{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "07d41c826eeaacbc16eff9f371b15542f1a2646fc6f34988f67209be3ef545be",
    "authored_runtime_manifest_sha256": "e10fbe5f4f640e9c3950f8e1fc383bfeec68fc86a96169e3740854fdbd4bec09",
    "authored_verdict_sha256": "fc06c410db20fab152091347f2bc3521a7ae8a202541df8a39f02f43133d6853",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "HTTPS Set-Cookie response header containing the literal bytes `sess=SECRET;\\x09Secure`",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "info_leak",
  "claimed_surface": "network_protocol",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "info_leak",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "HTTPS TCP response -> real curl CLI/libcurl cookie parser -> cookie jar -> plaintext HTTP TCP request to the same non-localhost host",
  "validated_surface": "network_protocol"
}
