Vulnerability Monitoring — VEX Triage
A match against an advisory feed means a product potentially contains a vulnerable component — not that it is exploitable in context. VEX (Vulnerability Exploitability eXchange) is how you record that judgement. FLEET ingests VEX to triage findings and can emit VEX for downstream consumers and CRA evidence.
Statuses
Section titled “Statuses”| FLEET status | OpenVEX | CycloneDX state | Effect |
|---|---|---|---|
not_affected |
not_affected |
not_affected, false_positive |
suppressed (no alerts) |
fixed |
fixed |
resolved, resolved_with_pedigree |
suppressed |
affected |
affected |
exploitable |
stays actionable |
under_investigation |
under_investigation |
in_triage |
stays actionable |
A suppressed finding drops out of the actionable list and does not raise alerts or auto-draft ENISA notifications. Source re-scans never overwrite an operator’s VEX decision.
Ingest
Section titled “Ingest”Both OpenVEX and CycloneDX-VEX are accepted; the format is auto-detected. A statement is matched to a finding by vulnerability id or alias.
curl -X POST https://your-fleet/api/v1/monitor/products/$ID/vex \ -H "Authorization: Bearer $FLEET_KEY" -H "content-type: application/json" \ -d '{ "@context": "https://openvex.dev/ns/v0.2.0", "@id": "urn:acme:vex:1", "statements": [ { "vulnerability": {"name": "CVE-2026-0001"}, "status": "not_affected", "justification": "vulnerable_code_not_in_execute_path" } ] }'# → { "data": { "format": "openvex", "statements": 1, "applied": 1 } }Ingested documents are retained as evidence.
Generate a VEX document from the product’s current findings:
curl "https://your-fleet/api/v1/monitor/products/$ID/vex" \ -H "Authorization: Bearer $FLEET_KEY" # OpenVEX (default)curl "https://your-fleet/api/v1/monitor/products/$ID/vex?format=cyclonedx" \ -H "Authorization: Bearer $FLEET_KEY" # CycloneDX-VEXPer-finding triage
Section titled “Per-finding triage”To set VEX on a single finding directly (without a document):
curl -X PATCH https://your-fleet/api/v1/monitor/findings/$FINDING_ID/vex \ -H "Authorization: Bearer $FLEET_KEY" -H "content-type: application/json" \ -d '{ "status": "not_affected", "justification": "not reachable" }'Editable VEX drafts
Section titled “Editable VEX drafts”For authoring a VEX document over time, each product has one mutable draft you edit and then apply (which ingests it onto findings and records the evidence document):
| Path | Method | Purpose |
|---|---|---|
/monitor/products/{id}/vex-draft |
POST | Create (?seed=true pre-fills from current findings) |
/monitor/products/{id}/vex-draft |
GET | Read the draft |
/monitor/products/{id}/vex-draft |
PUT | Replace the draft document (must parse as VEX) |
/monitor/products/{id}/vex-draft |
DELETE | Discard the draft |
/monitor/products/{id}/vex-draft/apply |
POST | Apply it (ingest onto findings) |
fleet_ingest_vex/fleet_emit_vex— apply or generate a VEX document.fleet_set_finding_vex— per-finding triage.fleet_edit_vex_draft/fleet_apply_vex_draft— author and apply a draft.