Jazzer is a free, coverage-guided in-process fuzzer for JVM applications, based on libFuzzer. It supports Java, Kotlin, Scala, and Clojure targets, along with JNI and native libraries. With JUnit 5.9.0 or newer, fuzz tests can be included alongside regular unit tests. The @FuzzTest annotation lets it generate and mutate method inputs, including primitives, strings, arrays, and standard library classes. Tests can run against saved crashing inputs in regression mode or fuzz for new coverage. Built-in sanitizers detect security issues such as SSRF, file path traversal, and OS command injection, and feed signals back into fuzzing. Jazzer works with Maven, Gradle, and Bazel, or can run as a standalone binary or through its Java main class. Supported systems are Linux x86_64 and arm64, macOS 12 or later on x86_64 and arm64, and Windows x86_64. The jazzer-junit package is available on Maven Central, and the repository uses the Apache-2.0 license.
Who it is for
Jazzer suits developers testing JVM applications and libraries, including Java, Kotlin, Scala, or Clojure projects. Its JUnit integration and build-tool support can fit teams that want fuzz tests alongside their regular test workflows.
What is good
- JUnit integration supports fuzz tests alongside unit tests.
- Built-in sanitizers flag several Java security issues.
- Works with Maven, Gradle, and Bazel.
- Supports Linux, macOS, and Windows.
- Free under Apache-2.0.
What to know first
- JUnit integration requires JUnit 5.9.0 or newer.
- Windows support is limited to x86_64.
- macOS support requires version 12 or later.
Verdict
Jazzer combines coverage-guided fuzzing with JUnit integration and security-focused sanitizers for JVM targets. Its listed platform support and JUnit version requirement are worth checking against a project’s setup.
Jazzer plans and pricing
All plansCompared on fuzz testing software
- Free plan
- Yes
- Input generation methods
- mutation, generation
- Target types
- JVM applications, Java, Kotlin, Scala, Clojure, JNI/native libraries
- Coverage guidance
- Yes
- Crash triage
- Yes
- Execution mode
- local
- Supported languages
- Java, Kotlin, Scala, Clojure
- CI/CD support
- Yes

