Rocket TRUfusion Enterprise - Server Side Request Forgery
CVE-2025-32355
Verified
Description
Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource.
Severity
High
Published Date
February 18, 2026
Template Author
princechaddha, rcesecurity, dhiyaneshdk
CVE-2025-32355.yaml
Remediation Steps
Update to the latest version with proxy configuration fixes.