REPRODUCIBLE CVE RESEARCH

Turning CVEs into reproducible defensive security labs.

CVE Mapping connects vendor claims to observable application state, normalized telemetry, detection engineering, and repeatable validation.

Reproduce→Observe→Detect→Validate

CATALOG

Published labs

4 published labs
PUBLISHED LAB VALIDATED
Gitea

CVE-2026-60004

CVE-2026-60004 Gitea diffpatch Git-hook installation

Vulnerable1.27.0Observed state change
Patched1.27.1Control blocked state change
Validation
  • ✓ Runtime validated
  • ✓ CI validated
  • ✓ Patched control verified
Detection coverage

Sigma · Splunk · Elastic

PUBLISHED LAB VALIDATED
GitLab

CVE-2026-19650

CVE-2026-19650 GitLab GraphQL multiplex GET handling

Vulnerable19.2.2-ee.0Observed state change
Patched19.2.4-ee.0Control blocked state change
Validation
  • ✓ Runtime validated
  • ✓ CI validated
  • ✓ Patched control verified
Detection coverage

Sigma · Splunk · Elastic · osquery

PUBLISHED LAB VALIDATED
Grafana Labs

CVE-2026-33377

CVE-2026-33377 Grafana dashboard import ACL overwrite

Vulnerable12.4.2Observed state change
Patched12.4.3+security-02Control blocked state change
Validation
  • ✓ Runtime validated
  • ✓ CI validated
  • ✓ Patched control verified
Detection coverage

Sigma · Splunk · Elastic

PUBLISHED LAB VALIDATED
Apache

CVE-2021-44228

CVE-2021-44228 Apache Log4j Log4Shell controlled lab

Vulnerable2.14.1Observed state change
Patched2.17.1Control blocked state change
Validation
  • ✓ Runtime validated
  • ✓ CI validated
  • ✓ Patched control verified
Detection coverage

Sigma · Splunk · Elastic

METHOD

Evidence before assertion.

A compact research model keeps each observation scoped, comparable, and reproducible. Read the methodology.

  1. 01

    Reproduce

    Run the disposable vulnerable and patched controls locally.

  2. 02

    Observe

    Correlate application state, evidence boundaries, and normalized telemetry.

  3. 03

    Detect

    Exercise detection content against the preserved telemetry fixtures.

  4. 04

    Validate

    Record the differential result and keep CI checks repeatable.

SAFETY

Authorized defensive research only.

Labs use disposable systems and localhost-only vulnerable services. CVE Mapping does not host vulnerable instances. Use only synthetic/local credentials and test systems you own or are explicitly authorized to assess. Review the safety model.

SEPARATE TRACK

Experimental / historical research

CVE-2026-19478 is retained as experimental research. It is not a published lab and does not carry the validation status shown in the catalog above.

View repository research

NEWSLETTER

New labs and detection notes.

One email per published lab, plus occasional defensive analysis. No spam, unsubscribe anytime.

Subscribe