/Vulnerability Library

Rocket TRUfusion Enterprise - Server Side Request Forgery

CVE-2025-32355
Verified

Description

Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource.

Severity

High

Published Date

February 18, 2026

Template Author

princechaddha, rcesecurity, dhiyaneshdk

CVE-2025-32355.yaml
7.5Severity

CVSS Metrics

References

https://www.rcesecurity.com/2026/02/when-audits-fail-from-pre-auth-ssrf-to-rce-in-trufusion-enterprise/https://nvd.nist.gov/vuln/detail/CVE-2025-32355

Remediation Steps

Update to the latest version with proxy configuration fixes.