Integrate ClusterFuzz with Vulnetix. Deploy ClusterFuzz for internal fuzzing at scale, monitor crash findings via the web UI and API, and export discovered vulnerabilities to Vulnetix.
Install & scan
$ # Deploy ClusterFuzz on GCP
git clone https://github.com/google/clusterfuzz
cd clusterfuzz
python butler.py create_config
python butler.py deploy
$ # ClusterFuzz REST API (requires API key from ClusterFuzz admin)
CF_URL="https://your-clusterfuzz.appspot.com"
CF_TOKEN="your-access-token"
# List open testcases
curl -s "${CF_URL}/testcases/load" -H "Authorization: Bearer ${CF_TOKEN}" | jq '.testcases' > clusterfuzz-crashes.json
vulnetix upload --file clusterfuzz-crashes.json
How Vulnetix compares: better together
Vulnetix does not replace ClusterFuzz. Keep running it. Vulnetix sits on top of ClusterFuzz (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.
| Capability | Vulnetix | ClusterFuzz |
|---|---|---|
| Security coverage | ||
| SAST (static code analysis) | ✓ Built-in rules + Semgrep augmentation | ✗ |
| SCA / dependencies | ✓ 40+ ecosystems, transitive graph | ✗ |
| DAST (dynamic testing) | ~ Ingests DAST results; no native dynamic engine | ✗ |
| Container & image | ✓ Image CVEs, base image, Dockerfile | ✗ |
| IaC / misconfiguration | ✓ Terraform, k8s, CloudFormation | ✗ |
| Secret scanning | ✓ 1,000+ rules, source + binary + git history | ✗ |
| Cloud / CSPM | ✓ Cloud-posture findings, compliance tab | ✗ |
| Mobile (MAST) | ~ Ingests mobile scanner output; no native mobile engine | ✗ |
| License compliance | ✓ SPDX, copyleft/AGPL/SSPL policy | ✗ |
| SBOM generation | ✓ CycloneDX 1.7 + SPDX 2.3, cosign-signable | ✗ |
| Malware / supply-chain | ✓ De-duplicated corpus + install-time firewall (25+ registries) | ✗ |
| Network / infra vuln | ~ Ingests network scanner output; no native network scanner | ✗ |
| Fuzzing | ✗ Ingests fuzzing crashes; no native fuzzer | ✓ Core: distributed continuous fuzzing infra powering OSS-Fuzz; multi-engine, corpus and crash management |
| Pentest / bug bounty | ✗ Ingests pentest/bug-bounty findings; not a testing service | ✗ |
| The Vulnetix orchestration layer | ||
| Cross-scanner dedup & one queue (ASPM) | ✓ Correlates every scanner into one prioritised queue with ownership routing | ~ Deduplicates crash testcases within fuzzing only; not cross-scanner ASPM consolidation of SAST/SCA/etc. |
| Exploit-intel prioritisation | ✓ EPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV | ✗ |
| Reachability analysis | ✓ Tree-sitter + CVEAffected; direct/transitive/semantic | ✗ |
| Versioned VEX + audit trail | ✓ Immutable OpenVEX/CycloneDX, cosign-signable | ✗ |
| Safe Harbour autofix | ✓ Resolves + applies the nearest safe version | ✗ |
| End-of-life policy | ✓ Flags/blocks past-EOL runtimes & packages | ✗ |
| SSVC / risk-based policy | ✓ SSVC v2 + CISA/FedRAMP/Essential-8 presets | ✗ |
✓ full · ~ partial · ✗ not covered
What ClusterFuzz does well
- Highly scalable distributed fuzzing infrastructure (Google's instance runs on ~30,000 VMs; the OSS-Fuzz instance on ~100,000) that powers OSS-Fuzz
- Accurate crash deduplication plus automatic testcase minimization
- Regression-range finding via bisection and automatic fix verification
- Multi-engine support (libFuzzer, AFL++, Honggfuzz) with ensemble/customizable strategies and fully automatic bug filing, triage and closing across issue trackers
Where Vulnetix adds to it: Vulnetix runs no fuzzers and does not stand up fuzzing fleets; it ingests ClusterFuzz/OSS-Fuzz crash reports and consolidates them into a single prioritised queue with exploit-intel scoring, reachability, VEX and EOL/SSVC policy. ClusterFuzz's dedup is crash-level within one engine, whereas Vulnetix dedups across all scanners; the two are complementary. ClusterFuzz discovers, Vulnetix orchestrates.
No migration, no rip-and-replace. ClusterFuzz keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.
Centralise ClusterFuzz results in Vulnetix
Upload ClusterFuzz JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.