Jazzer: Coverage-Guided Fuzzing for Semantic Vulnerabilities in the Java Ecosystem
Sergej Dechand, Tobias Wienand, Fabian Meumertzheim, Peter Samarin, Simon Resch, Khaled Yakdan, Thorsten Holz, Flavio Toffalini
Abstract
Fuzz testing has proven highly effective in uncovering software faults in low-level languages such as C and C++. Yet, memory-safe ecosystems like the Java Virtual Machine (JVM), which powers the majority of enterprise applications, have received limited attention from fuzzing research. Recent high-impact vulnerabilities such as Log4Shell and Spring4Shell highlight that memory-safe languages remain susceptible to severe security risks, including logic errors, injection vulnerabilities, and unsafe deserialization. Such vulnerability classes typically lie beyond the detection capabilities of traditional fuzzing frameworks, which are primarily designed to detect memory safety violations. In this paper, we address this gap with Jazzer11https://github.com/CodeIntelligenceTesting/jazzer, a fuzzing framework specifically designed for JVM applications. Jazzer adapts proven fuzzing techniques to the JVM via bytecode instrumentation, translating Java's high-level constructs into low-level coverage and trace feedback. To detect vulnerabilities beyond memory corruption, it complements C/C++ sanitizers with guiding oracles that hook into JVM APIs and provide guidance within sinks to uncover Java-specific vulnerabilities. Our comprehensive evaluation against JQF, the state-of-theart Java fuzzer, shows that Jazzer achieves higher coverage and faster execution speed across eleven diverse libraries, while discovering 18 bugs missed by prior work. Finally, we demonstrate real-world impact through large-scale deployment in OSS-Fuzz, where Jazzer has continuously fuzzed 205 opensource Java projects over a period of three years. This field study resulted in the discovery of 1217 confirmed and fixed security issues.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 6003daa2-9989-437f-8ee5-dd08e8b9ba14Related papers
- Detecting JVM JIT Compiler Bugs via Exploring Two-Dimensional Input SpacesHaoxiang Jia, Ming Wen, Zifan Xie, Xiaochen Guo et al.ICSE 2023 · 21 citations
- Contextualizing Sink Knowledge for Java Vulnerability DiscoveryFabian Fleischer, Cen Zhang, Joonun Jang, Jeongin Cho et al.S&P 2026 · 2 citations
- JITfuzz: Coverage-guided Fuzzing for JVM Just-in-Time CompilersMingyuan Wu, Minghai Lu, Heming Cui, Junjie Chen et al.ICSE 2023 · 36 citations
- SJFuzz: Seed and Mutator Scheduling for JVM FuzzingMingyuan Wu, Yicheng Ouyang, Minghai Lu, Junjie Chen et al.FSE 2023 · 14 citations
- Beyond the Surface: Towards Feature-Driven Fuzzing on the Chrome BrowserChaoyuan Peng, Muhui Jiang, Yajin Zhou, Lei WuISSTA 2026
