# wuppiefuzz mit Homebrew installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für wuppiefuzz in AI-Agent-Workflows.

## Installation

```sh
sudo av install brew:wuppiefuzz
```

Weitere Installationsbefehle:

### macOS

- Homebrew (100%):

```sh
brew install wuppiefuzz
```

  Evidenz: local Homebrew formula metadata

## Paketfakten

- **Paketschlüssel:** brew:wuppiefuzz
- **Paketmanager:** Homebrew
- **Version:** 1.6.0
- **Quellzusammenfassung:** Coverage-guided REST API fuzzer developed on top of LibAFL
- **Homepage:** <https://github.com/TNO-S3/WuppieFuzz>
- **Repository:** <https://github.com/TNO-S3/WuppieFuzz>
- **Zuletzt aktualisiert:** 2026-06-25T20:42:36Z
- **Generiert:** 2026-08-03T19:37:03+00:00

## Executables

- wuppiefuzz (Alias)

## Installationsverhalten

- Bottle: nicht verfügbar

## Version und Aktualität

- Seite generiert: 2026-08-03
- Manager-Version: 1.6.0
## Projektgeschichte und Nutzung

WuppieFuzz is TNO's open-source, coverage-guided REST API fuzzer built on LibAFL. The project targets black-box, grey-box, and white-box testing and emphasizes ease of use, explainable findings, and modularity.

### Projektgeschichte

The project is developed under the TNO-S3 GitHub organization and is implemented primarily in Rust. Its README presents WuppieFuzz as a practical REST API fuzzing tool, while its academic publication frames it as coverage-guided, stateful REST API fuzzing driven by OpenAPI specifications and REST-specific mutators.

The tool's research context is modern API security. The TNO repository and 2025/2026 publication describe a workflow in which an OpenAPI specification seeds request sequences, LibAFL and REST-specific mutation explore behavior, and coverage measurements guide which request sequences are sent next to reach complex application states.

### Adoptionsgeschichte

WuppieFuzz has moved beyond a repository-only release into security tooling visibility: its README lists media coverage, a ONE Conference e-magazine feature, an OpenAPI.tools listing, a Nordic APIs talk, and a Thoughtworks Technology Radar mention. The preferred citation points to the ICISSP 2026 proceedings, giving it both an open-source and research footprint.

### Wie es verwendet wird

Users run WuppieFuzz against a target application and provide an OpenAPI specification so the fuzzer can generate and mutate requests. For coverage-guided setups, the README shows passing coverage configuration such as JaCoCo data for a Java target; the paper also describes harness automation and reports that help developers fix bugs.

### Warum Paket-Nerds sich dafür interessieren

For security package collections, WuppieFuzz is notable because it brings LibAFL-style coverage-guided fuzzing into the REST API space instead of staying at the binary or library fuzzing layer. It sits near OpenAPI tooling, API security testing, Rust fuzzing infrastructure, and developer-friendly security automation.

### Zeitleiste

- 2024: Project media coverage and conference visibility begin appearing in the upstream README.
- 2025: TNO's publication record lists WuppieFuzz as a conference paper.
- 2025-12-17: The WuppieFuzz paper is submitted to arXiv.
- 2026: The README identifies WuppieFuzz v1.6.0 and cites the ICISSP 2026 proceedings.

### Related projects

- WuppieFuzz is built on LibAFL and is comparable to other REST API fuzzers and API testing tools that consume OpenAPI specifications. The paper explicitly discusses black-box, grey-box, and white-box API fuzzing in relation to existing approaches such as EvoMaster.

### Quellen

- <https://arxiv.org/abs/2512.15554>
- <https://github.com/TNO-S3/WuppieFuzz>
- <https://repository.tno.nl/SingleDoc?docId=81140>


## Sicherheitshinweise

Für wuppiefuzz wurde kein passendes lokales Secret-Handling-Manifest gefunden. Nucleus-Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.



## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: config.yaml

## Combined YAML source

View the package source record on GitHub. [combined/wuppiefuzz.yml](https://github.com/mxcl/pkgdb/blob/main/combined/wuppiefuzz.yml)


## Quellen

- pkg.so package database
- Geiger risk classifier
- curated configuration and credential file locations
- curated package history
- pkgdb category and tag curation
- cross-ecosystem install command graph
