Pentagrid reported that testing of Ergon's Airlock Web Application Firewall against portions of the OWASP Core Rule Set (CRS) regression suite found numerous payloads that Airlock allowed while CRS would normally block, spanning scanner detection, protocol enforcement, file inclusion, remote code execution, PHP injection, generic application attacks, SQL injection, and Java-related attack strings. The researchers also identified a PHP short-tag payload that bypassed both Airlock and CRS; after disclosure, CRS closed that detection gap, while Airlock still allowed the payload in the tested mid-2024 configuration and Ergon opened internal tickets to review the findings.
A second bypass highlighted a broader weakness in XML parsing: XSS payloads hidden in XML attribute values were not inspected by several CRS rules because they checked XML:/* text nodes but not XML://@* attributes. That gap aligns with CVE-2022-3442, a reflected XSS flaw Pentagrid disclosed in CREALOGIX's ebics.aspx endpoint, where attacker-controlled input in the EBICS Version field could be reflected into an HTML error response. CRS maintainers later fixed the XML-attribute false negative in v4.28.0 under GHSA-6jp8-c2w2-x7wr by extending coverage to XML attributes and adding regression tests, while CREALOGIX had already released patches and advised customers to update to version 7.1 or apply vendor fixes.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Pentagrid performed a white-box assessment of Ergon's Airlock WAF using parts of the OWASP CRS regression suite and found numerous payloads that Airlock allowed in the examined mid-2024 configuration across categories including SQL injection, RCE, file inclusion, scanner detection, and XSS-related cases. The testing also identified a PHP short-tag bypass affecting both Airlock and CRS, plus an XML-attribute XSS bypass affecting Airlock.
A GitHub issue documented that OWASP Core Rule Set rules failed to detect XSS payloads placed in XML attribute values because affected rules inspected XML text nodes but not attributes. The report showed the bypass worked across multiple rule families and at any paranoia level.
Pentagrid disclosed CVE-2022-3442 affecting CREALOGIX AG's EBICS banking server implementation at the ebics.aspx endpoint. CREALOGIX fixed the issue, released patched software, and advised customers to update to version 7.1 or apply provided patches.
In July 2026, maintainers said the XML attribute false negative was fixed in CRS main as of v4.28.0 via the security fix for GHSA-6jp8-c2w2-x7wr. The change added XML attribute inspection across multiple rule families and regression tests, causing the original proof of concept to be blocked.
Following discussions of Pentagrid's findings, Ergon opened internal tickets related to the identified Airlock WAF issues. The article presents this as the vendor's response to the reported bypasses.
After Pentagrid disclosed a PHP short-tag payload that bypassed both Airlock and CRS, OWASP CRS fixed its detection gap. In the tested Airlock setup described by Pentagrid, the same payload was still allowed.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
pentagrid.ch
Open sourcegithub.com
Open sourcepentagrid.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.