{
  "claim_outcome": "confirmed",
  "repro_result": "confirmed",
  "evidence_scope": "production_path",
  "observed_impact_class": "code_execution",
  "claimed_impact_class": "code_execution",
  "exploitability_confidence": "high",
  "attacker_controlled_input": "crafted HTTP/TCP requests from separate Docker network attacker containers to NGINX listeners 19321 and 19331",
  "trigger_path": "GET /leak... disclosure, POST /spray heap shaping, crafted GET /api/<percent-encoded URI> overflow, victim connection close, GET /rce-proof marker retrieval",
  "claimed_surface": "network_protocol",
  "validated_surface": "network_protocol",
  "end_to_end_target_reached": true,
  "sanitizer_used": false,
  "crash_observed": false,
  "read_write_primitive_observed": true,
  "exploit_chain_demonstrated": true,
  "verdict_origin": "reported",
  "accepted_exploit_knowledge_record_ids": [
    "fb7a0dd6-d382-4715-806a-42b35bafa7e5",
    "54f292a8-e50f-4b6a-92f7-470f471ba52f",
    "75c612dd-1cda-4aa3-9941-55bd11643159"
  ],
  "inferred": false
}
