No Strings Attached: An Empirical Study of String-related Software Bugs
Aryaz Eghbali, Michael Pradel
Abstract
Strings play many roles in programming because they often contain complex and semantically rich information. For example, programmers use strings to filter inputs via regular expression matching, to express the names of program elements accessed through some form of reflection, to embed code written in another formal language, and to assemble textual output produced by a program. The omnipresence of strings leads to a wide range of mistakes that developers may make, yet little is currently known about these mistakes. The lack of knowledge about string-related bugs leads to developers repeating the same mistakes again and again, and to poor support for finding and fixing such bugs. This paper presents the first empirical study of the root causes, consequences, and other properties of string-related bugs. We systematically study 204 string-related bugs in a diverse set of projects written in JavaScript, a language where strings play a particularly important role. Our findings include (i) that many string-related mistakes are caused by a recurring set of root cause patterns, such as incorrect string literals and regular expressions, (ii) that string-related bugs have a diverse set of consequences, including incorrect output or silent omission of expected behavior, (iii) that fixing string-related bugs often requires changing just a single line, with many of the required repair ingredients available in the surrounding code, (iv) that stringrelated bugs occur across all parts of applications, including the core components, and (v) that almost none of these bugs are detected by existing static analyzers. Our findings not only show the importance and prevalence of string-related bugs, but they help developers to avoid common mistakes and tool builders to tackle the challenge of finding and fixing string-related bugs. CCS CONCEPTS • Software and its engineering → Software defect analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dfacd99c-e6e2-46a3-a11b-95dd80cf3673Cited by top-tier papers7
- Bugs in Quantum computing platforms: an empirical studyMatteo Paltenghi, Michael PradelOOPSLA 2022 · 70 citations
- Semantic bug seeding: a learning-based approach for creating realistic bugsJibesh Patra, Michael PradelFSE 2021 · 63 citations
- Exploiting Input Sanitization for Regex Denial of ServiceEfe Barlas, Xin Du, James C. DavisICSE 2022 · 16 citations
- When Your Infrastructure Is a Buggy Program: Understanding Faults in Infrastructure as Code EcosystemsGeorgios-Petros Drosos, Thodoris Sotiropoulos, Georgios Alexopoulos, Dimitris Mitropoulos et al.OOPSLA 2024 · 14 citations
- Inline TestsYu Liu, Pengyu Nie, Owolabi Legunsen, Milos GligoricASE 2022 · 10 citations
Builds on1
Related papers
- Well-typed programs can go wrong: a study of typing-related bugs in JVM compilersStefanos Chaliasos, Thodoris Sotiropoulos, Georgios-Petros Drosos, Charalambos Mitropoulos et al.OOPSLA 2021 · 31 citations
- Characterizing Regression Bug‑Inducing Changes and Improving LLM‑Based Regression Bug DetectionXuezhi Song, Yijian Wu, Bihuan Chen, Zhengjie Lu et al.ICSE 2026
- Riding out DOMsday: Towards Detecting and Preventing DOM Cross-Site ScriptingWilliam Melicher, Anupam Das, Mahmood Sharif, Lujo Bauer et al.NDSS 2018 · 84 citations
- Do bugs lead to unnaturalness of source code?Yanjie Jiang, Hui Liu, Yuxia Zhang, Weixing Ji et al.FSE 2022 · 8 citations
- Dissecting Real-World Cross-Language BugsHaoran Yang, Haipeng CaiFSE 2025 · 2 citations
