Skip to content

Repository files navigation

Awesome Fuzzing Awesome

Fuzzing or fuzz testing is an automated software testing technique that involves providing invalid, unexpected, or random data as inputs to a computer program. The program is then monitored for exceptions such as crashes, failing built-in code assertions, or potential memory leaks. Typically, fuzzers are used to test programs that take structured inputs.

A curated list of references to awesome Fuzzing for security testing. Additionally there is a collection of freely available academic papers, tools and so on.

Your favorite tool or your own paper is not listed? Fork and create a Pull Request to add it!

Contents

Books

Talks

Papers

To achieve a well-defined scope, I have chosen to include publications on fuzzing from 4 top major security conferences (2008–2026): (i) Network and Distributed System Security Symposium (NDSS), (ii) IEEE Symposium on Security and Privacy (S&P), (iii) USENIX Security Symposium (USEC), and (iv) ACM Conference on Computer and Communications Security (CCS).

Note: Papers are selected based on whether the title contains the keyword "fuzz." If a paper is related to fuzzing but does not include "fuzz" in its title, it may have been missed. In that case, please open a Pull Request and it will be reviewed for inclusion.

The Network and Distributed System Security Symposium (NDSS)

2026 (13 papers)
2025 (10 papers)
2024 (7 papers)
2023 (4 papers)
2022 (4 papers)
2021 (4 papers)
2020 (4 papers)
2019 (5 papers)
2018 (4 papers)
2017 (2 papers)
2016 (1 paper)
2008 (1 paper)

IEEE Symposium on Security and Privacy (IEEE S&P)

2026 (14 papers)
2025 (7 papers)
2024 (14 papers)
2023 (10 papers)
2022 (5 papers)
2021 (5 papers)
2020 (5 papers)
2019 (4 papers)
2018 (3 papers)
2017 (1 paper)
2015 (1 paper)
2010 (1 paper)

USENIX Security

2026 (4 papers)
2025 (15 papers)
2024 (12 papers)
2023 (19 papers)
2022 (14 papers)
2021 (6 papers)
2020 (10 papers)
2019 (2 papers)
2018 (3 papers)
2017 (2 papers)
2015 (1 paper)
2014 (1 paper)
2013 (1 paper)
2012 (1 paper)

ACM Conference on Computer and Communications Security (ACM CCS)

2025 (11 papers)
2024 (19 papers)
2023 (9 papers)
2022 (6 papers)
2021 (8 papers)
2020 (1 paper)
2019 (3 papers)
2018 (2 papers)
2017 (7 papers)
2016 (3 papers)
2013 (2 papers)
2012 (1 paper)
2008-2009 (2 papers)

ArXiv (Fuzzing with Artificial Intelligence & Machine Learning)

The others

Tools

A curated collection of open-source fuzzing tools, grouped by their primary testing target. Each tool appears in one category; its description identifies the relevant interfaces and techniques. Tools are selected for research relevance, availability of official implementations, and documented capabilities.

File

  • G2FUZZ (2025) - An AFL++-based fuzzer that uses LLMs to synthesize and mutate input generators for grammar-aware fuzzing of non-textual formats.
  • LibAFL (2022) - A Rust framework for building custom fuzzers from reusable components, with support for multiple platforms and scaling across cores and machines.
  • WINNIE (2021) - A Windows application fuzzer that combines harness synthesis with fast process cloning to test code beyond graphical interfaces.
  • AFL++ (2019) - A superior fork to Google's AFL with more speed, more and better mutations, more and better instrumentation, and custom module support.
  • MOpt-AFL (2019) - An AFL-based fuzzer that uses particle swarm optimization to adapt mutation operator selection probabilities for more effective fuzzing.
  • REDQUEEN (2019) - A binary fuzzer that uses input-to-state correspondence to overcome magic bytes and checksums without symbolic execution.
  • Angora (2018) - A mutation-based coverage guided fuzzer that increases branch coverage by solving path constraints without symbolic execution.
  • InsTrim (2018) - A lightweight instrumentation approach for AFL that uses control-flow analysis to reduce the number of instrumented basic blocks while preserving execution path distinguishability.
  • QSYM (2018) - A concolic execution engine designed for hybrid fuzzing that works with AFL to generate inputs for new execution paths.
  • AFLGo (2017) - An AFL-based directed greybox fuzzer that generates inputs to reach specified target locations in a program.
  • VUzzer (2017) - An application-aware binary fuzzer that uses static analysis and dynamic taint analysis to guide input mutations, with a 64-bit implementation.
  • AFLFast (2016) - An AFL-based greybox fuzzer that uses power schedules to focus fuzzing effort on low-frequency execution paths.
  • Driller (2016) - A hybrid fuzzer that augments AFL with selective symbolic execution using angr to generate inputs for paths that fuzzing cannot reach.
  • AFL (2014) - A coverage-guided fuzzer that uses instrumentation and genetic mutations to discover bugs. Its GitHub repository is archived; AFL++ is recommended for new projects.
  • Valgrind (2000) - A dynamic analysis framework with tools for detecting memory management and threading errors and profiling program execution.

