Definition

What is VEX?

Also: Vulnerability Exploitability eXchange

VEX, or Vulnerability Exploitability eXchange, is a machine-readable statement of whether a known vulnerability affects a specific product and why.

VEX adds product-specific exploitability context to vulnerability findings associated with an SBOM. Common statuses are affected, not affected, fixed and under investigation; formats encode these statuses according to their own models. CycloneDX VEX, for example, uses analysis states including affected, not_affected, resolved and in_triage. A statement can include a justification, action and supporting detail, allowing downstream teams to understand a manufacturer's decision instead of treating every component match as an exploitable product vulnerability. Vellaci records per-product and per-version triage with reasons and exports CycloneDX 1.5 VEX documents.

Reference: CISA minimum requirements for VEX; CycloneDX VEX specification

CISA VEX minimum requirementsCycloneDX specification

Updated 2026-09-29 · Paraphrase for orientation, not legal advice.

In practice

Related terms

See the term as a workflow.

Vellaci turns each of these definitions into a record with an owner, a timestamp and evidence.