Scalable fuzzing infrastructure.
ClusterFuzz is a scalable fuzzing infrastructure that finds security and stability issues in software.
Google uses ClusterFuzz to fuzz all Google products and as the fuzzing backend for OSS-Fuzz.
ClusterFuzz provides many features which help seamlessly integrate fuzzing into a software project's development process:
You can find detailed documentation here.
As of February 2023, ClusterFuzz has found ~27,000 bugs in Google (e.g. Chrome). Additionally, ClusterFuzz has helped identify and fix over 8,900 vulnerabilities and 28,000 bugs across 850 projects integrated with OSS-Fuzz.
You can file an issue to ask questions, request features, or ask for help.
We will use clusterfuzz-announce(#)googlegroups.com to make announcements about ClusterFuzz.
For a more lightweight version of ClusterFuzz that runs on CI/CD systems, check out ClusterFuzzLite.