{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "f90f8dc10738df6ba9877b31497fedf915b69962387e3016e65fa0c2eeeb2a37",
    "authored_runtime_manifest_sha256": "0f77bb563ac8d6fb1504aee8aca163793c79a8e72447b9f42ba64c39280d8836",
    "authored_verdict_sha256": "eaaeea90b7d6e497692188442757a9cb63479d6f51eb490c5dfdb1aea9b558bf",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "0ada138e-e91d-4aa4-b2e4-7f21bfb2fb08"
  ],
  "attacker_controlled_input": "HTTPS origin certificate accepted only through native system trust, followed by a request whose explicit custom CA policy should reject it",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "authz_bypass",
  "claimed_surface": "library_api",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "realistic_harness",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "authz_bypass",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "curl_multi API sequential same-origin transfers -> connection cache match -> reused TLS connection despite different effective native_ca_store policy",
  "validated_surface": "library_api"
}
