{
  "claim_outcome": "confirmed",
  "claim_block_reason": null,
  "repro_result": "confirmed",
  "validated_surface": "network_protocol",
  "evidence_scope": "production_path",
  "claimed_impact_class": "code_execution",
  "observed_impact_class": "code_execution",
  "exploitability_confidence": "high",
  "attacker_controlled_input": "One exact serialized Log4jLogEvent.LogEventProxy byte stream whose MarshalledObject contains a Commons Collections CC6 Runtime.exec graph, replayed over unauthenticated TCP to vulnerable and patched receivers (payload SHA-256 recorded in logs/payload_identity.txt).",
  "trigger_path": "Apache logging-log4j-samples TcpSocketServer.SocketHandler accepts TCP -> ObjectInputStreamLogEventBridge.wrapStream -> FilteredObjectInputStream(socket.getInputStream()).readObject -> Log4jLogEvent.LogEventProxy.readResolve/message -> MarshalledObject.get -> inner ObjectInputStream -> CC6 Runtime.exec.",
  "end_to_end_target_reached": true,
  "sanitizer_used": false,
  "crash_observed": false,
  "read_write_primitive_observed": false,
  "exploit_chain_demonstrated": true,
  "blocking_mitigation": null,
  "inferred": false
}
