{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "feed718dc145c4f337311f42559cfc8740bc109e89366d65879c18de3d19d739",
    "authored_runtime_manifest_sha256": "0aafc3fe63cfb3dc93a2a6fead591459a776d3002a4de03199ae03a1e0a6ce39",
    "authored_verdict_sha256": "d3ae650f5636a5aab48c96147a03fd318377a70f6ac40916129919fa109a9c6e",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "HTTP/1.1 POST with Transfer-Encoding: chunked; headers (ending CRLFCRLF) in one TCP write, then a separate TCP write with non-hex chunk-size line 'ZZZ\\r\\n', socket held open with no further bytes",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "dos",
  "claimed_surface": "network_protocol",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "dos",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "inets httpd TCP listener -> httpd_manager accept -> httpd_request_handler handle_info({tcp,...}) bare-catch decoder continuation -> error tuple stored as NewMFA -> socket re-armed {active,once} with no timeout -> worker parked indefinitely; repeated across >max_clients (150) connections -> 503 heavy-load denial for legitimate clients",
  "validated_surface": "network_protocol"
}
