Atheris
Atheris is a coverage-guided Python fuzzer built on libFuzzer. It enables fuzzing of both pure Python code and Python C extensions with integrated AddressSanitizer support for detecting memory corruption issues.
When to Use
Choose Atheris when:
- Fuzzing pure Python code with coverage guidance
- Testing Python C extensions for memory corruption
- Integration with libFuzzer ecosystem is desired
- AddressSanitizer support is needed
Quick Start
Run:
Installation
Atheris supports 32-bit and 64-bit Linux, and macOS. We recommend fuzzing on Linux because it's simpler to manage and often faster.
Prerequisites
- Python 3.7 or later
- Recent version of clang (preferably latest release)
- For Docker users: Docker Desktop
Linux/macOS
Docker Environment (Recommended)
For a fully operational Linux environment with all dependencies configured:
Build and run:
Verification
Writing a Harness
Harness Structure for Pure Python
Structured Input with FuzzedDataProvider
A target taking several typed arguments wastes most of the fuzzer's inputs if the harness
slices data by hand, because every mutation shifts the byte offsets of everything after it.
atheris.FuzzedDataProvider splits one bytes input into typed values instead:
See structured-input.md [blocked] for the full method reference, the fixed-draw- order rule, and what each method returns once the buffer runs dry.
Harness Rules
See Also: For detailed harness writing techniques, patterns for handling complex inputs, and advanced strategies, see the fuzz-harness-writing technique skill.
Fuzzing Pure Python Code
For fuzzing broader parts of an application or library, use instrumentation functions:
Instrumentation Options:
atheris.instrument_func- Decorator for single function instrumentationatheris.instrument_imports()- Context manager for instrumenting all imported modulesatheris.instrument_all()- Instrument all Python code system-wide
Fuzzing Python C Extensions
Python C extensions require compilation with specific flags for instrumentation and sanitizer support.
Environment Configuration
If using the provided Dockerfile, these are already configured. For local setup:
Example: Fuzzing cbor2
Install the extension from source:
The --no-binary-package flag ensures the C extension is compiled locally with
instrumentation rather than pulled as a prebuilt wheel. Persist that choice with
no-binary-package = ["cbor2"] under [tool.uv] in pyproject.toml, or a later
uv sync can silently swap in an uninstrumented wheel.
Create cbor2-fuzz.py:
Run:
Important: When running locally (not in Docker), you must set
LD_PRELOADmanually.
Corpus Management
Creating Initial Corpus
Run with corpus:
Corpus Minimization
Atheris inherits corpus minimization from libFuzzer:
See Also: For corpus creation strategies, dictionaries, and seed selection, see the fuzzing-corpus technique skill.
Running Campaigns
Basic Run
With Corpus Directory
Common Options
Interpreting Output
Sanitizer Integration
AddressSanitizer (ASan)
AddressSanitizer is automatically integrated when using the provided Docker environment or when compiling with appropriate flags.
For local setup:
Configure ASan behavior:
LD_PRELOAD Configuration
For native extension fuzzing:
See Also: For detailed sanitizer configuration, common issues, and advanced flags, see the address-sanitizer and undefined-behavior-sanitizer technique skills.
Common Sanitizer Issues
Advanced Usage
Tips and Tricks
Custom Instrumentation
Fine-tune what gets instrumented:
Performance Tuning
UndefinedBehaviorSanitizer (UBSan)
Add UBSan to catch additional bugs:
Note: Modify flags in Dockerfile if using containerized setup.
Real-World Examples
Two complete harnesses — a pure-Python parser and an HTTP response parser — are in examples.md [blocked].
Troubleshooting
Related Skills
Technique Skills
Related Fuzzers
Resources
Key External Resources
Atheris GitHub Repository Official repository with installation instructions, examples, and documentation for fuzzing both pure Python and native extensions.
Native Extension Fuzzing Guide Comprehensive guide covering compilation flags, LD_PRELOAD setup, sanitizer configuration, and troubleshooting for Python C extensions.
Continuously Fuzzing Python C Extensions Trail of Bits blog post covering CI/CD integration, ClusterFuzzLite setup, and real-world examples of fuzzing Python C extensions in continuous integration pipelines.
ClusterFuzzLite Python Integration Guide for integrating Atheris fuzzing into CI/CD pipelines using ClusterFuzzLite for automated continuous fuzzing.
Video Resources
Videos and tutorials are available in the main Atheris documentation and libFuzzer resources.

