logo

Bugs that survive the heat of continuous fuzzing

ID: c3e81b58-2907-5dfa-b3af-086497146f0e

STIX ID: report--c3e81b58-2907-5dfa-b3af-086497146f0e

Feed Name: GitHub Security Lab

Threat Score
55/100

Date Published: 2025-12-29

Date Updated: 2026-04-27

Author: Antonio Morales

...
...

This blog post examines why long-running continuous fuzzing (via OSS-Fuzz) still misses serious bugs, illustrating with three case studies—GStreamer (29 vulnerabilities), Poppler (including a 1‑click RCE in Evince), and Exiv2 (multiple CVEs). It identifies causes such as low fuzzer coverage, unfuzzed dependencies, lack of encoder testing, and bugs requiring large or long-running inputs, and presents a five-step workflow (preparation, coverage, context, value, triaging) and advanced techniques to improve fuzzing effectiveness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.