credit to @marcoqu for opening https://github.com/wcdolphin/flask-cors/issues/54 which inspired this work
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix packaging: missing source files
Fix packaging: missing source files (#381)
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →