← All labs

Gitea

CVE-2026-60004

CVE-2026-60004 Gitea diffpatch Git-hook installation

REPRODUCED LAB VALIDATED

OVERVIEW

Lab observed

Vulnerable1.27.0
Patched1.27.1

Vendor reported

Vendor-reported fixed versions

1.27.1

Only the lab versions above were independently reproduced by CVE Mapping.

LAB OBSERVED

What this lab demonstrates

The fixed marker appeared on 1.27.0 after one controlled request and remained absent on 1.27.1 after the equivalent request.

The vulnerable and patched modes used equivalent controlled actions. Application state—not a successful HTTP status alone—is decisive.

VULNERABLE VS PATCHED RESULT

VULNERABLE

Runtime accepted and the documented state difference was observed.

PATCHED CONTROL

Runtime accepted and the expected safe state was retained.

CI VALIDATED

Evidence, telemetry, and detection checks are recorded in the manifest.

DETECTION COVERAGE

Detection engineering

  • Sigma1 lab-validated analytic
  • Splunk1 lab-validated analytic
  • Elastic1 lab-validated analytic

Request telemetry provides context, while the strongest analytic requires correlated application-state telemetry. A request alone does not prove exploitation.

Lab queries

Sigma — gitea_diffpatch_request_attempt.yml lab-validated
title: Suspicious Gitea Repository Diffpatch API Request
id: d64bb6d2-ef14-4a39-9238-2f9ec0c2f341
status: test
description: Detects Gitea diffpatch API activity for investigation; this is request-attempt context and does not confirm successful CVE-2026-60004 exploitation.
references:
  - https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m
  - https://docs.gitea.com/api/operations/repo-apply-diff-patch/
author: CVE Mapping
date: "2026-08-27"
logsource:
  product: gitea
  service: normalized_http_request
detection:
  selection:
    event_type: http_request
    service: gitea
    method: POST
    path|re: ^/api/v1/repos/[^/]+/[^/]+/diffpatch$
  condition: selection
falsepositives:
  - Authorized patch application by administrators, CI/CD, repository automation, API clients, developer tools, scanners, security tests, or labs
level: medium

View on GitHub

Splunk — gitea_diffpatch_request_attempt.spl lab-validated
/*
CVE-2026-60004 suspicious Gitea diffpatch request-attempt analytic.
This request-only search does not confirm successful exploitation.
*/
event_type="http_request" service="gitea" method="POST"
| where match(path, "^/api/v1/repos/[^/]+/[^/]+/diffpatch$")
| eval analytic="gitea_diffpatch_request_attempt"

View on GitHub

Elastic — gitea_diffpatch_request_attempt.json lab-validated
{
  "name": "Suspicious Gitea repository diffpatch API request",
  "cve": "CVE-2026-60004",
  "type": "query",
  "language": "kuery",
  "query": "event_type:http_request and service:gitea and method:POST and path:/api/v1/repos/*/*/diffpatch",
  "severity": "medium",
  "risk_rationale": "Diffpatch activity is high-value investigation context on affected Gitea versions, but a request alone does not confirm successful exploitation.",
  "false_positive_note": "Authorized patch application by administrators, CI/CD, repository automation, API clients, developer tools, scanners, security tests, and labs can match.",
  "references": [
    "https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m",
    "https://docs.gitea.com/api/operations/repo-apply-diff-patch/"
  ],
  "fixture_discrimination": {"vulnerable": 1, "patched": 1, "benign": 0}
}

View on GitHub

FIXTURE DISCRIMINATION

Lab fixture performance

Validated state-change analytics matched vulnerable activity; 1 matched the patched control. See the detection validation record for discrimination notes. Contextual analytics are reported separately and are not promoted to vulnerability discriminators.

Validated state-change · Vulnerable1 matched
Validated state-change · Patched1 matched
Validated state-change · Benign0 matched
Contextual request · Vulnerable0 matched
Contextual request · Patched0 matched
Contextual request · Benign0 matched

EVIDENCE & TELEMETRY

Preserved and verifiable

Sanitized evidence and normalized telemetry are tracked by manifest and SHA-256 integrity files.

RISK CONTEXT

Vendor enrichment

Additional risk feeds are omitted without a verified current lookup.

MITRE ATT&CK
Unassigned

COPYABLE RUNBOOK

Start with the Quickstart.

Disposable, localhost-only runbook commands taken from the lab's QUICKSTART.md. Proof internals stay in the repository — these are the operator workflow commands.

Prerequisites
python3 scripts/validate-gitea-bootstrap.py --all
python3 scripts/validate-compose.py --all
labs/gitea/shared/scripts/lab.sh preflight
labs/gitea/shared/scripts/lab.sh prepare
Vulnerable Mode
labs/gitea/shared/scripts/lab.sh up vulnerable
labs/gitea/shared/scripts/lab.sh wait vulnerable
labs/gitea/shared/scripts/lab.sh init-baseline vulnerable
labs/gitea/shared/scripts/lab.sh init-prereqs vulnerable
labs/gitea/shared/scripts/lab.sh check-60004-prereqs vulnerable
python3 labs/gitea/CVE-2026-60004/poc/reproduce.py vulnerable
python3 labs/gitea/CVE-2026-60004/scripts/verify.py verify-mode vulnerable
labs/gitea/shared/scripts/lab.sh down vulnerable
labs/gitea/shared/scripts/lab.sh clean vulnerable --yes
Patched Control
labs/gitea/shared/scripts/lab.sh up patched
labs/gitea/shared/scripts/lab.sh wait patched
labs/gitea/shared/scripts/lab.sh init-baseline patched
labs/gitea/shared/scripts/lab.sh init-prereqs patched
labs/gitea/shared/scripts/lab.sh check-60004-prereqs patched
python3 labs/gitea/CVE-2026-60004/poc/reproduce.py patched
python3 labs/gitea/CVE-2026-60004/scripts/verify.py verify-mode patched
labs/gitea/shared/scripts/lab.sh down patched
labs/gitea/shared/scripts/lab.sh clean patched --yes
Inspect Evidence and Telemetry
python3 labs/gitea/CVE-2026-60004/scripts/verify.py compare
python3 scripts/verify-integrity.py --all
python3 scripts/normalize-gitea-60004.py --check
python3 scripts/validate-gitea-60004-detections.py --all
Cleanup
labs/gitea/shared/scripts/lab.sh clean vulnerable --yes
labs/gitea/shared/scripts/lab.sh clean patched --yes

LIMITATIONS & SAFETY

Scope stays explicit.

The lab does not claim independent reproduction of every vendor-reported version. It requires authorized defensive use, synthetic identity, and a bounded controlled proof.