logo

{JS-ON: Security-OFF}: Abusing JSON-Based SQL to Bypass WAF

ID: 0f9579a6-7d62-5dc2-99ff-fa3c61ffa850

STIX ID: report--0f9579a6-7d62-5dc2-99ff-fa3c61ffa850

Feed Name: Claroty Team82

Threat Score
70/100

Date Published: 2023-07-30

Date Updated: 2026-04-17

Author: Noam Moshe

...
...

Team82 details a novel, generic web application firewall (WAF) bypass that exploits mismatched JSON-in-SQL parsing between modern database engines and WAFs. By prepending or embedding JSON syntax in SQL injection payloads (using JSON operators/functions supported by PostgreSQL, MySQL, SQLite, etc.), attackers can evade detection by multiple major WAF products (Palo Alto, AWS, Cloudflare, F5, Imperva) and exfiltrate data; Team82 demonstrates payload construction, automation (SQLMap integration), and notes vendor fixes following disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.