REPRODUCIBLE CVE RESEARCH

Turning CVEs into reproducible defensive security labs.

CVE Mapping connects vendor claims to observable application state, normalized telemetry, detection engineering, and repeatable validation.

ReproduceObserveDetectValidate

CATALOG

Published labs

1 published lab
PUBLISHED LAB VALIDATED
GitLab

CVE-2026-19650

CVE-2026-19650 GitLab GraphQL multiplex GET handling

Vulnerable19.2.2-ee.0Observed state change
Patched19.2.4-ee.0Control blocked state change
Validation
  • ✓ Runtime validated
  • ✓ CI validated
  • ✓ Patched control verified
Detection coverage

Sigma · Splunk · Elastic · osquery

METHOD

Evidence before assertion.

A compact research model keeps each observation scoped, comparable, and reproducible.

  1. 01

    Reproduce

    Run the disposable vulnerable and patched controls locally.

  2. 02

    Observe

    Correlate application state, evidence boundaries, and normalized telemetry.

  3. 03

    Detect

    Exercise detection content against the preserved telemetry fixtures.

  4. 04

    Validate

    Record the differential result and keep CI checks repeatable.

SAFETY

Authorized defensive research only.

Labs use disposable systems and localhost-only vulnerable services. CVE Mapping does not host vulnerable instances. Use only synthetic/local credentials and test systems you own or are explicitly authorized to assess.

SEPARATE TRACK

Experimental / historical research

CVE-2026-19478 is retained as experimental research. It is not a published lab and does not carry the validation status shown in the catalog above.

View repository research