Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v4w8-49pv-mf72 | ChatterBot Vulnerable to Denial of Service via Database Connection Pool Exhaustion |
Thu, 05 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chatterbot
Chatterbot chatterbot |
|
| CPEs | cpe:2.3:a:chatterbot:chatterbot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Chatterbot
Chatterbot chatterbot |
Tue, 20 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 20 Jan 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gunthercox
Gunthercox chatterbot |
|
| Vendors & Products |
Gunthercox
Gunthercox chatterbot |
Mon, 19 Jan 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ChatterBot is a machine learning, conversational dialog engine for creating chat bots. ChatterBot versions up to 1.2.10 are vulnerable to a denial-of-service condition caused by improper database session and connection pool management. Concurrent invocations of the get_response() method can exhaust the underlying SQLAlchemy connection pool, resulting in persistent service unavailability and requiring a manual restart to recover. Version 1.2.11 fixes the issue. | |
| Title | ChatterBot has Denial of Service via Database Connection Pool Exhaustion | |
| Weaknesses | CWE-400 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-20T20:05:48.462Z
Reserved: 2026-01-16T15:46:40.842Z
Link: CVE-2026-23842
Updated: 2026-01-20T20:04:07.426Z
Status : Analyzed
Published: 2026-01-19T19:16:04.510
Modified: 2026-02-05T18:03:53.000
Link: CVE-2026-23842
No data.
OpenCVE Enrichment
Updated: 2026-04-18T05:15:15Z
Github GHSA