cargo-fuzz is a free, open-source Cargo subcommand for fuzzing Rust code with libFuzzer. It invokes the fuzzer rather than supplying one itself. To get started, `cargo fuzz init` creates fuzzing files for a crate, while `cargo fuzz add <target>` creates a target and `cargo fuzz run <target>` runs it to look for bugs. The tool can reduce a failing input or a corpus of inputs, and version 0.10.0 or newer can produce source-based coverage information. Its documentation includes structure-aware fuzzing and a GitHub Actions workflow for building and running targets in CI. Listed systems include x86-64 Linux, x86-64 and Apple-Silicon macOS, and Windows with LLVM sanitizer support; Windows programs can also use MSVC AddressSanitizer. The project requires the nightly Rust compiler because it uses a `-Z` compiler flag for address sanitization, as well as a C++ compiler with C++11 support. It is distributed under the MIT and Apache 2.0 licenses.
Who it is for
It suits Rust developers who want to fuzz crate targets locally or include fuzz runs in GitHub Actions. Users need a nightly Rust compiler and a C++11-capable compiler.
What is good
- Free and open source under MIT and Apache 2.0.
- Commands create projects, targets, and run fuzzing.
- Can minimize failing inputs and input corpora.
- Coverage information is available from version 0.10.0 onward.
- Documentation includes a GitHub Actions workflow.
What to know first
- Requires the nightly Rust compiler.
- Requires a C++ compiler with C++11 support.
- Coverage requires cargo-fuzz version 0.10.0 or newer.
Verdict
cargo-fuzz provides Rust projects with commands for fuzz-target setup, execution, input minimization, and coverage. Check the compiler and platform requirements before using it.
cargo-fuzz plans and pricing
All plansCompared on fuzz testing software
- Input generation methods
- mutation, generation, hybrid
- Target types
- raw byte buffers, structured Rust data, libraries, APIs, compiler code, allocator operations
- Coverage guidance
- Yes
- Crash triage
- Yes
- Execution mode
- local
- Supported languages
- Rust
- CI/CD support
- Yes