Kernel

  • Moneta (2025) - A GPU driver fuzzer that recalls execution states captured on real hardware for ex-vivo fuzzing.
  • SyzSpec (2025) - A specification generator for Linux kernel fuzzing that uses under-constrained symbolic execution to infer syscall interfaces.
  • CountDown (2024) - A kernel fuzzer that uses shared reference counts to guide syscall sequences toward use-after-free bugs.
  • MOCK (2024) - A Linux kernel fuzzer that learns contextual dependencies between syscalls to generate context-aware test cases.
  • SyzTrust (2024) - An on-device fuzzer for IoT trusted operating systems that uses state and branch coverage to guide input generation.
  • VirtFuzz (2024) - A LibAFL-based Linux kernel fuzzer that injects inputs through VirtIO devices to test wireless stacks.
  • ACTOR (2023) - An action-guided kernel fuzzing framework that generates inputs leveraging triggered actions and their temporal relationships.
  • FuzzNG (2023) - A Linux kernel syscall fuzzer designed to minimize reliance on manually written system call descriptions.
  • KextFuzz (2023) - A fuzzing prototype for macOS kernel extensions on Apple Silicon that instruments extensions and patches entitlement checks.
  • SegFuzz (2023) - A kernel concurrency fuzzer that uses interleaving segment coverage and mutation-based thread scheduling to discover bugs.
  • SyzDirect (2023) - A directed greybox fuzzer for reaching target locations in the Linux kernel.
  • DR.FUZZ (2022) - A semantic-informed driver fuzzer that tests Linux device drivers without their hardware devices or device emulators.
  • Drifuzz (2022) - A hardware-free device driver fuzzer that combines concolic execution with high-quality initial seed generation.
  • FuzzUSB (2022) - A hybrid stateful fuzzing framework for USB gadget stacks in the Linux kernel.
  • StateFuzz (2022) - A Linux driver fuzzer that identifies state variables through static analysis and uses their values as fuzzing feedback.
  • NTFuzz (2021) - A type-aware Windows kernel fuzzer that statically analyzes system binaries to infer system call types for more effective fuzzing.
  • SyzGen (2021) - A syscall specification generator that analyzes closed-source macOS drivers to enable interface-aware fuzzing.
  • KRACE (2020) - A coverage-guided fuzzing framework that detects data races in kernel file systems by exploring concurrency through multi-threaded syscall sequences.
  • PeriScope (2019) - A probing and fuzzing framework that tests device drivers at the hardware-OS boundary through MMIO and DMA inputs.
  • Razzer (2019) - A kernel fuzzer that uses static analysis and two-phase fuzzing to detect race conditions and concurrency bugs in Linux kernels.
  • Hydra (2019) - A fuzzing framework for automatically discovering semantic bugs in file systems using input mutators, feedback engines, and customizable checkers.
  • Janus (2019) - A file system fuzzer that finds memory corruptions in Linux kernel file systems by mutating both filesystem images and syscall sequences simultaneously.
  • DIFUZE (2017) - An interface-aware fuzzer for Linux kernel drivers that automatically recovers ioctl interfaces via LLVM analysis and generates targeted test cases.
  • IMF (2017) - A kernel API fuzzer that leverages automated API model inference to discover vulnerabilities in macOS kernel APIs.
  • kAFL (2017) - A hardware-assisted x86-64 VM kernel fuzzing framework with performant VM reloads for finding OS kernel vulnerabilities.
  • syzkaller (2015) - An unsupervised coverage-guided kernel fuzzer supporting FreeBSD, Fuchsia, gVisor, Linux, NetBSD, OpenBSD, and Windows.
  • Trinity (2012) - A Linux system call fuzzer that generates semi-intelligent random arguments to syscalls, including valid file descriptors, flags, and range-biased values.

Libraries & APIs

  • Hopper (2023) - A library fuzzer that interprets generated API calls and learns argument constraints without requiring manually written fuzz drivers.
  • IvySyn - A fully-automated framework for discovering memory error vulnerabilities in Deep Learning (DL) frameworks.
  • GraphFuzz - An experimental framework for building structure-aware, library API fuzzers.

