OWASP VXDF (Validated Exploitable Data Flow) Format (original) (raw)

OWASP VXDF: The Standard for Verifiable Exploit Evidence

The Problem

Security teams are overwhelmed by vulnerability alerts from scanning tools (SAST, DAST, SCA). Most alerts are false positives or theoretical vulnerabilities with no practical exploit path, leading to:

The Solution: VXDF

OWASP VXDF (Validated Exploitable Data Flow) is a standardized, machine-readable JSON format for describing confirmed exploitable code vulnerabilities with mandatory validation evidence.

Key Features

What VXDF Contains

Who Benefits

Project Resources

Documentation & Tools

Integration & Implementation

Get Involved

For Contributors:

For Tool Vendors:

For Organizations:


VXDF Project Roadmap

Current Status (Q2 2025)

✅ Completed (2024-Q1 2025)

🔄 In Progress (Q2 2025)

Q3 2025 Milestones

Core Platform Enhancement

Contribution Opportunities

For Developers

For Organizations

For Vendors

Get Involved

Current Priorities:

Partnership Inquiries:


Roadmap Updated: June 2025 | Next Review: September 2025


VXDF Project Meetings

Weekly Project Call

Every Tuesday, 8:00 AM - 9:00 AM Pacific Time

Time Zone Conversions

Working Groups

Schema & Standards Working Group

Tool Integration Working Group

How to Participate

  1. Join Slack: #project-vxdf for announcements
  2. Add Meeting: Use the calendar link above
  3. Review Agenda: Check the Google Doc before meetings

Meeting Resources


Weekly meetings every Tuesday 8:00 AM Pacific Time