CVE-2025-32355
rocketsoftware trufusion_enterprise Server-Side Request Forgery (SSRF)
Record summary
CVE-2025-32355 has a selected CVSS score of 7.9 (high); EIP currently links 1 Nuclei template.
Description
Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 31, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 24, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
TRUfusion EnterpriseBrowse Rocket Software / TRUfusion Enterprise | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHRocket TRUfusion Enterprise - Server Side Request Forgery
Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource.
Impact
Attackers can make the proxy load arbitrary resources, potentially leading to information disclosure or further attacks.
Remediation
Update to the latest version with proxy configuration fixes.
Source: ProjectDiscovery