Skip to content

Vulnerability Monitoring — VEX Triage

A match against an advisory feed means a product potentially contains a vulnerable component — not that it is exploitable in context. VEX (Vulnerability Exploitability eXchange) is how you record that judgement. FLEET ingests VEX to triage findings and can emit VEX for downstream consumers and CRA evidence.

FLEET status OpenVEX CycloneDX state Effect
not_affected not_affected not_affected, false_positive suppressed (no alerts)
fixed fixed resolved, resolved_with_pedigree suppressed
affected affected exploitable stays actionable
under_investigation under_investigation in_triage stays actionable

A suppressed finding drops out of the actionable list and does not raise alerts or auto-draft ENISA notifications. Source re-scans never overwrite an operator’s VEX decision.

Both OpenVEX and CycloneDX-VEX are accepted; the format is auto-detected. A statement is matched to a finding by vulnerability id or alias.

Terminal window
curl -X POST https://your-fleet/api/v1/monitor/products/$ID/vex \
-H "Authorization: Bearer $FLEET_KEY" -H "content-type: application/json" \
-d '{
"@context": "https://openvex.dev/ns/v0.2.0",
"@id": "urn:acme:vex:1",
"statements": [
{ "vulnerability": {"name": "CVE-2026-0001"},
"status": "not_affected",
"justification": "vulnerable_code_not_in_execute_path" }
]
}'
# → { "data": { "format": "openvex", "statements": 1, "applied": 1 } }

Ingested documents are retained as evidence.

Generate a VEX document from the product’s current findings:

Terminal window
curl "https://your-fleet/api/v1/monitor/products/$ID/vex" \
-H "Authorization: Bearer $FLEET_KEY" # OpenVEX (default)
curl "https://your-fleet/api/v1/monitor/products/$ID/vex?format=cyclonedx" \
-H "Authorization: Bearer $FLEET_KEY" # CycloneDX-VEX

To set VEX on a single finding directly (without a document):

Terminal window
curl -X PATCH https://your-fleet/api/v1/monitor/findings/$FINDING_ID/vex \
-H "Authorization: Bearer $FLEET_KEY" -H "content-type: application/json" \
-d '{ "status": "not_affected", "justification": "not reachable" }'

For authoring a VEX document over time, each product has one mutable draft you edit and then apply (which ingests it onto findings and records the evidence document):

Path Method Purpose
/monitor/products/{id}/vex-draft POST Create (?seed=true pre-fills from current findings)
/monitor/products/{id}/vex-draft GET Read the draft
/monitor/products/{id}/vex-draft PUT Replace the draft document (must parse as VEX)
/monitor/products/{id}/vex-draft DELETE Discard the draft
/monitor/products/{id}/vex-draft/apply POST Apply it (ingest onto findings)
  • fleet_ingest_vex / fleet_emit_vex — apply or generate a VEX document.
  • fleet_set_finding_vex — per-finding triage.
  • fleet_edit_vex_draft / fleet_apply_vex_draft — author and apply a draft.