CVE-2025-32355

HIGH EXPLOITED NUCLEI

Rocket TRUfusion Enterprise <7.10.4.0 - SSRF

Title source: llm

Description

Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource.

Nuclei Templates (1)

Rocket TRUfusion Enterprise - Server Side Request Forgery
HIGHVERIFIEDby princechaddha,rcesecurity,DhiyaneshDk
Shodan: html:"TRUfusion Enterprise"

Scores

CVSS v3 7.3
EPSS 0.0190
EPSS Percentile 83.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

VulnCheck KEV 2026-03-31
CWE
CWE-918
Status published
Products (1)
rocketsoftware/trufusion_enterprise < 7.10.5.0
Published Feb 17, 2026
Tracked Since Feb 18, 2026