CVE-2026-23842: Chatterbot

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

ChatterBot is a machine learning, conversational dialog engine for creating chat bots. ChatterBot versions up to 1.2.10 are vulnerable to a denial-of-service condition caused by improper database session and connection pool management. Concurrent invocations of the get_response() method can exhaust the underlying SQLAlchemy connection pool, resulting in persistent service unavailability and requiring a manual restart to recover. Version 1.2.11 fixes the issue.

Affected products

  • Chatterbot Chatterbot: before 1.2.11 (fixed in 1.2.11)

Published 2026-01-19. Last modified 2026-06-17.