Record summary

CVE-2025-32355 has a selected CVSS score of 7.9 (high); EIP currently links 1 Nuclei template.

Description

Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 31, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 24, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHRocket TRUfusion Enterprise - Server Side Request Forgery

Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource.

Impact

Attackers can make the proxy load arbitrary resources, potentially leading to information disclosure or further attacks.

Remediation

Update to the latest version with proxy configuration fixes.

Authorsprincechaddha, rcesecurity, DhiyaneshDk
Template tagscvecve2025rockettrufusionssrfvkev
Shodan: html:"TRUfusion Enterprise"

Source: ProjectDiscovery

References

4