{
  "artifact_sha256": {
    "repro/fixed-attempt-1.log": "b30e5a532dc4390fb7b122b44d2a5aba4128e46a457e5e8870601f34a3ba6b29",
    "repro/fixed-attempt-2.log": "c5afc0185862af91e1b0f899fcdea3cb4098635dae13fe95a886509477807201",
    "repro/target-identity.log": "9b2d64973b3600d6852c952279942e6e51c36e7a84f71e7a88f18269658c8488",
    "repro/vulnerable-attempt-1.log": "e995fcb7f7e5422788e3fc188312333fc71aa3bfd1b01c9d57d0586a9bfdfafd",
    "repro/vulnerable-attempt-2.log": "ba0967b31d8a4e8657df1bdb6b7fd788529a2524cb3d7cba0f5c2865a681edc8"
  },
  "entrypoint_detail": "Real curl CLI uses --resolve to connect tab-cookie.invalid to a local HTTPS TCP peer that sends Set-Cookie sess=SECRET;<TAB>Secure, then to a plaintext HTTP TCP peer that captures the subsequent request",
  "entrypoint_kind": "tcp_peer",
  "healthcheck_passed": true,
  "notes": "Two clean vulnerable product attempts disclosed the Secure-intended cookie over plaintext HTTP; two fixed-commit product attempts retained Secure and omitted the cookie. No sanitizer was used.",
  "proof_artifacts": [
    "repro/vulnerable-attempt-1.log",
    "repro/vulnerable-attempt-2.log",
    "repro/fixed-attempt-1.log",
    "repro/fixed-attempt-2.log",
    "repro/target-identity.log"
  ],
  "runtime_stack": [
    "curl command-line product",
    "libcurl HTTP cookie parser",
    "OpenSSL TLS",
    "Python TCP/TLS peer"
  ],
  "service_started": true,
  "target_identity": {
    "architecture": "x86_64",
    "commit_sha": "621e507300e6c83966567b6ae0352ca82544df13",
    "platform": "linux",
    "repository_url": "https://github.com/curl/curl",
    "target_digest": "99769c35eb8a8ef5d8c6f984733cb9a16c536698292048e4b4ef2b6fe755f495"
  },
  "target_path_reached": true
}
