GHSA-v4w8-49pv-mf72
HIGHCVE-2026-23842ChatterBot versions up to 1.2.10 are vulnerable to a denial-of-service condition caused by improper database session and connection pool management. Concurrent invocations of the getresponse() method can exhaust the underlying SQLAlchemy connection pool, resulting in persistent service unavailability and requiring a manual restart to recover.
- Affected
- <= 1.2.10
- Fixed in
- 1.2.11
- Weakness
- CWE-400
- Published
- 2026-01-20
- Source
- github