
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23842 is a denial-of-service vulnerability in ChatterBot, a machine learning conversational dialog engine for Python, caused by improper database session and connection pool management. All versions up to and including 1.2.10 are affected. The vulnerability was disclosed on January 17, 2026, via a GitHub Security Advisory, and a fix was released the same day in version 1.2.11. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption). ChatterBot's get_response() method relies on SQLAlchemy for database access but does not enforce concurrency limits, rate limiting, or explicit session lifecycle controls. When multiple threads concurrently invoke get_response(), database connections are rapidly consumed and not released in a timely manner, exhausting the SQLAlchemy QueuePool. This causes subsequent requests to block and eventually fail with a TimeoutError, rendering the service unavailable. The fix in version 1.2.11 introduced scoped_session for thread-safe session management, added safe pool configuration defaults (pool_size, max_overflow, pool_timeout, pool_recycle, pool_pre_ping), and wrapped all session operations in try/finally blocks to guarantee connection release (GitHub Advisory, Patch Commit).
Successful exploitation causes persistent service unavailability of the ChatterBot instance, requiring a manual restart to restore functionality. The attack has no impact on confidentiality or data integrity, but completely eliminates availability for legitimate users. Any deployment of ChatterBot ≤ 1.2.10 that exposes the get_response() method to concurrent network requests — such as a public-facing chatbot service — is susceptible without any authentication requirement (GitHub Advisory).
Public proof-of-concept (PoC) exploit code is available on GitHub, including a repository specifically demonstrating the attack against ChatterBot 1.2.10 (PoC Repository). A PoC video was also published as part of the official security advisory. The EPSS score is approximately 0.044%, indicating low but non-zero probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).
ChatBot object pointing to the target and spawns multiple concurrent threads, each calling bot.get_response("hello").get_response() method with concurrent invocations:from chatterbot import ChatBot
import threading
bot = ChatBot("dos-test")
def attack():
bot.get_response("hello")
threads = []
for _ in range(30):
t = threading.Thread(target=attack)
t.start()
threads.append(t)
for t in threads:
t.join()QueuePool connections without releasing them, triggering TimeoutError exceptions.sqlalchemy.exc.TimeoutError or QueuePool limit of size X overflow Y reached errors in application logs, indicating connection pool exhaustion.The primary remediation is to upgrade ChatterBot to version 1.2.11 or later, which introduces thread-safe scoped_session management, safe connection pool defaults, and guaranteed session cleanup via try/finally blocks (ChatterBot Release). As a temporary workaround for deployments that cannot immediately upgrade, operators should implement rate limiting and concurrency controls at the application or reverse proxy layer (e.g., Nginx, API gateway) to restrict the number of simultaneous requests to the ChatterBot service. Additionally, restricting network access to the ChatterBot service to trusted clients only reduces the attack surface.
The vulnerability was reported by security researcher AdityaBhatt3010, who published a detailed write-up on Infosec Writeups titled "CVE-2026-23842: My First CVE — Exploiting Connection Pool Exhaustion in a Popular Python Chatbot" (Infosec Writeups). The vulnerability was also noted in a CISA vulnerability bulletin for the week of January 19, 2026. Community coverage was moderate, with mentions on security aggregators including VulnDB, CVEFeed, and Bluesky security accounts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."