$npx skillfedfor your agent

boofuzz

A fork and successor of the Sulley Fuzzing Framework

With conditionsPyPI SecurityReleased Oct 202376.8K downloads / moGPL-2.0-onlyPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — boofuzz-0.4.2-py3-none-any.whl
v0.4.2 · released 2023-10-06 · Python >=3.8,<4.0 · 9 runtime deps: attrs, click, colorama, Flask, funcy, psutil, pydot, pyserial

Yes, if you are conducting security testing or protocol validation and accept the GPL-2.0-only copyleft license. Boofuzz is actively maintained, has low install friction, carries no known vulnerabilities, and provides a mature, well-documented fuzzing framework. Not suitable for proprietary projects without separate licensing or if you require a permissive license.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.8 or later.
  • Fuzzing a live target requires network access and a running service to test against.
  • Low install friction with a pure Python wheel distribution and nine runtime dependencies that are all widely available.

License · maintenance · safety

GPL-2.0-only (copyleft) — Boofuzz is licensed under GPL-2.0-only (copyleft). Any code that links to or distributes boofuzz must be released under compatible terms; proprietary projects cannot use this library without separate licensing arrangements.

last release 2023-10-06 (1043 days) · last repo commit 2026-08-06 · 2,354 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 76,799 downloads/mo, #14,589 on PyPI

Verify before relying

pip install boofuzz

from boofuzz import Session, s_string, s_int

session = Session()
session.connect(target_host, target_port)
session.fuzz()
  • Whether the web UI (added in v0.4.2) requires additional system dependencies or configuration beyond the listed runtime packages.
  • Performance characteristics when fuzzing large protocol definitions or high-volume targets.
  • Compatibility with Windows serial fuzzing given the pyserial dependency and platform-specific behavior.
Same gist for agents: .md · .json

What it is and what it does

Boofuzz is a successor to the Sulley fuzzing framework, designed to systematically test network protocols and services by generating malformed, unexpected, or edge-case data and observing how targets respond. It combines data generation, instrumentation (failure detection), target reset, and test recording into a cohesive fuzzing workflow. The framework supports multiple communication mediums—TCP, UDP, serial, raw Ethernet and IP layers, Unix sockets, and NETCONF—making it applicable to a wide range of protocol testing scenarios.

The package provides both a programmatic API for building custom fuzz scripts and a command-line interface for generic fuzzing workflows. It records test results to CSV, maintains a database of test cases, and includes a web UI for monitoring fuzzing progress. Boofuzz is actively maintained, supports Python 3.8 through 3.11, and aims to be more accessible and extensible than its predecessor while incorporating lessons learned from years of open-source fuzzing practice.

Use it for

  • Discover vulnerabilities in network services by systematically testing protocol implementations with malformed inputs.
  • Validate robustness of embedded devices or IoT systems that communicate over serial, Ethernet, or IP protocols.
  • Test custom protocol implementations during development to catch edge cases before deployment.
  • Fuzz NETCONF servers or other standardized network protocols to ensure compliance and stability.
  • Generate and replay specific test cases to reproduce and verify fixes for protocol handling bugs.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you are conducting security testing or protocol validation and accept the GPL-2.0-only copyleft license.

Boofuzz is actively maintained, has low install friction, carries no known vulnerabilities, and provides a mature, well-documented fuzzing framework. Not suitable for proprietary projects without separate licensing or if you require a permissive license.

Install

boofuzz on PyPI

Before you install

Low install friction with a pure Python wheel distribution and nine runtime dependencies that are all widely available. The project is actively maintained with a recent commit on 2026-08-06 and has been in active development since its first release in 2016.

Requires Python 3.8 or later. Fuzzing a live target requires network access and a running service to test against.

License in practice

Boofuzz is licensed under GPL-2.0-only (copyleft). Any code that links to or distributes boofuzz must be released under compatible terms; proprietary projects cannot use this library without separate licensing arrangements.

Quickstart

pip install boofuzz

from boofuzz import Session, s_string, s_int

session = Session()
session.connect(target_host, target_port)
session.fuzz()

Verify before relying

  • Whether the web UI (added in v0.4.2) requires additional system dependencies or configuration beyond the listed runtime packages.
  • Performance characteristics when fuzzing large protocol definitions or high-volume targets.
  • Compatibility with Windows serial fuzzing given the pyserial dependency and platform-specific behavior.

Package facts

LicenseGPL-2.0-only copyleft
Python supportSupports the current Python release >=3.8,<4.0
Install frictionLow. Pure-Python wheel
Runtime dependencies
9 packages
attrsclickcoloramaFlaskfuncypsutilpydotpyserialtornado
MaintenanceActively maintained 1,043 days since the last release
Last repo commit
First released
Downloads76,799 / month, #14,589 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaEnvironment :: ConsoleEnvironment :: Console :: CursesIntended Audience :: DevelopersIntended Audience :: Science/ResearchLicense :: OSI Approved :: GNU General Public License v2 (GPLv2)Natural Language :: EnglishOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: SecurityTopic :: Software Development :: Testing :: Traffic GenerationTopic :: System :: Networking

Evidence: boofuzz-0.4.2-py3-none-any.whl

Tags

Capabilities
network protocol fuzzingfuzz testing frameworkvulnerability discovery toolprotocol testing automationnetwork service fuzzersecurity testing frameworkmalformed data generation
Topics
security-testingprotocol-fuzzingvulnerability-discovery
PyPI keywords
securityfuzzing

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “network protocol fuzzing”

  • boofuzzBoofuzz is a network protocol fuzzing framework that generates…
  • hegel-coreHegel-core provides property-based testing data generation and…
  • dpktdpkt parses and creates TCP/IP protocol packets with minimal…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also atheris · fuzzfetch · hegel-core · RapidFuzz · dnstwist · rstr · hypothesis · cobs · detect-test-pollution · thefuzz

Further reading