EDEFuzz: A Web API Fuzzer for Excessive Data Exposures
Lianglu Pan, Shaanan Cohney, Toby Murray, Van-Thuan Pham
Abstract
APIs often transmit far more data to client applications than they need, and in the context of web applications, often do so over public channels. This issue, termed Excessive Data Exposure (EDE), was OWASP's third most significant API vulnerability of 2019. However, there are few automated tools-either in research or industry-to effectively find and remediate such issues. This is unsurprising as the problem lacks an explicit test oracle: the vulnerability does not manifest through explicit abnormal behaviours (e.g., program crashes or memory access violations). In this work, we develop a metamorphic relation to tackle that challenge and build the first fuzzing tool-that we call EDEFuzz-to systematically detect EDEs. EDEFuzz can significantly reduce false negatives that occur during manual inspection and ad-hoc text-matching techniques, the current most-used approaches. We tested EDEFuzz against the sixty-nine applicable targets from the Alexa Top-200 and found 33,365 potential leaks-illustrating our tool's broad applicability and scalability. In a more-tightly controlled experiment of eight popular websites in Australia, EDEFuzz achieved a high true positive rate of 98.65% with minimal configuration, illustrating our tool's accuracy and efficiency.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2e9d044a-67e3-475f-bce4-9ff1baadd308Cited by top-tier papers6
- Anota: Identifying Business Logic Vulnerabilities via Annotation-Based SanitizationMeng Wang, Philipp Görz, Joschua Schilling, Keno Hassler et al.NDSS 2026 · 4 citations
- Are Your Requests Your True Needs? Checking Excessive Data Collection in VPA AppFuman Xie, Chuan Yan, Mark Huasong Meng, Shao-Ming Teng et al.ICSE 2024 · 4 citations
- SATORI: Static Test Oracle Generation for REST APIsJuan C. Alonso, Alberto Martin-Lopez, Sergio Segura, Gabriele Bavota et al.ASE 2025 · 2 citations
- Peeling Off the Cocoon: Unveiling Suppressed Golden Seeds for Mutational Greybox FuzzingRuixiang Qian, Chunrong Fang, Zengxu Chen, Youxin Fu et al.OOPSLA 2026
- The Tragedy of Convenience: Cascading User-Data Leakage from SMS-delivered URLsMuhammad Danish, Enrique Sobrados, Priya Kaushik, Bhupendra Acharya et al.CCS 2026
Builds on5
- Testing Database Engines via Pivoted Query SynthesisManuel Rigger, Zhendong SuOSDI 2020 · 150 citations
- Nyx-net: network fuzzing with incremental snapshotsSergej Schumilo, Cornelius Aschermann, Andrea Jemmett, Ali Abbasi et al.EuroSys 2022 · 76 citations
- Testing Machine Translation via Referential TransparencyPinjia He, Clara Meister, Zhendong SuICSE 2021 · 50 citations
- WebEvo: taming web application evolution via detecting semantic structure changesFei Shao, Rui Xu, Wasif Arman Haque, Jingwei Xu et al.ISSTA 2021 · 11 citations
- Toss a Fault to Your Witcher: Applying Grey-box Coverage-Guided Mutational Fuzzing to Detect SQL and Command Injection VulnerabilitiesErik Trickel, Fabio Pagani, Chang Zhu, Lukas Dresel et al.S&P 2023
Related papers
- Mockingbird: Efficient Excessive Data Exposures Detection via Dynamic Code InstrumentationChenxiao Xia, Jiazheng Sun, Jun Zheng, Yu-an Tan et al.ASE 2025
- Minerva: browser API fuzzing with dynamic mod-ref analysisChijin Zhou, Quan Zhang, Mingzhe Wang, Lihua Guo et al.FSE 2022 · 20 citations
- Atropos: Effective Fuzzing of Web Applications for Server-Side VulnerabilitiesEmre Güler, Sergej Schumilo, Moritz Schloegel, Nils Bars et al.USENIX Security 2024 · 45 citations
- Auspex: Unveiling Inconsistency Bugs of Transaction Fee Mechanism in BlockchainZheyuan He, Zihao Li, Jiahao Luo, Feng Luo et al.USENIX Security 2025
- No Harness, No Problem: Oracle-guided Harnessing for Auto-generating C API Fuzzing HarnessesGabriel Sherman, Stefan NagyICSE 2025 · 1 citation