Network & Protocols

  • ChatAFL (2024) - An AFLNet-based protocol fuzzer that uses LLMs to infer message grammars, enrich seeds, and generate messages that explore new protocol states.
  • ResolverFuzz (2024) - A DNS fuzzer that combines query-response generation with differential analysis to detect non-crash vulnerabilities in resolvers.
  • SGFuzz (2022) - A libFuzzer-based fuzzer that adds state-transition feedback to explore stateful software, including network protocol implementations.

Web Applications & APIs

  • WuppieFuzz - A coverage-guided REST API fuzzer developed on top of LibAFL.
  • MINER - A REST API fuzzer that utilizes three data-driven designs working together to guide sequence generation, improve request generation quality, and capture unique errors caused by incorrect parameter usage.
  • RestTestGen - A robust tool and framework designed for automated black-box testing of RESTful web APIs.
  • TEFuzz - A tailored fuzzing-based framework to facilitate the detection and exploitation of template escape bugs.
  • Witcher - A web application fuzzer that utilizes mutational fuzzing to explore web applications and fault escalation to detect command and SQL injection vulnerabilities.

Browsers

  • FuzzOrigin (2022) - A browser fuzzer that tests origin handling to discover universal cross-site scripting vulnerabilities.
  • CorbFuzz (2021) - A browser security policy testing framework that synthesizes web application responses to test cross-origin response blocking implementations.
  • FreeDom (2020) - A DOM fuzzer that generates HTML documents and DOM interactions to discover browser vulnerabilities.

Compilers & Language Runtimes

  • RGFuzz (2025) - A WebAssembly runtime fuzzer that uses compiler rules to guide test generation and compares execution results across runtimes and architectures.
  • FuzzJIT (2023) - A Fuzzilli-based JavaScript engine fuzzer that uses an oracle to detect incorrect behavior introduced by JIT compilation.
  • CodeAlchemist (2019) - A JavaScript engine fuzzer that assembles code fragments while respecting semantic constraints to generate valid test programs.

Firmware & Embedded Systems

  • Hoedur (2023) - An embedded firmware fuzzer that uses multiple input streams to represent interactions with different hardware interfaces.
  • Fuzzware (2022) - A firmware fuzzer that models memory-mapped I/O accesses to test microcontroller firmware without full peripheral emulation.
  • FIRM-AFL (2019) - An IoT firmware fuzzer that combines user-mode and system-mode emulation to improve fuzzing throughput for POSIX-compatible firmware.

Hypervisors & Virtual Devices

  • HyperPill (2024) - A hypervisor fuzzer that uses the hardware virtualization interface to exercise hypervisor behavior without hypervisor-specific input grammars.
  • ViDeZZo (2023) - A virtual device fuzzing framework that models dependencies within and between messages to test devices in QEMU and VirtualBox.
  • V-SHUTTLE (2021) - An AFL-based fuzzer for virtual devices in hosted hypervisors, with semantics-aware input generation.

Hardware & Microarchitecture

  • DifuzzRTL - A differential fuzz testing approach for CPU verification.
  • MorFuzz - A generic RISC-V processor fuzzing framework that can efficiently detect software triggerable functional bugs.
  • SpecFuzz - A tool that exposes speculative execution paths through software instrumentation so fuzzers can detect Spectre-type vulnerabilities in programs.
  • Transynther - Automatically generates and tests building blocks for Meltdown attacks with various faults and microcode assists.

Android & Mobile Systems

  • AHA-Fuzz (2025) - An intent-aware greybox fuzzer that uses eBPF-based analysis to test hardened Android applications.
  • MALintent (2025) - A coverage-guided Android fuzzer that generates and mutates intents to test application intent receivers.
  • FANS - A fuzzing tool for Android native system services with four components: interface collector, interface model extractor, dependency inferer, and fuzzer engine.

Blockchain & Smart Contracts

  • Fluffy - A multi-transaction differential fuzzer for finding consensus bugs in Ethereum.
  • LOKI - A Blockchain consensus protocol fuzzing framework that detects consensus memory related and logic bugs.
  • ILF (2019) - An Ethereum smart contract fuzzer that learns a transaction-generation policy from symbolic execution through imitation learning.

DBMS

  • BuzzBee (2024) - A DBMS fuzzer that uses semantic abstraction, context-sensitive constraints, and dependency-guided mutations to generate database queries.
  • SQLRight (2022) - A DBMS fuzzer that combines coverage feedback, validity-oriented query mutations, and result-checking oracles to detect logical bugs.
  • Squirrel - A fuzzer for database management systems (DBMSs).

Contributing

Contributions welcome! Read the contribution guidelines first.

About

A curated list of awesome Fuzzing(or Fuzz Testing) for software security

Topics

Resources

Code of conduct

Contributing

Stars

997 stars

Watchers

46 watching

Forks

Releases

Packages

Used by

Contributors

Languages