Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk4 min

How to Diff a VEX Document Claim by Claim

A claim-by-claim VEX diff compares vulnerability and exact product scope before status, supporting explanation or action, and revision timing.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To diff two Vulnerability Exploitability eXchange (VEX) documents claim by claim, match each assertion by vulnerability and exact product scope, then compare status, rationale or action, and timing. A line-based diff can show what text moved; an auditable VEX diff must show whether the issuer changed which product versions are affected and why.

What counts as a VEX claim?

OpenVEX describes its central unit as a statement: an assertion about a vulnerability in a product, with a status and supporting context. Treat a claim as the combination of vulnerability, product identity, version or component scope where specified, status, rationale or action, and time. Two records are counterparts only when their vulnerability and product scopes correspond closely enough to compare.

A VEX status is the issuer’s assertion, not independent proof that an exploit is or is not possible. In particular, retain an issuer’s explanation for a not-affected conclusion, and do not interpret under-investigation as either affected or not affected. OpenVEX Specification

Prepare both documents before matching claims

First establish what each file is. A .json extension does not identify a VEX format: OpenVEX serializes a JSON-LD structure, while CSAF VEX is a profile within the CSAF advisory model. Record the declared format and specification version, document identifier, issuer, document version, and issue or update timestamps. Parse each file against its own declared format and version; do not apply a CSAF 2.1 parser to a 2.0 document without validating compatibility. OpenVEX Specification; CSAF 2.1

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Free Fling File Transfer Software for Windows [PC Download]
  • Intuitive interface of a conventional FTP client
  • Easy and Reliable FTP Site Maintenance.
  • FTP Automation and Synchronization

Build a stable claim key

Use a key that captures identity, not merely display text. Start with the vulnerability identifier and a stable product identifier. Add version or version range, platform or release, and component or subcomponent when present. OpenVEX recommends product identifiers that can be correlated with software bill of materials entries and commonly uses CVE-style vulnerability identifiers. CSAF references products in a product tree and attaches vulnerability statuses to product IDs. A familiar product name alone can match the wrong edition or release. OpenVEX Specification; CSAF 2.0 VEX profile

Compare product and version scope first

Before reading the status change, compare which products the assertion covers. Check product identity, platform and release, component scope, and the version representation. Scope can be expressed as enumerated versions or ranges; a shift from one release to a broad range is material even if the status is unchanged. Record additions, removals, expansions, and contractions explicitly rather than burying them in a text-field diff. CISA VEX Use Cases

Product matching may require issuer-specific detail. Cisco’s CVR lookup, for example, asks customers to match CVE and product, platform, and release. When identifiers do not map cleanly, keep the records unmatched or mark the match uncertain instead of silently equating them. Cisco CVR/VEX FAQ

Compare status, explanation, and action together

Statuses are controlled values, but their labels differ by format. Preserve the original labels in the output; if a downstream report normalizes them, show the mapping separately so readers can distinguish source wording from your categorization.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Format Source-native status labels Context to compare
OpenVEX not_affected, affected, fixed, under_investigation not_affected requires a justification or impact statement; affected requires an action statement.
CSAF VEX known_not_affected, known_affected, fixed, under_investigation known_not_affected needs impact information; known_affected needs product-specific remediation information.

Compare old and new status alongside the associated justification, impact explanation, status notes, and action or remediation. Do not infer that two free-text explanations are equivalent just because their wording resembles each other. OpenVEX notes that free-form impact text is not machine-readable and recommends machine-readable justifications for automation. OpenVEX Specification; CSAF 2.1

Keep fixed tied to the versions that contain the fix; the label alone does not establish the boundaries of affected or fixed scope. Likewise, an under_investigation claim is unresolved, not a midpoint between affected and not affected.

Rank #2
VideoPad Video Editor - Create Professional Videos with Transitions and Effects [Download]
  • Apply effects and transitions, adjust video speed and more
  • One of the fastest video stream processors on the market
  • Drag and drop video clips for easy video editing
  • Capture video from a DV camcorder, VHS, webcam, or import most video file formats
  • Create videos for DVD, HD, YouTube and more

Compare timestamps and revision metadata

Show document issue time, statement timestamp where available, last-updated time, and document version. Keep assertion time distinct from the time you retrieved the file. A newer file may change only metadata, or it may change claim content; report those cases separately.

OpenVEX describes statements as evolving: later statements can override or enrich earlier information, and the document version must increase when content changes, including statements. Do not assume every VEX format uses the same supersession rules; apply the declared format’s timestamp inheritance and revision semantics. OpenVEX Specification

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Produce an auditable diff

Use one row per matched claim, then separate lists for claims found only in the old or new document and for uncertain matches. A useful report makes the literal field changes visible and keeps semantic interpretation distinct from them.

Field What to record
Match key Vulnerability ID; stable product identity; version, platform, release, and component scope where applicable.
Scope Previous and current product/version scope, with additions, removals, expansion, or narrowing called out.
Status Previous and current source-native labels; any normalization shown separately.
Rationale Previous and current justification, impact statement, or status notes.
Action Previous and current action or remediation information.
Time and revision Statement and document timestamps, document version, and retrieval time where relevant.
Classification and review Change class, literal field differences, interpretation, and any reason for human review.

Useful change classes include:

  • Vulnerability/product claim added or removed.
  • Product or version scope expanded, narrowed, or otherwise changed.
  • Status changed, including a move into or out of investigation.
  • Justification, impact explanation, or action/remediation added, removed, or changed.
  • Document or statement timing/version changed without a claim-content change.
  • Match is uncertain and needs issuer or human review.

Where automation helps—and where review remains necessary

Security tools consume VEX statuses, so parsing and field-level comparison can make revisions easier to process. Microsoft Security Response Center announced on September 8, 2026, that it was publishing VEX statements for all Microsoft-assigned CVEs, describing the goal as more machine-readable information for security tooling. That is a dated supplier announcement, not a promise about every VEX issuer or every downstream integration. MSRC announcement, September 8, 2026

Automation cannot safely resolve every identity or meaning question. Route a diff for human review when product identifiers fail to match, version boundaries are unclear, a mapping is unsupported, the format or schema is uncertain, or the apparent status change depends on ambiguous prose. A machine-readable diff exposes the evidence; it does not independently validate the issuer’s exploitability assessment.

Quick Recap

Bestseller No. 1
Free Fling File Transfer Software for Windows [PC Download]
Free Fling File Transfer Software for Windows [PC Download]
Intuitive interface of a conventional FTP client; Easy and Reliable FTP Site Maintenance.; FTP Automation and Synchronization
Bestseller No. 2
VideoPad Video Editor - Create Professional Videos with Transitions and Effects [Download]
VideoPad Video Editor - Create Professional Videos with Transitions and Effects [Download]
Apply effects and transitions, adjust video speed and more; One of the fastest video stream processors on the market
$69.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.