Gitea
CVE-2026-60004
CVE-2026-60004 Gitea diffpatch Git-hook installation
OVERVIEW
Lab observed
Vendor reported
Vendor-reported fixed versions
1.27.1Only the lab versions above were independently reproduced by CVE Mapping.
LAB OBSERVED
What this lab demonstrates
The fixed marker appeared on 1.27.0 after one controlled request and remained absent on 1.27.1 after the equivalent request.
The vulnerable and patched modes used equivalent controlled actions. Application state—not a successful HTTP status alone—is decisive.
VULNERABLE VS PATCHED RESULT
Runtime accepted and the documented state difference was observed.
Runtime accepted and the expected safe state was retained.
Evidence, telemetry, and detection checks are recorded in the manifest.
DETECTION COVERAGE
Detection engineering
- Sigma1 lab-validated analytic
- Splunk1 lab-validated analytic
- Elastic1 lab-validated analytic
Request telemetry provides context, while the strongest analytic requires correlated application-state telemetry. A request alone does not prove exploitation.
Lab queries
Sigma — gitea_diffpatch_request_attempt.yml lab-validated
title: Suspicious Gitea Repository Diffpatch API Request
id: d64bb6d2-ef14-4a39-9238-2f9ec0c2f341
status: test
description: Detects Gitea diffpatch API activity for investigation; this is request-attempt context and does not confirm successful CVE-2026-60004 exploitation.
references:
- https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m
- https://docs.gitea.com/api/operations/repo-apply-diff-patch/
author: CVE Mapping
date: "2026-08-27"
logsource:
product: gitea
service: normalized_http_request
detection:
selection:
event_type: http_request
service: gitea
method: POST
path|re: ^/api/v1/repos/[^/]+/[^/]+/diffpatch$
condition: selection
falsepositives:
- Authorized patch application by administrators, CI/CD, repository automation, API clients, developer tools, scanners, security tests, or labs
level: medium
Splunk — gitea_diffpatch_request_attempt.spl lab-validated
/*
CVE-2026-60004 suspicious Gitea diffpatch request-attempt analytic.
This request-only search does not confirm successful exploitation.
*/
event_type="http_request" service="gitea" method="POST"
| where match(path, "^/api/v1/repos/[^/]+/[^/]+/diffpatch$")
| eval analytic="gitea_diffpatch_request_attempt"
Elastic — gitea_diffpatch_request_attempt.json lab-validated
{
"name": "Suspicious Gitea repository diffpatch API request",
"cve": "CVE-2026-60004",
"type": "query",
"language": "kuery",
"query": "event_type:http_request and service:gitea and method:POST and path:/api/v1/repos/*/*/diffpatch",
"severity": "medium",
"risk_rationale": "Diffpatch activity is high-value investigation context on affected Gitea versions, but a request alone does not confirm successful exploitation.",
"false_positive_note": "Authorized patch application by administrators, CI/CD, repository automation, API clients, developer tools, scanners, security tests, and labs can match.",
"references": [
"https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m",
"https://docs.gitea.com/api/operations/repo-apply-diff-patch/"
],
"fixture_discrimination": {"vulnerable": 1, "patched": 1, "benign": 0}
}
FIXTURE DISCRIMINATION
Lab fixture performance
Validated state-change analytics matched vulnerable activity; 1 matched the patched control. See the detection validation record for discrimination notes. Contextual analytics are reported separately and are not promoted to vulnerability discriminators.
EVIDENCE & TELEMETRY
Preserved and verifiable
Sanitized evidence and normalized telemetry are tracked by manifest and SHA-256 integrity files.
RISK CONTEXT
Vendor enrichment
Additional risk feeds are omitted without a verified current lookup.
MITRE ATT&CK
Unassigned
COPYABLE RUNBOOK
Start with the Quickstart.
Disposable, localhost-only runbook commands taken from the lab's QUICKSTART.md. Proof internals stay in the repository — these are the operator workflow commands.
Prerequisites
python3 scripts/validate-gitea-bootstrap.py --all
python3 scripts/validate-compose.py --alllabs/gitea/shared/scripts/lab.sh preflight
labs/gitea/shared/scripts/lab.sh prepareVulnerable Mode
labs/gitea/shared/scripts/lab.sh up vulnerable
labs/gitea/shared/scripts/lab.sh wait vulnerable
labs/gitea/shared/scripts/lab.sh init-baseline vulnerable
labs/gitea/shared/scripts/lab.sh init-prereqs vulnerable
labs/gitea/shared/scripts/lab.sh check-60004-prereqs vulnerable
python3 labs/gitea/CVE-2026-60004/poc/reproduce.py vulnerable
python3 labs/gitea/CVE-2026-60004/scripts/verify.py verify-mode vulnerable
labs/gitea/shared/scripts/lab.sh down vulnerable
labs/gitea/shared/scripts/lab.sh clean vulnerable --yesPatched Control
labs/gitea/shared/scripts/lab.sh up patched
labs/gitea/shared/scripts/lab.sh wait patched
labs/gitea/shared/scripts/lab.sh init-baseline patched
labs/gitea/shared/scripts/lab.sh init-prereqs patched
labs/gitea/shared/scripts/lab.sh check-60004-prereqs patched
python3 labs/gitea/CVE-2026-60004/poc/reproduce.py patched
python3 labs/gitea/CVE-2026-60004/scripts/verify.py verify-mode patched
labs/gitea/shared/scripts/lab.sh down patched
labs/gitea/shared/scripts/lab.sh clean patched --yesInspect Evidence and Telemetry
python3 labs/gitea/CVE-2026-60004/scripts/verify.py compare
python3 scripts/verify-integrity.py --all
python3 scripts/normalize-gitea-60004.py --check
python3 scripts/validate-gitea-60004-detections.py --allCleanup
labs/gitea/shared/scripts/lab.sh clean vulnerable --yes
labs/gitea/shared/scripts/lab.sh clean patched --yesLIMITATIONS & SAFETY
Scope stays explicit.
The lab does not claim independent reproduction of every vendor-reported version. It requires authorized defensive use, synthetic identity, and a bounded controlled proof.