← All database systems
DuckDB is supported by SQLancer — the main repository ships a
testing implementation for it.
SQLancer is credited with 302 bugs in it, reported between 2020-04-07 and
2026-09-07.
Its source is at duckdb/duckdb.
A further 7 reports were
filed and rejected by the developers as invalid or duplicate. Those are kept
in the dataset for transparency and are excluded from every count here.
How the project uses SQLancer
Official testing
The DuckDB project keeps a regression test for each SQLancer finding under test/issues/rigger/, so the bugs it found stay fixed.
# description: SQLancer bug that found a crash in the instr implementation
test/issues/rigger/instr_crash.test in the DuckDB repository, one of the files the project keeps for this.test/issues/rigger/instr_crash.test
last verified 2026-09-13
How the bugs break down
By year reported
- 2020
-
85
- 2021
-
1
- 2022
-
7
- 2023
-
39
- 2024
-
9
- 2025
-
52
- 2026
-
103
- Year not recorded
-
6
Who found them
- Found by the SQLancer project
-
286
- Found by someone outside the project
-
15
- Reporter not recorded
-
1
By status
- Fixed
-
271
- Confirmed
-
9
- Open
-
22
By symptom
- Logic bug
-
30
- Unexpected error
-
13
- Crash
-
32
- Unclassified
-
227
By technique
- Technique not recorded
-
268
- Ternary Logic Partitioning (TLP)
-
34
Why each bug counts
- Filed by someone who runs SQLancer campaigns
-
112
- The reproducer carries SQLancer's generated schema
-
102
- Listed in the project's own bug repository
-
46
- The report names a SQLancer oracle
-
33
- The report names SQLancer
-
9
Who reported them (8)
- Manuel Rigger
-
75
- DerZc
-
48
- Yibo-Dong
-
39
- suyZhong
-
38
- Zhaokun Xiang
-
24
- Chi Zhang
-
23
- wanteatfruit
-
14
- Suyang Zhong
-
9
Every bug on record (309)
One row per report, newest first, each linking to the report itself. Rejected
reports are marked and are not part of any count above.
Every figure on this page is computed from
_data/impact/.
The attribution policy
explains what has to be true for a bug to be counted.