Tool report: EvoMaster—black and white box search-based fuzzing for REST, GraphQL and RPC APIs

  • Andrea Arcuri*
  • , Man Zhang
  • , Susruthan Seran
  • , Juan Pablo Galeotti
  • , Amid Golmohammadi
  • , Onur Duman
  • , Agustina Aldasoro
  • , Hernan Ghianni
  • *Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

Abstract

In this paper, we present the latest version 3.0.0 of EvoMaster, an open-source search-based fuzzer aimed at Web APIs. We discuss and present all its recent improvements, including advanced white-box heuristics, advanced search algorithms, support for databases and external services, as well as dealing with GraphQL and RPC APIs besides the original use case for REST APIs. The tool’s installers have been downloaded more than 3000 times. EvoMaster is in daily use for fuzzing millions of lines of code in hundreds of APIs in large Fortune 500 companies, such as for example the e-commerce Meituan.

Original languageEnglish
Article number4
JournalAutomated Software Engineering
Volume32
Issue number1
DOIs
StatePublished - Jun 2025

Keywords

  • Fuzzing
  • SBST
  • Tool
  • Web API

Fingerprint

Dive into the research topics of 'Tool report: EvoMaster—black and white box search-based fuzzing for REST, GraphQL and RPC APIs'. Together they form a unique fingerprint.

Cite this