Definition
What is VEX?
Also: Vulnerability Exploitability eXchange
VEX, or Vulnerability Exploitability eXchange, is a machine-readable statement of whether a known vulnerability affects a specific product and why.
VEX adds product-specific exploitability context to vulnerability findings associated with an SBOM. Common statuses are affected, not affected, fixed and under investigation; formats encode these statuses according to their own models. CycloneDX VEX, for example, uses analysis states including affected, not_affected, resolved and in_triage. A statement can include a justification, action and supporting detail, allowing downstream teams to understand a manufacturer's decision instead of treating every component match as an exploitable product vulnerability. Vellaci records per-product and per-version triage with reasons and exports CycloneDX 1.5 VEX documents.
Reference: CISA minimum requirements for VEX; CycloneDX VEX specification
CISA VEX minimum requirementsCycloneDX specification
Updated 2026-09-29 · Paraphrase for orientation, not legal advice.