CVE-2025-32355

Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is misconfigured in a way that allows specifying absolute URLs in the HTTP request line, causing the proxy to load the given resource.
Configurations

No configuration.

History

11 Mar 2026, 16:16

Type Values Removed Values Added
CWE CWE-918
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

18 Feb 2026, 17:51

Type Values Removed Values Added
Summary
  • (es) Rocket TRUfusion Enterprise hasta la versión 7.10.4.0 utiliza un proxy inverso para gestionar las conexiones entrantes. Sin embargo, el proxy está mal configurado de tal manera que permite especificar URLs absolutas en la línea de solicitud HTTP, lo que provoca que el proxy cargue el recurso especificado.

17 Feb 2026, 20:22

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-17 20:22

Updated : 2026-03-11 16:16


NVD link : CVE-2025-32355

Mitre link : CVE-2025-32355

CVE.ORG link : CVE-2025-32355


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)